Package impact

python PyPI / tensorflow

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2022-36012 unknown 4y ago TensorFlow vulnerable to assertion fail on MLIR empty edge names
CVE-2022-35987 unknown 4y ago TensorFlow vulnerable to `CHECK` fail in `DenseBincount`
CVE-2022-35941 unknown 4y ago TensorFlow vulnerable to `CHECK` failure in `AvgPoolOp`
CVE-2022-36026 unknown 4y ago TensorFlow vulnerable to `CHECK` fail in `QuantizeAndDequantizeV3`
CVE-2022-36018 unknown 4y ago TensorFlow vulnerable to `CHECK` fail in `RaggedTensorToVariant`
CVE-2022-36019 unknown 4y ago TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVarsPerChannel`
CVE-2022-36027 unknown 4y ago TensorFlow is an open source platform for machine learning. When converting transposed convolutions using per-channel weight quantization the converter segfaults and crashes the Python process. We ha…
CVE-2022-35939 unknown 4y ago TensorFlow vulnerable to OOB write in `scatter_nd` in TF Lite
CVE-2022-35937 unknown 4y ago TensorFlow vulnerable to OOB read in `Gather_nd` in TF Lite
CVE-2022-35934 unknown 4y ago TensorFlow vulnerable to `CHECK` failure in tf.reshape via overflows
CVE-2022-35935 unknown 4y ago TensorFlow vulnerable to `CHECK` failure in `SobolSample` via missing validation
CVE-2022-35997 unknown 4y ago TensorFlow vulnerable to `CHECK` fail in `tf.sparse.cross`
CVE-2022-35999 unknown 4y ago TensorFlow is an open source platform for machine learning. When `Conv2DBackpropInput` receives empty `out_backprop` inputs (e.g. `[3, 1, 0, 1]`), the current CPU/GPU kernels `CHECK` fail (one with d…
CVE-2022-29216 unknown 4y ago TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, TensorFlow's `saved_model_cli` tool is vulnerable to a code injection. This can be used t…
CVE-2022-29213 unknown 4y ago TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the `tf.compat.v1.signal.rfft2d` and `tf.compat.v1.signal.rfft3d` lack input validation a…
CVE-2022-29212 unknown 4y ago Core dump when loading TFLite models with quantization in TensorFlow
CVE-2022-29211 unknown 4y ago Segfault if `tf.histogram_fixed_width` is called with NaN values in TensorFlow
CVE-2022-29210 unknown 4y ago Heap buffer overflow due to incorrect hash function in TensorFlow
CVE-2022-29209 unknown 4y ago Type confusion leading to `CHECK`-failure based denial of service in TensorFlow
CVE-2022-29208 unknown 4y ago TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.EditDistance` has incomplete validation. Users can pass…
CVE-2022-29207 unknown 4y ago TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, multiple TensorFlow operations misbehave in eager mode when the resource handle provided …
CVE-2022-29206 unknown 4y ago Missing validation results in undefined behavior in `SparseTensorDenseAdd
CVE-2022-29205 unknown 4y ago TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, there is a potential for segfault / denial of service in TensorFlow by calling `tf.compat…
CVE-2022-29204 unknown 4y ago Missing validation causes denial of service via `Conv3DBackpropFilterV2`
CVE-2022-29203 unknown 4y ago Integer overflow in `SpaceToBatchND`
CVE-2022-29202 unknown 4y ago Denial of service in `tf.ragged.constant` due to lack of validation
CVE-2022-29201 unknown 4y ago Missing validation results in undefined behavior in `QuantizedConv2D`
CVE-2022-29200 unknown 4y ago TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.LSTMBlockCell` does not fully validate the input argume…
CVE-2022-29199 unknown 4y ago Missing validation causes denial of service via `LoadAndRemapMatrix`
CVE-2022-29198 unknown 4y ago Missing validation causes denial of service via `SparseTensorToCSRSparseMatrix`
CVE-2022-29197 unknown 4y ago Missing validation causes denial of service via `UnsortedSegmentJoin`
CVE-2022-29196 unknown 4y ago TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.Conv3DBackpropFilterV2` does not fully validate the inp…
CVE-2022-29195 unknown 4y ago Missing validation causes denial of service via `StagePeek`
CVE-2022-29194 unknown 4y ago Missing validation causes denial of service via `DeleteSessionTensor`
CVE-2022-29192 unknown 4y ago Missing validation crashes `QuantizeAndDequantizeV4Grad`
CVE-2022-29191 unknown 4y ago Missing validation causes denial of service via `GetSessionTensor`
CVE-2022-29193 unknown 4y ago TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.TensorSummaryV2` does not fully validate the input argu…
CVE-2022-23583 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a denial of service by altering a `SavedModel` such that any binary op would trigger `CHECK` failures. This occurs …
CVE-2022-23582 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a denial of service by altering a `SavedModel` such that `TensorByteSize` would trigger `CHECK` failures. `TensorSh…
CVE-2022-23579 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The Grappler optimizer in TensorFlow can be used to cause a denial of service by altering a `SavedModel` such that `SafeToRemoveIdentity` woul…
CVE-2022-23578 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. If a graph node is invalid, TensorFlow can leak memory in the implementation of `ImmutableExecutorState::Initialize`. Here, we set `item->kern…
CVE-2022-23575 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of `OpLevelCostEstimator::CalculateTensorSize` is vulnerable to an integer overflow if an attacker can create an operation …
CVE-2022-23576 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of `OpLevelCostEstimator::CalculateOutputSize` is vulnerable to an integer overflow if an attacker can create an operation …
