Skip to main content

Vendor/product archive

google / tensorflow CVEs

Beta · best-effort

431 CVEs tagged to google / tensorflow7 Critical, 110 High, 215 Medium, 99 Low, 0 Unrated.

CVE-2022-21734

Published Feb 3, 2022

Tensorflow is an Open Source Machine Learning Framework. The implementation of `MapStage` is vulnerable a `CHECK`-fail if the key tensor is not a scalar. The fix will be included…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-21729

Published Feb 3, 2022

Tensorflow is an Open Source Machine Learning Framework. The implementation of `UnravelIndex` is vulnerable to a division by zero caused by an integer overflow bug. The fix will b…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-21725

Published Feb 3, 2022

Tensorflow is an Open Source Machine Learning Framework. The estimator for the cost of some convolution operations can be made to execute a division by 0. The function fails to ch…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23568

Published Feb 3, 2022

Tensorflow is an Open Source Machine Learning Framework. The implementation of `AddManySparseToTensorsMap` is vulnerable to an integer overflow which results in a `CHECK`-fail whe…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23567

Published Feb 3, 2022

Tensorflow is an Open Source Machine Learning Framework. The implementations of `Sparse*Cwise*` ops are vulnerable to integer overflows. These can be used to trigger large allocat…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-21736

Published Feb 3, 2022

Tensorflow is an Open Source Machine Learning Framework. The implementation of `SparseTensorSliceDataset` has an undefined behavior: under certain condition it can be made to dere…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2022-21733

Published Feb 3, 2022

Tensorflow is an Open Source Machine Learning Framework. The implementation of `StringNGrams` can be used to trigger a denial of service attack by causing an out of memory conditi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-21732

Published Feb 3, 2022

Tensorflow is an Open Source Machine Learning Framework. The implementation of `ThreadPoolHandle` can be used to trigger a denial of service attack by allocating too much memory.…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-21731

Published Feb 3, 2022

Tensorflow is an Open Source Machine Learning Framework. The implementation of shape inference for `ConcatV2` can be used to trigger a denial of service attack via a segfault caus…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-21730

Published Feb 3, 2022

Tensorflow is an Open Source Machine Learning Framework. The implementation of `FractionalAvgPoolGrad` does not consider cases where the input tensors are invalid allowing an atta…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-21728

Published Feb 3, 2022

Tensorflow is an Open Source Machine Learning Framework. The implementation of shape inference for `ReverseSequence` does not fully validate the value of `batch_dim` and can resul…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-21727

Published Feb 3, 2022

Tensorflow is an Open Source Machine Learning Framework. The implementation of shape inference for `Dequantize` is vulnerable to an integer overflow weakness. The `axis` argument…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2022-21726

Published Feb 3, 2022

Tensorflow is an Open Source Machine Learning Framework. The implementation of `Dequantize` does not fully validate the value of `axis` and can result in heap OOB accesses. The `a…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41228

Published Nov 5, 2021

TensorFlow is an open source platform for machine learning. In affected versions TensorFlow's `saved_model_cli` tool is vulnerable to a code injection as it calls `eval` on user s…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41227

Published Nov 5, 2021

TensorFlow is an open source platform for machine learning. In affected versions the `ImmutableConst` operation in TensorFlow can be tricked into reading arbitrary memory contents…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41225

Published Nov 5, 2021

TensorFlow is an open source platform for machine learning. In affected versions TensorFlow's Grappler optimizer has a use of unitialized variable. If the `train_nodes` vector (ob…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41222

Published Nov 5, 2021

TensorFlow is an open source platform for machine learning. In affected versions the implementation of `SplitV` can trigger a segfault is an attacker supplies negative arguments.…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41221

Published Nov 5, 2021

TensorFlow is an open source platform for machine learning. In affected versions the shape inference code for the `Cudnn*` operations in TensorFlow can be tricked into accessing i…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41220

Published Nov 5, 2021

TensorFlow is an open source platform for machine learning. In affected versions the async implementation of `CollectiveReduceV2` suffers from a memory leak and a use after free.…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41216

Published Nov 5, 2021

TensorFlow is an open source platform for machine learning. In affected versions the shape inference function for `Transpose` is vulnerable to a heap buffer overflow. This occurs…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41213

Published Nov 5, 2021

TensorFlow is an open source platform for machine learning. In affected versions the code behind `tf.function` API can be made to deadlock when two `tf.function` decorated Python…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41218

Published Nov 5, 2021

TensorFlow is an open source platform for machine learning. In affected versions the shape inference code for `AllToAll` can be made to execute a division by 0. This occurs whenev…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41209

Published Nov 5, 2021

TensorFlow is an open source platform for machine learning. In affected versions the implementations for convolution operators trigger a division by 0 if passed empty filter tenso…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41208

Published Nov 5, 2021

TensorFlow is an open source platform for machine learning. In affected versions the code for boosted trees in TensorFlow is still missing validation. As a result, attackers can t…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41207

Published Nov 5, 2021

TensorFlow is an open source platform for machine learning. In affected versions the implementation of `ParallelConcat` misses some input validation and can produce a division by…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 176-200 of 431 CVEsPage 8 of 18