Package impact

python PyPI / tensorflow

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2022-36012 unknown 4y ago TensorFlow vulnerable to assertion fail on MLIR empty edge names debianpython
CVE-2022-35987 unknown 4y ago TensorFlow vulnerable to `CHECK` fail in `DenseBincount` debianpython
CVE-2022-35941 unknown 4y ago TensorFlow vulnerable to `CHECK` failure in `AvgPoolOp` debianpython
CVE-2022-36026 unknown 4y ago TensorFlow vulnerable to `CHECK` fail in `QuantizeAndDequantizeV3` debianpython
CVE-2022-36018 unknown 4y ago TensorFlow vulnerable to `CHECK` fail in `RaggedTensorToVariant` debianpython
CVE-2022-36019 unknown 4y ago TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVarsPerChannel` debianpython
CVE-2022-36027 unknown 4y ago TensorFlow is an open source platform for machine learning. When converting transposed convolutions using per-channel weight quantization the converter segfaults and crashes the Python process. We ha… debianpython
CVE-2022-35939 unknown 4y ago TensorFlow vulnerable to OOB write in `scatter_nd` in TF Lite debianpython
CVE-2022-35937 unknown 4y ago TensorFlow vulnerable to OOB read in `Gather_nd` in TF Lite debianpython
CVE-2022-35934 unknown 4y ago TensorFlow vulnerable to `CHECK` failure in tf.reshape via overflows debianpython
CVE-2022-35935 unknown 4y ago TensorFlow vulnerable to `CHECK` failure in `SobolSample` via missing validation debianpython
CVE-2022-35997 unknown 4y ago TensorFlow vulnerable to `CHECK` fail in `tf.sparse.cross` debianpython
CVE-2022-35999 unknown 4y ago TensorFlow is an open source platform for machine learning. When `Conv2DBackpropInput` receives empty `out_backprop` inputs (e.g. `[3, 1, 0, 1]`), the current CPU/GPU kernels `CHECK` fail (one with d… debianpython
CVE-2022-29216 unknown 4y ago TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, TensorFlow's `saved_model_cli` tool is vulnerable to a code injection. This can be used t… debianpython
CVE-2022-29213 unknown 4y ago TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the `tf.compat.v1.signal.rfft2d` and `tf.compat.v1.signal.rfft3d` lack input validation a… debianpython
CVE-2022-29212 unknown 4y ago Core dump when loading TFLite models with quantization in TensorFlow debianpython
CVE-2022-29211 unknown 4y ago Segfault if `tf.histogram_fixed_width` is called with NaN values in TensorFlow debianpython
CVE-2022-29210 unknown 4y ago Heap buffer overflow due to incorrect hash function in TensorFlow debianpython
CVE-2022-29209 unknown 4y ago Type confusion leading to `CHECK`-failure based denial of service in TensorFlow debianpython
CVE-2022-29208 unknown 4y ago TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.EditDistance` has incomplete validation. Users can pass… debianpython
CVE-2022-29207 unknown 4y ago TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, multiple TensorFlow operations misbehave in eager mode when the resource handle provided … debianpython
CVE-2022-29206 unknown 4y ago Missing validation results in undefined behavior in `SparseTensorDenseAdd debianpython
CVE-2022-29205 unknown 4y ago TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, there is a potential for segfault / denial of service in TensorFlow by calling `tf.compat… debianpython
CVE-2022-29204 unknown 4y ago Missing validation causes denial of service via `Conv3DBackpropFilterV2` debianpython
CVE-2022-29203 unknown 4y ago Integer overflow in `SpaceToBatchND` debianpython
CVE-2022-29202 unknown 4y ago Denial of service in `tf.ragged.constant` due to lack of validation debianpython
CVE-2022-29201 unknown 4y ago Missing validation results in undefined behavior in `QuantizedConv2D` debianpython
CVE-2022-29200 unknown 4y ago TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.LSTMBlockCell` does not fully validate the input argume… debianpython
CVE-2022-29199 unknown 4y ago Missing validation causes denial of service via `LoadAndRemapMatrix` debianpython
CVE-2022-29198 unknown 4y ago Missing validation causes denial of service via `SparseTensorToCSRSparseMatrix` debianpython
CVE-2022-29197 unknown 4y ago Missing validation causes denial of service via `UnsortedSegmentJoin` debianpython
CVE-2022-29196 unknown 4y ago TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.Conv3DBackpropFilterV2` does not fully validate the inp… debianpython
CVE-2022-29195 unknown 4y ago Missing validation causes denial of service via `StagePeek` debianpython
CVE-2022-29194 unknown 4y ago Missing validation causes denial of service via `DeleteSessionTensor` debianpython
CVE-2022-29192 unknown 4y ago Missing validation crashes `QuantizeAndDequantizeV4Grad` debianpython
CVE-2022-29191 unknown 4y ago Missing validation causes denial of service via `GetSessionTensor` debianpython
CVE-2022-29193 unknown 4y ago TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.TensorSummaryV2` does not fully validate the input argu… debianpython
CVE-2022-23583 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a denial of service by altering a `SavedModel` such that any binary op would trigger `CHECK` failures. This occurs … debianpython
CVE-2022-23582 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a denial of service by altering a `SavedModel` such that `TensorByteSize` would trigger `CHECK` failures. `TensorSh… debianpython
CVE-2022-23579 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The Grappler optimizer in TensorFlow can be used to cause a denial of service by altering a `SavedModel` such that `SafeToRemoveIdentity` woul… debianpython
CVE-2022-23578 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. If a graph node is invalid, TensorFlow can leak memory in the implementation of `ImmutableExecutorState::Initialize`. Here, we set `item->kern… debianpython
CVE-2022-23575 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of `OpLevelCostEstimator::CalculateTensorSize` is vulnerable to an integer overflow if an attacker can create an operation … debianpython
CVE-2022-23576 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of `OpLevelCostEstimator::CalculateOutputSize` is vulnerable to an integer overflow if an attacker can create an operation … debianpython