CVE-2022-23577 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of `GetInitOp` is vulnerable to a crash caused by dereferencing a null pointer. The fix will be included in TensorFlow 2.8.…
CVE-2022-21735 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of `FractionalMaxPool` can be made to crash a TensorFlow process via a division by 0. The fix will be included in TensorFlo…
CVE-2022-21734 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of `MapStage` is vulnerable a `CHECK`-fail if the key tensor is not a scalar. The fix will be included in TensorFlow 2.8.0.…
CVE-2022-21733 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of `StringNGrams` can be used to trigger a denial of service attack by causing an out of memory condition after an integer …
CVE-2022-21732 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of `ThreadPoolHandle` can be used to trigger a denial of service attack by allocating too much memory. This is because the …
CVE-2022-21731 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of shape inference for `ConcatV2` can be used to trigger a denial of service attack via a segfault caused by a type confusi…
CVE-2022-21729 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of `UnravelIndex` is vulnerable to a division by zero caused by an integer overflow bug. The fix will be included in Tensor…
CVE-2022-21725 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The estimator for the cost of some convolution operations can be made to execute a division by 0. The function fails to check that the stride …
CVE-2022-23584 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a use after free behavior when decoding PNG images. After `png::CommonFreeDecode(&decode)` gets called, the values …
CVE-2022-23566 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. TensorFlow is vulnerable to a heap OOB write in `Grappler`. The `set_output` function writes to an array at the specified index. Hence, this g…
CVE-2022-23564 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. When decoding a resource handle tensor from protobuf, a TensorFlow process can encounter cases where a `CHECK` assertion is invalidated based …
CVE-2022-23563 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. In multiple places, TensorFlow uses `tempfile.mktemp` to create temporary files. While this is acceptable in testing, in utilities and librari…
CVE-2022-23562 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of `Range` suffers from integer overflows. These can trigger undefined behavior or, in some scenarios, extremely large allo…
CVE-2022-23561 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would cause a write outside of bounds of an array in TFLite. In fact, the attacker can override the …
CVE-2022-23560 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would allow limited reads and writes outside of arrays in TFLite. This exploits missing validation i…
CVE-2022-23559 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would cause an integer overflow in embedding lookup operations. Both `embedding_size` and `lookup_si…
CVE-2022-23558 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would cause an integer overflow in `TfLiteIntArrayCreate`. The `TfLiteIntArrayGetSizeInBytes` return…
CVE-2022-23565 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. An attacker can trigger denial of service via assertion failure by altering a `SavedModel` on disk such that `AttrDef`s of some operation are …
CVE-2022-23557 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would trigger a division by zero in `BiasAndClamp` implementation. There is no check that the `bias_…
CVE-2022-21741 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. ### Impact An attacker can craft a TFLite model that would trigger a division by zero in the implementation of depthwise convolutions. The par…
CVE-2022-21740 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of `SparseCountSparseOutput` is vulnerable to a heap overflow. The fix will be included in TensorFlow 2.8.0. We will also c…
CVE-2022-21739 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of `QuantizedMaxPool` has an undefined behavior where user controlled inputs can trigger a reference binding to null pointe…
CVE-2022-21738 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of `SparseCountSparseOutput` can be made to crash a TensorFlow process by an integer overflow whose result is then used in …
CVE-2022-21737 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of `*Bincount` operations allows malicious users to cause denial of service by passing in arguments which would trigger a `…
CVE-2022-21736 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of `SparseTensorSliceDataset` has an undefined behavior: under certain condition it can be made to dereference a `nullptr` …
CVE-2022-23567 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementations of `Sparse*Cwise*` ops are vulnerable to integer overflows. These can be used to trigger large allocations (so, OOM based …
CVE-2022-23568 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of `AddManySparseToTensorsMap` is vulnerable to an integer overflow which results in a `CHECK`-fail when building new `Tens…
CVE-2022-23569 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. Multiple operations in TensorFlow can be used to trigger a denial of service via `CHECK`-fails (i.e., assertion failures). This is similar to …
CVE-2022-23570 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. When decoding a tensor from protobuf, TensorFlow might do a null-dereference if attributes of some mutable arguments to some operations are mi…
