Back

CVE-2005-2976

Integer overflow in io-xpm.c in gdk-pixbuf 0.22.0 in GTK+ before 2.8.7 allows attackers to cause a denial of service (crash) or execute arbitrary code via an XPM file with large height, width, and colour values, a different vulnerability than CVE-2005-3186.

Published: Nov 18, 2005 Modified: Jun 16, 2026
CWE-190

CVSS Metrics

Affected Products (2)

Vendor Product Version
gnome gdkpixbuf 0.22
gnome gtk * < 2.8.7

GitHub Security Advisory GHSA-9hm7-qmgf-q88w

Integer overflow in io-xpm.c in gdk-pixbuf 0.22.0 in GTK+ before 2.8.7 allows attackers to cause...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 4.54%

Top 9% most likely to be exploited

Threat Score 31.4 / 100

Data Sources

NVD EPSS GitHub