<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 18:21:12 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-11394</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-11394</link>
      <description>bdu:2026-11394</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-11394</guid>
    </item>
    <item>
      <title>EUVD-2026-358228</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-358228</link>
      <description>EUVD-2026-358228</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-358228</guid>
    </item>
    <item>
      <title>fkie_cve-2026-59087</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59087</link>
      <description>&lt;p&gt;A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader. A remote attacker could exploit this vulnerability by tricking a user into opening a specially crafted Seattle Filmworks file. This could lead to a heap overflow, allowing the attacker to write several kilobytes of controlled data beyond the intended memory buffer. Such an overflow can result in memory corruption, potentially leading to arbitrary code execution or a denial of service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader. A remote attacker could exploit this vulnerability by tricking a user into opening a specially crafted Seattle Filmworks file. This could lead to a heap overflow, allowing the attacker to write several kilobytes of controlled data beyond the intended memory buffer. Such an overflow can result in memory corruption, potentially leading to arbitrary code execution or a denial of service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-59087</guid>
    </item>
    <item>
      <title>GHSA-hh4m-xc2h-qj94</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hh4m-xc2h-qj94</link>
      <description>&lt;p&gt;A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader. A remote attacker could exploit this vulnerability by tricking a user into opening a specially crafted Seattle Filmworks file. This could lead to a heap overflow, allowing the attacker to write several kilobytes of controlled data beyond the intended memory buffer. Such an overflow can result in memory corruption, potentially leading to arbitrary code execution or a denial of service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader. A remote attacker could exploit this vulnerability by tricking a user into opening a specially crafted Seattle Filmworks file. This could lead to a heap overflow, allowing the attacker to write several kilobytes of controlled data beyond the intended memory buffer. Such an overflow can result in memory corruption, potentially leading to arbitrary code execution or a denial of service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hh4m-xc2h-qj94</guid>
    </item>
    <item>
      <title>OESA-2026-3245 — gimp security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3245</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP4: gimp&lt;/p&gt;
&lt;p&gt;GIMP is a cross-platform image editor available for GNU/Linux, OS X, Windows and more operating systems. It is free software, you can change its source code and distribute your changes. Whether you are a graphic designer, photographer, illustrator, or scientist, GIMP provides you with sophisticated tools to get your job done. You can further enhance your productivity with GIMP thanks to many customization options and 3rd party plugins.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;(CVE-2026-59087)&lt;/p&gt;
&lt;p&gt;(CVE-2026-59088)&lt;/p&gt;
&lt;p&gt;A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memory for a row table. The image header dimensions (ysize and zsize) are read as 16-bit unsigned integers. If a crafted file sets both dimensions to their maximum value (65535), the multiplication ysize * zsize overflows the standard 32-bit int boundary before being passed to calloc. This integer overflow issue results in undefined behavior, aborting the plugin and causing a denial of service.(CVE-2026-66757)&lt;/p&gt;
&lt;p&gt;A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when cfitsio subsequently writes a full row of pixels in the buffer, c…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP4: gimp&lt;/p&gt;
&lt;p&gt;GIMP is a cross-platform image editor available for GNU/Linux, OS X, Windows and more operating systems. It is free software, you can change its source code and distribute your changes. Whether you are a graphic designer, photographer, illustrator, or scientist, GIMP provides you with sophisticated tools to get your job done. You can further enhance your productivity with GIMP thanks to many customization options and 3rd party plugins.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;(CVE-2026-59087)&lt;/p&gt;
&lt;p&gt;(CVE-2026-59088)&lt;/p&gt;
&lt;p&gt;A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memory for a row table. The image header dimensions (ysize and zsize) are read as 16-bit unsigned integers. If a crafted file sets both dimensions to their maximum value (65535), the multiplication ysize * zsize overflows the standard 32-bit int boundary before being passed to calloc. This integer overflow issue results in undefined behavior, aborting the plugin and causing a denial of service.(CVE-2026-66757)&lt;/p&gt;
&lt;p&gt;A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when cfitsio subsequently writes a full row of pixels in the buffer, c…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3245</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11547-1 — gimp-3.2.4-4.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11547-1</link>
      <description>&lt;p&gt;gimp-3.2.4-4.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;gimp-3.2.4-4.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11547-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-59087</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59087</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: gimp, Ubuntu:Pro:18.04:LTS: gimp, Ubuntu:Pro:20.04:LTS: gimp, Ubuntu:Pro:22.04:LTS: gimp, Ubuntu:Pro:24.04:LTS: gimp, Ubuntu:26.04:LTS: gimp&lt;/p&gt;
&lt;p&gt;A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader. A remote attacker could exploit this vulnerability by tricking a user into opening a specially crafted Seattle Filmworks file. This could lead to a heap overflow, allowing the attacker to write several kilobytes of controlled data beyond the intended memory buffer. Such an overflow can result in memory corruption, potentially leading to arbitrary code execution or a denial of service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: gimp, Ubuntu:Pro:18.04:LTS: gimp, Ubuntu:Pro:20.04:LTS: gimp, Ubuntu:Pro:22.04:LTS: gimp, Ubuntu:Pro:24.04:LTS: gimp, Ubuntu:26.04:LTS: gimp&lt;/p&gt;
&lt;p&gt;A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader. A remote attacker could exploit this vulnerability by tricking a user into opening a specially crafted Seattle Filmworks file. This could lead to a heap overflow, allowing the attacker to write several kilobytes of controlled data beyond the intended memory buffer. Such an overflow can result in memory corruption, potentially leading to arbitrary code execution or a denial of service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59087</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2731 — GIMP: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2731</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in GIMP ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen und einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in GIMP ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen und einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2731</guid>
    </item>
  </channel>
</rss>
