VDB
CVE-2006-3404
CVE-2006-3404
PUBLISHED
CVSS 5.099999904632568 MEDIUM
Buffer overflow in the xcf_load_vector function in app/xcf/xcf-load.c for gimp before 2.2.12 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XCF file with a large num_axes value in the VECTORS property.
EPSS 4.61% · 91.0th percentile
Risk Scores
CVSS 2.0
5.099999904632568
EPSS Score
4.61%
91.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| gimp | gimp | 0 |
Timeline
- Jul 6, 2006 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
References
- 200070 vendor-advisory
- 20060724 Re: [ GLSA 200607-08 ] GIMP: Buffer overflow mailing-list
- https://issues.rpath.com/browse/RPL-522 url
- ADV-2006-2703 vdb
- RHSA-2006:0598 vendor-advisory
- ADV-2006-4634 vdb
- oval:org.mitre.oval:def:5908 vdb
- 21198 third-party-advisory
- MDKSA-2006:127 vendor-advisory
- 20060724 rPSA-2006-0135-1 gimp mailing-list
- gimp-xcfloadvector-bo(27687) vdb
- 1016527 vdb
- 27037 vdb
- 102720 vendor-advisory
- 21182 third-party-advisory
- 20060724 ERRATA: [ GLSA 200607-08 ] GIMP: Buffer overflow mailing-list
- 18877 vdb
- GLSA-200607-08 vendor-advisory
- 21459 third-party-advisory
- SUSE-SR:2006:019 vendor-advisory
…and 12 more