FreshPorts - VuXML
This page displays vulnerability information about FreeBSD Ports.
The VUXML data was last processed by FreshPorts on 2025-06-06 18:03:49 UTC
List all Vulnerabilities, by package
List all Vulnerabilities, by date
k68
These are the vulnerabilities relating to the commit you have selected:
VuXML ID | Description |
da0a4374-3fc9-11f0-a39d-b42e991fc52e | Gimp -- GIMP XWD File Parsing Integer Overflow Remote Code Execution Vulnerability
zdi-disclosures@trendmicro.com reports:
GIMP XWD File Parsing Integer Overflow Remote Code Execution
Vulnerability. This vulnerability allows remote attackers to execute
arbitrary code on affected installations of GIMP. User interaction
is required to exploit this vulnerability in that the target must
visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of XWD files. The issue
results from the lack of proper validation of user-supplied data,
which can result in an integer overflow before allocating a buffer.
An attacker can leverage this vulnerability to execute code in the
context of the current process. Was ZDI-CAN-25082.
Discovery 2025-04-23 Entry 2025-06-02 gimp
< 3.0.0,2
CVE-2025-2760
https://nvd.nist.gov/vuln/detail/CVE-2025-2760
|
dc99c67a-3fc9-11f0-a39d-b42e991fc52e | Gimp -- GIMP FLI File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
zdi-disclosures@trendmicro.com reports:
GIMP FLI File Parsing Out-Of-Bounds Write Remote Code Execution
Vulnerability. This vulnerability allows remote attackers to execute
arbitrary code on affected installations of GIMP. User interaction
is required to exploit this vulnerability in that the target must
visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of FLI files. The issue
results from the lack of proper validation of user-supplied data,
which can result in a write past the end of an allocated buffer.
An attacker can leverage this vulnerability to execute code in the
context of the current process. Was ZDI-CAN-25100.
Discovery 2025-04-23 Entry 2025-06-02 gimp
< 3.0.0,2
CVE-2025-2761
https://nvd.nist.gov/vuln/detail/CVE-2025-2761
|