CVE-2022-23595 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. When building an XLA compilation cache, if default settings are used, TensorFlow triggers a null pointer dereference. In the default scenario,…
CVE-2022-23594 unknown 4y ago Out of bounds read in Tensorflow
CVE-2022-23593 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The `simplifyBroadcast` function in the MLIR-TFRT infrastructure in TensorFlow is vulnerable to a segfault (hence, denial of service), if call…
CVE-2022-23592 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. TensorFlow's type inference can cause a heap out of bounds read as the bounds checking is done in a `DCHECK` (which is a no-op during producti…
CVE-2022-23591 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The `GraphDef` format in TensorFlow does not allow self recursive functions. The runtime assumes that this invariant is satisfied. However, a …
CVE-2022-23590 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. A `GraphDef` from a TensorFlow `SavedModel` can be maliciously altered to cause a TensorFlow process to crash due to encountering a `StatusOr`…
CVE-2022-23589 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. Under certain scenarios, Grappler component of TensorFlow can trigger a null pointer dereference. There are 2 places where this can occur, for…
CVE-2022-23571 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. When decoding a tensor from protobuf, a TensorFlow process can encounter cases where a `CHECK` assertion is invalidated based on user controll…
CVE-2022-23572 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. Under certain scenarios, TensorFlow can fail to specialize a type during shape inference. This case is covered by the `DCHECK` function howeve…
CVE-2022-23588 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a denial of service by altering a `SavedModel` such that Grappler optimizer would attempt to build a tensor using a…
CVE-2022-23587 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. Under certain scenarios, Grappler component of TensorFlow is vulnerable to an integer overflow during cost estimation for crop and resize. Sin…
CVE-2022-23586 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a denial of service by altering a `SavedModel` such that assertions in `function.cc` would be falsified and crash t…
CVE-2022-23573 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of `AssignOp` can result in copying uninitialized data to a new tensor. This later results in undefined behavior. The imple…
CVE-2022-23585 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. When decoding PNG images TensorFlow can produce a memory leak if the image is invalid. After calling `png::CommonInitDecode(..., &decode)`, th…
CVE-2022-23574 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. There is a typo in TensorFlow's `SpecializeType` which results in heap OOB read/write. Due to a typo, `arg` is initialized to the `i`th mutabl…
CVE-2022-21730 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of `FractionalAvgPoolGrad` does not consider cases where the input tensors are invalid allowing an attacker to read from ou…
CVE-2022-21728 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of shape inference for `ReverseSequence` does not fully validate the value of `batch_dim` and can result in a heap OOB read…
CVE-2022-21727 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of shape inference for `Dequantize` is vulnerable to an integer overflow weakness. The `axis` argument can be `-1` (the def…
CVE-2022-21726 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of `Dequantize` does not fully validate the value of `axis` and can result in heap OOB accesses. The `axis` argument can be…
CVE-2022-23580 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. During shape inference, TensorFlow can allocate a large vector based on a value from a tensor controlled by the user. The fix will be included…
CVE-2022-23581 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The Grappler optimizer in TensorFlow can be used to cause a denial of service by altering a `SavedModel` such that `IsSimplifiableReshape` wou…
CVE-2020-15212 unknown 6y ago In TensorFlow Lite before versions 2.2.1 and 2.3.1, models using segment sum can trigger writes outside of bounds of heap allocated buffers by inserting negative elements in the segment ids tensor. U…
CVE-2020-15214 unknown 6y ago In TensorFlow Lite before versions 2.2.1 and 2.3.1, models using segment sum can trigger a write out bounds / segmentation fault if the segment ids are not sorted. Code assumes that the segment ids a…
CVE-2020-15213 unknown 6y ago In TensorFlow Lite before versions 2.2.1 and 2.3.1, models using segment sum can trigger a denial of service by causing an out of memory allocation in the implementation of segment sum. Since code us…
CVE-2020-15210 unknown 6y ago In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, if a TFLite saved model uses the same tensor as both input and output of an operator, then, depending on the operator, we can…
CVE-2020-15211 unknown 6y ago In TensorFlow Lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, saved models in the flatbuffer format use a double indexing scheme: a model has a set of subgraphs, each subgraph has a set o…
CVE-2020-15209 unknown 6y ago In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, a crafted TFLite model can force a node to have as input a tensor backed by a `nullptr` buffer. This can be achieved by chang…
CVE-2020-15208 unknown 6y ago In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, when determining the common dimension size of two tensors, TFLite uses a `DCHECK` which is no-op outside of debug compilation…