CVE-2022-23577 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of `GetInitOp` is vulnerable to a crash caused by dereferencing a null pointer. The fix will be included in TensorFlow 2.8.… debianpython
CVE-2022-21735 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of `FractionalMaxPool` can be made to crash a TensorFlow process via a division by 0. The fix will be included in TensorFlo… debianpython
CVE-2022-21734 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of `MapStage` is vulnerable a `CHECK`-fail if the key tensor is not a scalar. The fix will be included in TensorFlow 2.8.0.… debianpython
CVE-2022-21733 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of `StringNGrams` can be used to trigger a denial of service attack by causing an out of memory condition after an integer … debianpython
CVE-2022-21732 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of `ThreadPoolHandle` can be used to trigger a denial of service attack by allocating too much memory. This is because the … debianpython
CVE-2022-21731 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of shape inference for `ConcatV2` can be used to trigger a denial of service attack via a segfault caused by a type confusi… debianpython
CVE-2022-21729 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of `UnravelIndex` is vulnerable to a division by zero caused by an integer overflow bug. The fix will be included in Tensor… debianpython
CVE-2022-21725 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The estimator for the cost of some convolution operations can be made to execute a division by 0. The function fails to check that the stride … debianpython
CVE-2022-23584 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a use after free behavior when decoding PNG images. After `png::CommonFreeDecode(&decode)` gets called, the values … debianpython
CVE-2022-23566 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. TensorFlow is vulnerable to a heap OOB write in `Grappler`. The `set_output` function writes to an array at the specified index. Hence, this g… debianpython
CVE-2022-23564 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. When decoding a resource handle tensor from protobuf, a TensorFlow process can encounter cases where a `CHECK` assertion is invalidated based … debianpython
CVE-2022-23563 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. In multiple places, TensorFlow uses `tempfile.mktemp` to create temporary files. While this is acceptable in testing, in utilities and librari… debianpython
CVE-2022-23562 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of `Range` suffers from integer overflows. These can trigger undefined behavior or, in some scenarios, extremely large allo… debianpython
CVE-2022-23561 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would cause a write outside of bounds of an array in TFLite. In fact, the attacker can override the … debianpython
CVE-2022-23560 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would allow limited reads and writes outside of arrays in TFLite. This exploits missing validation i… debianpython
CVE-2022-23559 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would cause an integer overflow in embedding lookup operations. Both `embedding_size` and `lookup_si… debianpython
CVE-2022-23558 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would cause an integer overflow in `TfLiteIntArrayCreate`. The `TfLiteIntArrayGetSizeInBytes` return… debianpython
CVE-2022-23565 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. An attacker can trigger denial of service via assertion failure by altering a `SavedModel` on disk such that `AttrDef`s of some operation are … debianpython
CVE-2022-23557 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would trigger a division by zero in `BiasAndClamp` implementation. There is no check that the `bias_… debianpython
CVE-2022-21741 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. ### Impact An attacker can craft a TFLite model that would trigger a division by zero in the implementation of depthwise convolutions. The par… debianpython
CVE-2022-21740 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of `SparseCountSparseOutput` is vulnerable to a heap overflow. The fix will be included in TensorFlow 2.8.0. We will also c… debianpython
CVE-2022-21739 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of `QuantizedMaxPool` has an undefined behavior where user controlled inputs can trigger a reference binding to null pointe… debianpython
CVE-2022-21738 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of `SparseCountSparseOutput` can be made to crash a TensorFlow process by an integer overflow whose result is then used in … debianpython
CVE-2022-21737 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of `*Bincount` operations allows malicious users to cause denial of service by passing in arguments which would trigger a `… debianpython
CVE-2022-21736 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of `SparseTensorSliceDataset` has an undefined behavior: under certain condition it can be made to dereference a `nullptr` … debianpython
CVE-2022-23567 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementations of `Sparse*Cwise*` ops are vulnerable to integer overflows. These can be used to trigger large allocations (so, OOM based … debianpython
CVE-2022-23568 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of `AddManySparseToTensorsMap` is vulnerable to an integer overflow which results in a `CHECK`-fail when building new `Tens… debianpython
CVE-2022-23569 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. Multiple operations in TensorFlow can be used to trigger a denial of service via `CHECK`-fails (i.e., assertion failures). This is similar to … debianpython
CVE-2022-23570 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. When decoding a tensor from protobuf, TensorFlow might do a null-dereference if attributes of some mutable arguments to some operations are mi… debianpython
