A vulnerability labeled as critical has been found in ImageMagick up to 6.9.13-27/7.1.2-1 on 32-bit. This vulnerability affects the function bytes_per_line. Executing manipulation can lead to heap-based buffer overflow.
This vulnerability appears as CVE-2025-57803. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
A vulnerability classified as problematic has been found in GitLab Community Edition and Enterprise Edition up to 18.2.7/18.3.3/18.4.1. Affected is an unknown function of the component HTTP Handler. Performing manipulation results in allocation of resources.
This vulnerability is identified as CVE-2025-2934. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in ImageMagick up to 6.9.13-27/7.1.2-1. It has been rated as problematic. This vulnerability affects the function GetGeometry. Performing manipulation of the argument width/height results in divide by zero.
This vulnerability is cataloged as CVE-2025-55212. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability described as critical has been identified in ImageMagick up to 6.9.13-27/7.1.2-1. This affects the function InterpretImageFilename. Such manipulation leads to write-what-where condition.
This vulnerability is traded as CVE-2025-55298. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability labeled as problematic has been found in GitLab Enterprise Edition up to 18.3.3/18.4.1. Affected is an unknown function of the component GraphQL Mutation Handler. Such manipulation leads to incorrect authorization.
This vulnerability is uniquely identified as CVE-2025-11340. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
A vulnerability marked as problematic has been reported in GitLab Community Edition and Enterprise Edition up to 18.2.7/18.3.3/18.4.1. Affected by this vulnerability is an unknown functionality of the component GraphQL Handler. Performing manipulation results in allocation of resources.
This vulnerability was named CVE-2025-10004. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
A vulnerability described as problematic has been identified in ImageMagick up to 6.9.13-31/7.1.2-6. Affected by this issue is some unknown functionality of the file coders/bmp.c. The manipulation of the argument extent results in integer overflow.
This vulnerability is identified as CVE-2025-62171. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
The U.S. Cybersecurity & Infrastructure Security Agency (CISA) is warning government agencies to patch an Oracle Identity Manager tracked as CVE-2025-61757 that has been exploited in attacks, potentially as a zero-day. [...]
Researchers Were Able to Query 3.5 Billion Accounts Security researchers were able to scoop up the telephone numbers of billions of WhatsApp users through an enumeration tool provided by app owner Meta. The sheer quantity of leaked numbers - 3.5 billion in total - would amount to "the largest data leak in history."