Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 33 min
Buscando: "Gimp" — 6 resultados ✕ Limpiar búsqueda
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1009
Esta semana
RSS
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106062] A heap-based buffer overflow was found in GIMP’s DirectDraw Surface (DDS) loader. When loading a cra…
A heap-based buffer overflow was found in GIMP’s DirectDraw Surface (DDS) loader. When loading a crafted DDS image, buffer sizes derived from width, height, and pitch can be computed using 32-bit arithmetic that overflows. The allocated buffer is too small for the amount of pixel data written through GEGL (CWE-787), following integer overflow in size calculations (CWE-190). This may allow heap cor…
M Alto vulnerabilidad
24/09/2026
Vulnerabilidad alta en GIMP: ejecución de código remoto mediante archivos GIMPressionist
Se identificó una falla en el procesamiento de archivos de preajustes GIMPressionist en GIMP que permite escritura fuera de límites de memoria. Un atacante podría distribuir archivos maliciosos disfrazados de preajustes legítimos, logrando corrupción de memoria, bloqueos del sistema o ejecución de código arbitrario en equipos de diseñadores y desarrolladores en empresas LATAM. El CVSS 7.8 indica riesgo alto con exposición práctica.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92248] A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially…
A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header. This leads to an undersized heap allocation, resulting in a heap-based buffer overflow when the image data is decoded. This buffer overflow corrupts adjacent hea…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90947] A flaw was found in GIMP. When processing a specially crafted lighting preset file, the Lighting Eff…
A flaw was found in GIMP. When processing a specially crafted lighting preset file, the Lighting Effects filter does not properly validate the number of light sources. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by convincing a user to open a malicious preset file, potentially causing a crash or enabling arbitrary code execution.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90948] A flaw was found in GIMP's ICO file loader. When processing an ICO file containing an embedded PNG i…
A flaw was found in GIMP's ICO file loader. When processing an ICO file containing an embedded PNG image, an integer overflow can occur during the calculation of the required buffer size. This leads to an undersized buffer being allocated, causing a heap-based buffer overflow when the decoded pixel data is written. A remote attacker could exploit this by crafting a malicious ICO file, which, when …
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90949] A flaw was found in GIMP's PSP (Paint Shop Pro) file loader. When processing a compressed selection …
A flaw was found in GIMP's PSP (Paint Shop Pro) file loader. When processing a compressed selection channel, a heap-based buffer overflow can occur due to a mismatch between the allocated buffer size and the amount of data decompressed. A remote attacker could exploit this vulnerability by crafting a malicious PSP file. Opening this file in GIMP could lead to a crash or arbitrary code execution.