Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tensorflow HIGH 7.5
CVE-2022-41907

TensorFlow is an open source platform for machine learning. When `tf.raw_ops.ResizeNearestNeighborGrad` is given a large `size` input, it overflows. …

Fix: 2.8.4 / 2.9.3+
Fix from $1,950 2022-11-18
Tensorflow HIGH 7.5
CVE-2022-41908

TensorFlow is an open source platform for machine learning. An input `token` that is not a UTF-8 bytestring will trigger a `CHECK` fail in `tf.raw_op…

Fix: 2.8.4 / 2.9.3+
Fix from $1,950 2022-11-18
Tensorflow CRITICAL 9.8
CVE-2022-41900

TensorFlow is an open source platform for machine learning. The security vulnerability results in FractionalMax(AVG)Pool with illegal pooling_ratio. …

Fix: 2.8.4 / 2.9.3+
Fix from $2,300 2022-11-18
Tensorflow HIGH 7.5
CVE-2022-41901

TensorFlow is an open source platform for machine learning. An input `sparse_matrix` that is not a matrix with a shape with rank 0 will trigger a `CH…

Fix: 2.8.4 / 2.9.3+
Fix from $1,950 2022-11-18
Tensorflow HIGH 7.5
CVE-2022-41897

TensorFlow is an open source platform for machine learning. If `FractionMaxPoolGrad` is given outsize inputs `row_pooling_sequence` and `col_pooling_…

Fix: 2.8.4 / 2.9.3+
Fix from $1,950 2022-11-18
Tensorflow HIGH 7.5
CVE-2022-41898

TensorFlow is an open source platform for machine learning. If `SparseFillEmptyRowsGrad` is given empty inputs, TensorFlow will crash. We have patche…

Fix: 2.8.4 / 2.9.3+
Fix from $1,950 2022-11-18
Tensorflow HIGH 7.5
CVE-2022-41899

TensorFlow is an open source platform for machine learning. Inputs `dense_features` or `example_state_data` not of rank 2 will trigger a `CHECK` fail…

Fix: 2.8.4 / 2.9.3+
Fix from $1,950 2022-11-18
Tensorflow HIGH 7.5
CVE-2022-41895

TensorFlow is an open source platform for machine learning. If `MirrorPadGrad` is given outsize input `paddings`, TensorFlow will give a heap OOB err…

Fix: 2.8.4 / 2.9.3+
Fix from $1,950 2022-11-18
Tensorflow HIGH 7.5
CVE-2022-41896

TensorFlow is an open source platform for machine learning. If `ThreadUnsafeUnigramCandidateSampler` is given input `filterbank_channel_count` greate…

Fix: 2.8.4 / 2.9.3+
Fix from $1,950 2022-11-18
Tensorflow HIGH 8.1
CVE-2022-41894

TensorFlow is an open source platform for machine learning. The reference kernel of the `CONV_3D_TRANSPOSE` TensorFlow Lite operator wrongly incremen…

Fix: 2.8.4 / 2.9.3+
Fix from $1,950 2022-11-18
Tensorflow HIGH 7.5
CVE-2022-41893

TensorFlow is an open source platform for machine learning. If `tf.raw_ops.TensorListResize` is given a nonscalar value for input `size`, it results …

Fix: 2.8.4 / 2.9.3+
Fix from $1,950 2022-11-18
Tensorflow HIGH 7.5
CVE-2022-41890

TensorFlow is an open source platform for machine learning. If `BCast::ToShape` is given input larger than an `int32`, it will crash, despite being s…

Fix: 2.8.4 / 2.9.3+
Fix from $1,950 2022-11-18
Tensorflow HIGH 7.5
CVE-2022-41891

TensorFlow is an open source platform for machine learning. If `tf.raw_ops.TensorListConcat` is given `element_shape=[]`, it results segmentation fau…

Fix: 2.8.4 / 2.9.3+
Fix from $1,950 2022-11-18
Tensorflow HIGH 7.5
CVE-2022-41888

TensorFlow is an open source platform for machine learning. When running on GPU, `tf.image.generate_bounding_box_proposals` receives a `scores` input…

