Back
CVE-2005-2976
Integer overflow in io-xpm.c in gdk-pixbuf 0.22.0 in GTK+ before 2.8.7 allows attackers to cause a denial of service (crash) or execute arbitrary code via an XPM file with large height, width, and colour values, a different vulnerability than CVE-2005-3186.
Published: Nov 18, 2005
Modified: Jun 16, 2026
CWE-190
CVSS Metrics
Affected Products (2)
| Vendor | Product | Version |
|---|---|---|
| gnome | gdkpixbuf | 0.22 |
| gnome | gtk | * < 2.8.7 |
GitHub Security Advisory GHSA-9hm7-qmgf-q88w
Integer overflow in io-xpm.c in gdk-pixbuf 0.22.0 in GTK+ before 2.8.7 allows attackers to cause...
References (46)
- http://secunia.com/advisories/17522 Vendor Advisory
- http://secunia.com/advisories/17538 Vendor Advisory
- http://secunia.com/advisories/17562 Vendor Advisory
- http://secunia.com/advisories/17592 Vendor Advisory
- http://secunia.com/advisories/17594 Vendor Advisory
- http://secunia.com/advisories/17615 Vendor Advisory
- http://secunia.com/advisories/17657 Vendor Advisory
- http://secunia.com/advisories/17710 Vendor Advisory
- http://secunia.com/advisories/17770 Vendor Advisory
- http://secunia.com/advisories/17791 Vendor Advisory
- http://securitytracker.com/id?1015216 Third Party Advisory, VDB Entry
- http://support.avaya.com/elmodocs2/security/ASA-2005-229.pdf Third Party Advisory
- http://www.debian.org/security/2005/dsa-911 Third Party Advisory
- http://www.debian.org/security/2005/dsa-913 Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200511-14.xml Third Party Advisory
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
4.54%
Top 9% most likely to be exploited
Threat Score
31.4 / 100
Data Sources
NVD
EPSS
GitHub