Vulnerabilities > Gimp > High

DATE CVE VULNERABILITY TITLE RISK
2021-12-23 CVE-2021-45463 load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered.
local
low complexity
gegl gimp redhat fedoraproject
7.8
2016-07-12 CVE-2016-4994 Use After Free vulnerability in Gimp
Use-after-free vulnerability in the xcf_load_image function in app/xcf/xcf-load.c in GIMP allows remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted XCF file.
local
low complexity
gimp CWE-416
7.8
2012-07-12 CVE-2012-2763 Classic Buffer Overflow vulnerability in Gimp
Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, allows remote attackers to execute arbitrary code via a long string in a command to the script-fu server.
network
low complexity
gimp CWE-120
7.5