← Vulnerability feed

Vulnerability record · CVE-2005-3186 · published 18 November 2005

CVE-2005-3186: Gnome gdkpixbuf vulnerability

Gnome · Gdkpixbuf

Integer overflow in the GTK+ gdk-pixbuf XPM image rendering library in GTK+ 2.4.0 allows attackers to execute arbitrary code via an XPM file with a number of colors that causes insufficient memory to be allocated, which leads to a heap-based buffer overflow.

7.5 CVSS 2.0 High EPSS 4.7% · top 8.6%
7.5CVSS 2.0 base score
4.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
60References
16 Jun 2026Last modified by NVD

Description

Integer overflow in the GTK+ gdk-pixbuf XPM image rendering library in GTK+ 2.4.0 allows attackers to execute arbitrary code via an XPM file with a number of colors that causes insufficient memory to be allocated, which leads to a heap-based buffer overflow.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.8/SCOSA-2006.8.txt
http://secunia.com/advisories/17522
http://secunia.com/advisories/17538
http://secunia.com/advisories/17562
http://secunia.com/advisories/17588
http://secunia.com/advisories/17591
http://secunia.com/advisories/17592
http://secunia.com/advisories/17594
http://secunia.com/advisories/17615
http://secunia.com/advisories/17657
http://secunia.com/advisories/17710
http://secunia.com/advisories/17770
http://secunia.com/advisories/17791
http://secunia.com/advisories/18509
http://securityreason.com/securityalert/188
http://securitytracker.com/id?1015216
http://support.avaya.com/elmodocs2/security/ASA-2005-229.pdf
http://www.debian.org/security/2005/dsa-911
http://www.debian.org/security/2005/dsa-913
http://www.gentoo.org/security/en/glsa/glsa-200511-14.xml
http://www.idefense.com/application/poi/display?id=339&type=vulnerabilities PatchVendor Advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2005:214
http://www.novell.com/linux/security/advisories/2005_65_gtk2.html
http://www.redhat.com/support/errata/RHSA-2005-810.html PatchVendor Advisory
http://www.redhat.com/support/errata/RHSA-2005-811.html
http://www.securityfocus.com/archive/1/428052/100/0/threaded
http://www.securityfocus.com/bid/15435
http://www.ubuntu.com/usn/usn-216-1
http://www.vupen.com/english/advisories/2005/2433
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9503
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.8/SCOSA-2006.8.txt
http://secunia.com/advisories/17522
http://secunia.com/advisories/17538
http://secunia.com/advisories/17562
http://secunia.com/advisories/17588
http://secunia.com/advisories/17591
http://secunia.com/advisories/17592
http://secunia.com/advisories/17594
http://secunia.com/advisories/17615
http://secunia.com/advisories/17657

Track CVE-2005-3186 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2021-44648Gnome gdkpixbuf out-of-bounds write vulnerabilityGNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability when decoding the lzw compressed stream of image data in GIF files with…EPSS 1.9%7.8CVE-2022-48622Gnome gdkpixbuf out-of-bounds write vulnerabilityIn GNOME GdkPixbuf (aka gdk-pixbuf) through 2.42.10, the ANI (Windows animated cursor) decoder encounters heap memory corruption (in ani_load_chunk i…EPSS 0.42%7.8CVE-2005-2975Gnome gdkpixbuf vulnerabilityio-xpm.c in the gdk-pixbuf XPM image rendering library in GTK+ before 2.8.7 allows attackers to cause a denial of service (infinite loop) via a craft…EPSS 3.7%7.5CVE-2005-2976Gnome gdkpixbuf integer overflow vulnerabilityInteger overflow in io-xpm.c in gdk-pixbuf 0.22.0 in GTK+ before 2.8.7 allows attackers to cause a denial of service (crash) or execute arbitrary cod…EPSS 4.5%7.5CVE-2004-0782Gnome gdkpixbuf vulnerabilityInteger overflow in pixbuf_create_from_xpm (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, allows …EPSS 9.2%7.5CVE-2004-0783Gnome gdkpixbuf out-of-bounds write vulnerabilityStack-based buffer overflow in xpm_extract_color (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, m…EPSS 9.4%5.0CVE-2004-0753Gnome gdkpixbuf vulnerabilityThe BMP image processor for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attackers to cause a denial of service (infinite loop)…EPSS 5.9%5.0CVE-2004-0788Gnome gdkpixbuf integer overflow vulnerabilityInteger overflow in the ICO image decoder for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attackers to cause a denial of servi…EPSS 5.9%

Source: NIST National Vulnerability Database (record CVE-2005-3186), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.