ZeroHour

Vulnerabilities

18 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-82330
+3 in the same advisory: …82324 …82328 …82343
A flaw was found in the file-pvr plugin in GIMP.

A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed) decoder does not properly perform memory bounds checking. This missing validation results in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.

NVD description · AI analysis pending
6.1<1%
  • gimp gimp
  • gimp enterprise linux
CVE-2026-79902
A flaw was found in the Seattle FilmWorks plugin in GIMP.

A flaw was found in the Seattle FilmWorks plugin in GIMP. When processing a specially crafted SFW image file, the plugin allocates a Variable-Length Array (VLA) on the stack without integer overflow checks, causing an unbounded stack allocation. This issue leads to an application crash, resulting in a denial of service.

NVD description · AI analysis pending
5.5<1%
  • gimp gimp
CVE-2026-80101
A flaw was found in the file-xwd plugin in GIMP.

A flaw was found in the file-xwd plugin in GIMP. When processing a specially crafted XWD image file, the plugin validates the image width and bytes-per-line parameters independently rather than ensuring their combined values are consistent with the allocated buffer size. This incorrect validation leads to improper bounds checking, causing a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents into the produced image.

NVD description · AI analysis pending
4.4<1%
  • gimp gimp
  • gimp enterprise linux
CVE-2026-78465
+1 in the same advisory: …78475
Heap buffer overflow in GIMP PCX plugin on 32-bit builds

CVE-2026-78465 is an integer overflow (CWE-190) in GIMP's file-pcx plugin, limited to 32-bit builds of the application. When a user opens a crafted PCX image that declares 4 color planes with sufficiently large dimensions, the plugin's allocation-size calculation exceeds the 32-bit integer limit, producing an undersized heap buffer that is then overflowed as image data is written into it. Successful exploitation causes memory corruption that can lead to arbitrary code execution in the context of the GIMP process, or at minimum a crash/denial of service. Only users running 32-bit GIMP builds are affected, and because the CVSS vector is local (AV:L) with user interaction required (UI:R), an attacker needs the victim to open a malicious PCX file. Exploitation has not been reported in the wild; one public proof-of-concept/issue reference exists on the GNOME GitLab tracker, EPSS is a low 0.2%, and the issue is not in CISA KEV.

Do: Users of 32-bit GIMP builds should avoid opening untrusted PCX files until a patched release is available, and should watch the GNOME/GIMP tracker (issue 16578) and Red Hat/vendor advisories for the fix; 64-bit builds are not affected, so switching to a 64-bit build where the OS supports it fully mitigates the flaw. Admins should inventory which endpoints run 32-bit GIMP builds and prioritize those for remediation.

7.0
group max
<1% PoC
  • gimp (file-pcx plugin)
largeon the order of 100,000s of 32-bit GIMP installations (estimate)
CVE-2026-18307
GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability.

GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TIF files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29404.

NVD description · AI analysis pending
7.8<1%
  • gimp gimp