Fix: 2.8.4 / 2.9.3+
Fix from $1,950 2022-11-18
Tensorflow HIGH 7.5
CVE-2022-41889

TensorFlow is an open source platform for machine learning. If a list of quantized tensors is assigned to an attribute, the pywrap code fails to pars…

Fix: 2.8.4 / 2.9.3+
Fix from $1,950 2022-11-18
Tensorflow HIGH 7.5
CVE-2022-41885

TensorFlow is an open source platform for machine learning. When `tf.raw_ops.FusedResizeAndPadConv2D` is given a large tensor shape, it overflows. We…

Fix: 2.7.4 / 2.8.1+
Fix from $1,950 2022-11-18
Tensorflow HIGH 7.5
CVE-2022-41886

TensorFlow is an open source platform for machine learning. When `tf.raw_ops.ImageProjectiveTransformV2` is given a large output shape, it overflows.…

Fix: 2.8.4 / 2.9.3+
Fix from $1,950 2022-11-18
Tensorflow HIGH 7.5
CVE-2022-41887

TensorFlow is an open source platform for machine learning. `tf.keras.losses.poisson` receives a `y_pred` and `y_true` that are passed through `funct…

Fix: 2.9.3+
Fix from $1,950 2022-11-18
Tensorflow HIGH 7.5
CVE-2022-41884

TensorFlow is an open source platform for machine learning. If a numpy array is created with a shape such that one element is zero and the others sum…

Fix: 2.8.4 / 2.9.3+
Fix from $1,950 2022-11-18
Tensorflow CRITICAL 9.1
CVE-2022-41880

TensorFlow is an open source platform for machine learning. When the `BaseCandidateSamplerOp` function receives a value in `true_classes` larger than…

Fix: 2.8.4 / 2.9.3+
Fix from $2,300 2022-11-18
Tensorflow HIGH 7.5
CVE-2022-41883

TensorFlow is an open source platform for machine learning. When ops that have specified input sizes receive a differing number of inputs, the execut…

Patch available
Fix from $1,950 2022-11-18
Android HIGH 7.8
CVE-2022-42533

In shared_metadata_init of SharedMetadata.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalatio…

Mitigation only
Fix from $1,950 2022-11-17
Android MEDIUM 6.7
CVE-2022-20460

In (TBD) mprot_unmap? of (TBD), there is a possible way to corrupt the memory mapping due to improper input validation. This could lead to local esca…

Mitigation only
Fix from $1,600 2022-11-17
Android MEDIUM 6.7
CVE-2022-20428

In (TBD) of (TBD), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with Syste…

No fix yet
Fix from $1,600 2022-11-17
Android MEDIUM 6.7
CVE-2022-20459

In (TBD) of (TBD), there is a possible way to redirect code execution due to improper input validation. This could lead to local escalation of privil…

No fix yet
Fix from $1,600 2022-11-17
Android MEDIUM 6.7
CVE-2022-20427

In (TBD) of (TBD), there is a possible way to corrupt memory due to improper input validation. This could lead to local escalation of privilege with …

Mitigation only
Fix from $1,600 2022-11-17
Android HIGH 7.8
CVE-2022-39883

Improper authorization vulnerability in StorageManagerService prior to SMR Nov-2022 Release 1 allows local attacker to call privileged API.

Mitigation only
Fix from $1,950 2022-11-09
Android HIGH 7.8
CVE-2022-39880

Improper input validation vulnerability in DualOutFocusViewer prior to SMR Nov-2022 Release 1 allows local attacker to perform an arbitrary code exec…

Mitigation only
Fix from $1,950 2022-11-09
Android HIGH 7.8
CVE-2022-39882

Heap overflow vulnerability in sflacf_fal_bytes_peek function in libsmat.so library prior to SMR Nov-2022 Release 1 allows local attacker to execute …

Mitigation only
Fix from $1,950 2022-11-09
Chrome HIGH 8.8
CVE-2022-3449

Use after free in Safe Browsing in Google Chrome prior to 106.0.5249.119 allowed an attacker who convinced a user to install a malicious extension to…

Fix: 106.0.5249.119+
Fix from $1,950 2022-11-09