Vulnerability index

Browse CVEs

1,761 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Tensorflow HIGH 7.8
CVE-2021-29603

TensorFlow is an end-to-end open source platform for machine learning. A specially crafted TFLite model could trigger an OOB write on heap in the TFL…

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14
Tensorflow HIGH 7.8
CVE-2021-29609

TensorFlow is an end-to-end open source platform for machine learning. Incomplete validation in `SparseAdd` results in allowing attackers to exploit …

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14
Tensorflow HIGH 7.8
CVE-2021-29610

TensorFlow is an end-to-end open source platform for machine learning. The validation in `tf.raw_ops.QuantizeAndDequantizeV2` allows invalid values f…

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14
Tensorflow HIGH 7.8
CVE-2021-29612

TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a heap buffer overflow in Eigen implementation of `tf.…

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14
Tensorflow HIGH 7.8
CVE-2021-29576

TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.MaxPool3DGradGrad` is vulnerable to a heap b…

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14
Tensorflow HIGH 7.8
CVE-2021-29577

TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.AvgPool3DGrad` is vulnerable to a heap buffe…

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14
Tensorflow HIGH 7.8
CVE-2021-29578

TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.FractionalAvgPoolGrad` is vulnerable to a he…

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14
Tensorflow HIGH 7.8
CVE-2021-29579

TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.MaxPoolGrad` is vulnerable to a heap buffer …

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14
Tensorflow MEDIUM 5.5
CVE-2021-29575

TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.ReverseSequence` allows for stack overflow a…

Fix: 2.2.3 / 2.3.3+
Fix from $1,600 2021-05-14
Tensorflow HIGH 7.8
CVE-2021-29558

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow in `tf.raw_ops.SparseSplit`. This…

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14
Tensorflow HIGH 7.8
CVE-2021-29566

TensorFlow is an end-to-end open source platform for machine learning. An attacker can write outside the bounds of heap allocated arrays by passing i…

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14
Tensorflow HIGH 7.8
CVE-2021-29571

TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.MaxPoolGradWithArgmax` can cause reads outsi…

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14
Tensorflow HIGH 7.1
CVE-2021-29560

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow in `tf.raw_ops.RaggedTensorToTens…

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14
Tensorflow HIGH 7.8
CVE-2021-29535

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow in `QuantizedMul` by passing in i…

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14
Tensorflow HIGH 7.8
CVE-2021-29536

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow in `QuantizedReshape` by passing …

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14
Tensorflow HIGH 7.8
CVE-2021-29537

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow in `QuantizedResizeBilinear` by p…

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14
Tensorflow HIGH 7.8
CVE-2021-29540

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow to occur in `Conv2DBackpropFilter…

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14
Tensorflow MEDIUM 5.5
CVE-2021-29542

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow by passing crafted inputs to `tf.…

Fix: 2.1.4 / 2.2.3+
Fix from $1,600 2021-05-14
Tensorflow HIGH 7.8
CVE-2021-29514

TensorFlow is an end-to-end open source platform for machine learning. If the `splits` argument of `RaggedBincount` does not specify a valid `SparseT…

Fix: 2.3.3 / 2.4.2+
Fix from $1,950 2021-05-14
Tensorflow HIGH 7.8
CVE-2021-29520

TensorFlow is an end-to-end open source platform for machine learning. Missing validation between arguments to `tf.raw_ops.Conv3DBackprop*` operation…

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14
Tensorflow HIGH 7.8
CVE-2021-29512

TensorFlow is an end-to-end open source platform for machine learning. If the `splits` argument of `RaggedBincount` does not specify a valid `SparseT…

Fix: 2.3.3 / 2.4.2+
Fix from $1,950 2021-05-14
Chrome HIGH 8.8
CVE-2021-21227

Insufficient data validation in V8 in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a craf…

Fix: 90.0.4430.93+
Fix from $1,950 2021-04-30
Chrome HIGH 8.8
CVE-2021-21231

Insufficient data validation in V8 in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a craf…

Fix: 90.0.4430.93+
Fix from $1,950 2021-04-30
Chrome HIGH 8.8
CVE-2021-21233

Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via …

Fix: 90.0.4430.93+
Fix from $1,950 2021-04-30
Chrome HIGH 8.8
CVE-2021-21220 KEVEPSS 69%

Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corrup…

Fix: 89.0.4389.128+
Fix from $1,950 2021-04-26
Chrome HIGH 8.8
CVE-2021-21225EPSS 7%

Out of bounds memory access in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to potentially exploit heap corruption via a craft…

Fix: 90.0.4430.85+
Fix from $1,950 2021-04-26
Chrome MEDIUM 6.5
CVE-2021-21222

Heap buffer overflow in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the renderer process to bypass site i…

Fix: 90.0.4430.85+
Fix from $1,600 2021-04-26
Android MEDIUM 6.7
CVE-2021-0488

In pb_write of pb_encode.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege w…

Patch available
Fix from $1,600 2021-04-15
Android HIGH 7.8
CVE-2021-0439

In setPowerModeWithHandle of com_android_server_power_PowerManagerService.cpp, there is a possible out of bounds write due to a missing bounds check.…

Patch available
Fix from $1,950 2021-04-13
Android CRITICAL 9.8
CVE-2021-0430

In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code executio…

Patch available
Fix from $2,300 2021-04-13