Skip to main content

Vendor/product archive

google / tensorflow CVEs

Beta · best-effort

431 CVEs tagged to google / tensorflow7 Critical, 110 High, 215 Medium, 99 Low, 0 Unrated.

CVE-2022-23577

Published Feb 4, 2022

Tensorflow is an Open Source Machine Learning Framework. The implementation of `GetInitOp` is vulnerable to a crash caused by dereferencing a null pointer. The fix will be include…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23576

Published Feb 4, 2022

Tensorflow is an Open Source Machine Learning Framework. The implementation of `OpLevelCostEstimator::CalculateOutputSize` is vulnerable to an integer overflow if an attacker can…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23575

Published Feb 4, 2022

Tensorflow is an Open Source Machine Learning Framework. The implementation of `OpLevelCostEstimator::CalculateTensorSize` is vulnerable to an integer overflow if an attacker can…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23574

Published Feb 4, 2022

Tensorflow is an Open Source Machine Learning Framework. There is a typo in TensorFlow's `SpecializeType` which results in heap OOB read/write. Due to a typo, `arg` is initialized…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23573

Published Feb 4, 2022

Tensorflow is an Open Source Machine Learning Framework. The implementation of `AssignOp` can result in copying uninitialized data to a new tensor. This later results in undefined…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23572

Published Feb 4, 2022

Tensorflow is an Open Source Machine Learning Framework. Under certain scenarios, TensorFlow can fail to specialize a type during shape inference. This case is covered by the `DCH…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23571

Published Feb 4, 2022

Tensorflow is an Open Source Machine Learning Framework. When decoding a tensor from protobuf, a TensorFlow process can encounter cases where a `CHECK` assertion is invalidated ba…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23570

Published Feb 4, 2022

Tensorflow is an Open Source Machine Learning Framework. When decoding a tensor from protobuf, TensorFlow might do a null-dereference if attributes of some mutable arguments to so…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23566

Published Feb 4, 2022

Tensorflow is an Open Source Machine Learning Framework. TensorFlow is vulnerable to a heap OOB write in `Grappler`. The `set_output` function writes to an array at the specified…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23565

Published Feb 4, 2022

Tensorflow is an Open Source Machine Learning Framework. An attacker can trigger denial of service via assertion failure by altering a `SavedModel` on disk such that `AttrDef`s of…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23564

Published Feb 4, 2022

Tensorflow is an Open Source Machine Learning Framework. When decoding a resource handle tensor from protobuf, a TensorFlow process can encounter cases where a `CHECK` assertion i…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23563

Published Feb 4, 2022

Tensorflow is an Open Source Machine Learning Framework. In multiple places, TensorFlow uses `tempfile.mktemp` to create temporary files. While this is acceptable in testing, in u…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23562

Published Feb 4, 2022

Tensorflow is an Open Source Machine Learning Framework. The implementation of `Range` suffers from integer overflows. These can trigger undefined behavior or, in some scenarios,…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23561

Published Feb 4, 2022

Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would cause a write outside of bounds of an array in TFLite. In fact, the attack…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23560

Published Feb 4, 2022

Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would allow limited reads and writes outside of arrays in TFLite. This exploits…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23559

Published Feb 4, 2022

Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would cause an integer overflow in embedding lookup operations. Both `embedding_…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23558

Published Feb 4, 2022

Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would cause an integer overflow in `TfLiteIntArrayCreate`. The `TfLiteIntArrayGe…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23557

Published Feb 4, 2022

Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would trigger a division by zero in `BiasAndClamp` implementation. There is no c…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-21741

Published Feb 3, 2022

Tensorflow is an Open Source Machine Learning Framework. ### Impact An attacker can craft a TFLite model that would trigger a division by zero in the implementation of depthwise c…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-21740

Published Feb 3, 2022

Tensorflow is an Open Source Machine Learning Framework. The implementation of `SparseCountSparseOutput` is vulnerable to a heap overflow. The fix will be included in TensorFlow 2…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2022-21739

Published Feb 3, 2022

Tensorflow is an Open Source Machine Learning Framework. The implementation of `QuantizedMaxPool` has an undefined behavior where user controlled inputs can trigger a reference bi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-21738

Published Feb 3, 2022

Tensorflow is an Open Source Machine Learning Framework. The implementation of `SparseCountSparseOutput` can be made to crash a TensorFlow process by an integer overflow whose res…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-21737

Published Feb 3, 2022

Tensorflow is an Open Source Machine Learning Framework. The implementation of `*Bincount` operations allows malicious users to cause denial of service by passing in arguments whi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23569

Published Feb 3, 2022

Tensorflow is an Open Source Machine Learning Framework. Multiple operations in TensorFlow can be used to trigger a denial of service via `CHECK`-fails (i.e., assertion failures).…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-21735

Published Feb 3, 2022

Tensorflow is an Open Source Machine Learning Framework. The implementation of `FractionalMaxPool` can be made to crash a TensorFlow process via a division by 0. The fix will be i…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 151-175 of 431 CVEsPage 7 of 18