CVE-2022-23595 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. When building an XLA compilation cache, if default settings are used, TensorFlow triggers a null pointer dereference. In the default scenario,… debianpython
CVE-2022-23594 unknown 4y ago Out of bounds read in Tensorflow debianpython
CVE-2022-23593 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The `simplifyBroadcast` function in the MLIR-TFRT infrastructure in TensorFlow is vulnerable to a segfault (hence, denial of service), if call… debianpython
CVE-2022-23592 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. TensorFlow's type inference can cause a heap out of bounds read as the bounds checking is done in a `DCHECK` (which is a no-op during producti… debianpython
CVE-2022-23591 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The `GraphDef` format in TensorFlow does not allow self recursive functions. The runtime assumes that this invariant is satisfied. However, a … debianpython
CVE-2022-23590 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. A `GraphDef` from a TensorFlow `SavedModel` can be maliciously altered to cause a TensorFlow process to crash due to encountering a `StatusOr`… debianpython
CVE-2022-23589 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. Under certain scenarios, Grappler component of TensorFlow can trigger a null pointer dereference. There are 2 places where this can occur, for… debianpython
CVE-2022-23571 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. When decoding a tensor from protobuf, a TensorFlow process can encounter cases where a `CHECK` assertion is invalidated based on user controll… debianpython
CVE-2022-23572 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. Under certain scenarios, TensorFlow can fail to specialize a type during shape inference. This case is covered by the `DCHECK` function howeve… debianpython
CVE-2022-23588 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a denial of service by altering a `SavedModel` such that Grappler optimizer would attempt to build a tensor using a… debianpython
CVE-2022-23587 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. Under certain scenarios, Grappler component of TensorFlow is vulnerable to an integer overflow during cost estimation for crop and resize. Sin… debianpython
CVE-2022-23586 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a denial of service by altering a `SavedModel` such that assertions in `function.cc` would be falsified and crash t… debianpython
CVE-2022-23573 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of `AssignOp` can result in copying uninitialized data to a new tensor. This later results in undefined behavior. The imple… debianpython
CVE-2022-23585 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. When decoding PNG images TensorFlow can produce a memory leak if the image is invalid. After calling `png::CommonInitDecode(..., &decode)`, th… debianpython
CVE-2022-23574 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. There is a typo in TensorFlow's `SpecializeType` which results in heap OOB read/write. Due to a typo, `arg` is initialized to the `i`th mutabl… debianpython
CVE-2022-21730 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of `FractionalAvgPoolGrad` does not consider cases where the input tensors are invalid allowing an attacker to read from ou… debianpython
CVE-2022-21728 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of shape inference for `ReverseSequence` does not fully validate the value of `batch_dim` and can result in a heap OOB read… debianpython
CVE-2022-21727 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of shape inference for `Dequantize` is vulnerable to an integer overflow weakness. The `axis` argument can be `-1` (the def… debianpython
CVE-2022-21726 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The implementation of `Dequantize` does not fully validate the value of `axis` and can result in heap OOB accesses. The `axis` argument can be… debianpython
CVE-2022-23580 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. During shape inference, TensorFlow can allocate a large vector based on a value from a tensor controlled by the user. The fix will be included… debianpython
CVE-2022-23581 unknown 4y ago Tensorflow is an Open Source Machine Learning Framework. The Grappler optimizer in TensorFlow can be used to cause a denial of service by altering a `SavedModel` such that `IsSimplifiableReshape` wou… debianpython
CVE-2020-15212 unknown 6y ago In TensorFlow Lite before versions 2.2.1 and 2.3.1, models using segment sum can trigger writes outside of bounds of heap allocated buffers by inserting negative elements in the segment ids tensor. U… debianpython
CVE-2020-15214 unknown 6y ago In TensorFlow Lite before versions 2.2.1 and 2.3.1, models using segment sum can trigger a write out bounds / segmentation fault if the segment ids are not sorted. Code assumes that the segment ids a… debianpython
CVE-2020-15213 unknown 6y ago In TensorFlow Lite before versions 2.2.1 and 2.3.1, models using segment sum can trigger a denial of service by causing an out of memory allocation in the implementation of segment sum. Since code us… debianpython
CVE-2020-15210 unknown 6y ago In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, if a TFLite saved model uses the same tensor as both input and output of an operator, then, depending on the operator, we can… debianpython
CVE-2020-15211 unknown 6y ago In TensorFlow Lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, saved models in the flatbuffer format use a double indexing scheme: a model has a set of subgraphs, each subgraph has a set o… debianpython
CVE-2020-15209 unknown 6y ago In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, a crafted TFLite model can force a node to have as input a tensor backed by a `nullptr` buffer. This can be achieved by chang… debianpython
CVE-2020-15208 unknown 6y ago In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, when determining the common dimension size of two tensors, TFLite uses a `DCHECK` which is no-op outside of debug compilation… debianpython