Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-40917

Опубликовано: 15 апр. 2026
Источник: nvd
CVSS3: 5
CVSS3: 7.1
EPSS Низкий

Описание

A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the icns_slurp() function, occurs when processing specially crafted ICNS image files. An attacker could provide a malicious ICNS file, potentially leading to application crashes or information disclosure on systems that process such files.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:gimp:gimp:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

EPSS

Процентиль: 6%
0.00167
Низкий

5 Medium

CVSS3

7.1 High

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 5
ubuntu
4 месяца назад

A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when processing specially crafted ICNS image files. An attacker could provide a malicious ICNS file, potentially leading to application crashes or information disclosure on systems that process such files.

CVSS3: 5
redhat
4 месяца назад

A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when processing specially crafted ICNS image files. An attacker could provide a malicious ICNS file, potentially leading to application crashes or information disclosure on systems that process such files.

CVSS3: 5
debian
4 месяца назад

A flaw was found in GIMP. This vulnerability, a heap buffer over-read ...

suse-cvrf
около 1 месяца назад

Security update for gimp

CVSS3: 5
github
4 месяца назад

A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when processing specially crafted ICNS image files. An attacker could provide a malicious ICNS file, potentially leading to application crashes or information disclosure on systems that process such files.

EPSS

Процентиль: 6%
0.00167
Низкий

5 Medium

CVSS3

7.1 High

CVSS3

Дефекты

CWE-125