Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tensorflow CRITICAL 9.8
CVE-2022-23587

Tensorflow is an Open Source Machine Learning Framework. Under certain scenarios, Grappler component of TensorFlow is vulnerable to an integer overfl…

Fix: after 2.6.2
Fix from $2,300 2022-02-04
Tensorflow HIGH 8.1
CVE-2022-23592

Tensorflow is an Open Source Machine Learning Framework. TensorFlow's type inference can cause a heap out of bounds read as the bounds checking is do…

Fix: 2.8.0+
Fix from $1,950 2022-02-04
Tensorflow HIGH 7.5
CVE-2022-23590

Tensorflow is an Open Source Machine Learning Framework. A `GraphDef` from a TensorFlow `SavedModel` can be maliciously altered to cause a TensorFlow…

Fix: 2.7.1+
Fix from $1,950 2022-02-04
Tensorflow HIGH 7.5
CVE-2022-23591

Tensorflow is an Open Source Machine Learning Framework. The `GraphDef` format in TensorFlow does not allow self recursive functions. The runtime ass…

Fix: after 2.6.2
Fix from $1,950 2022-02-04
Tensorflow HIGH 7.5
CVE-2022-23593

Tensorflow is an Open Source Machine Learning Framework. The `simplifyBroadcast` function in the MLIR-TFRT infrastructure in TensorFlow is vulnerable…

Fix: 2.8.0+
Fix from $1,950 2022-02-04
Tensorflow MEDIUM 6.5
CVE-2022-23588

Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a denial of service by altering a `SavedModel` such that Grappler…

Fix: after 2.6.2
Fix from $1,600 2022-02-04
Tensorflow MEDIUM 6.5
CVE-2022-23589

Tensorflow is an Open Source Machine Learning Framework. Under certain scenarios, Grappler component of TensorFlow can trigger a null pointer derefer…

Fix: after 2.6.2
Fix from $1,600 2022-02-04
Tensorflow MEDIUM 6.5
CVE-2022-23595

Tensorflow is an Open Source Machine Learning Framework. When building an XLA compilation cache, if default settings are used, TensorFlow triggers a …

Fix: after 2.6.2
Fix from $1,600 2022-02-04
Tensorflow MEDIUM 5.5
CVE-2022-23594

Tensorflow is an Open Source Machine Learning Framework. The TFG dialect of TensorFlow (MLIR) makes several assumptions about the incoming `GraphDef`…

Mitigation only
Fix from $1,600 2022-02-04
Tensorflow HIGH 8.8
CVE-2022-23566

Tensorflow is an Open Source Machine Learning Framework. TensorFlow is vulnerable to a heap OOB write in `Grappler`. The `set_output` function writes…

Fix: after 2.6.2
Fix from $1,950 2022-02-04
Tensorflow HIGH 8.8
CVE-2022-23573

Tensorflow is an Open Source Machine Learning Framework. The implementation of `AssignOp` can result in copying uninitialized data to a new tensor. T…

Fix: after 2.6.2
Fix from $1,950 2022-02-04
Tensorflow HIGH 8.8
CVE-2022-23574

Tensorflow is an Open Source Machine Learning Framework. There is a typo in TensorFlow's `SpecializeType` which results in heap OOB read/write. Due t…

Fix: after 2.6.2
Fix from $1,950 2022-02-04
Tensorflow MEDIUM 6.5
CVE-2022-23565

Tensorflow is an Open Source Machine Learning Framework. An attacker can trigger denial of service via assertion failure by altering a `SavedModel` o…

Fix: after 2.6.2
Fix from $1,600 2022-02-04
Tensorflow MEDIUM 6.5
CVE-2022-23570

Tensorflow is an Open Source Machine Learning Framework. When decoding a tensor from protobuf, TensorFlow might do a null-dereference if attributes o…

Fix: after 2.6.2
Fix from $1,600 2022-02-04
Tensorflow MEDIUM 6.5
CVE-2022-23571

Tensorflow is an Open Source Machine Learning Framework. When decoding a tensor from protobuf, a TensorFlow process can encounter cases where a `CHEC…

Fix: after 2.6.2
Fix from $1,600 2022-02-04
Tensorflow MEDIUM 6.5
CVE-2022-23572

Tensorflow is an Open Source Machine Learning Framework. Under certain scenarios, TensorFlow can fail to specialize a type during shape inference. Th…

Fix: after 2.6.2
Fix from $1,600 2022-02-04
Tensorflow MEDIUM 6.5
CVE-2022-23575

Tensorflow is an Open Source Machine Learning Framework. The implementation of `OpLevelCostEstimator::CalculateTensorSize` is vulnerable to an intege…

Fix: after 2.6.2
Fix from $1,600 2022-02-04
Tensorflow MEDIUM 6.5
CVE-2022-23576

Tensorflow is an Open Source Machine Learning Framework. The implementation of `OpLevelCostEstimator::CalculateOutputSize` is vulnerable to an intege…

Fix: after 2.6.2
Fix from $1,600 2022-02-04
Tensorflow MEDIUM 6.5
CVE-2022-23577

Tensorflow is an Open Source Machine Learning Framework. The implementation of `GetInitOp` is vulnerable to a crash caused by dereferencing a null po…

Fix: after 2.6.2
Fix from $1,600 2022-02-04
Tensorflow MEDIUM 6.5
CVE-2022-23579

Tensorflow is an Open Source Machine Learning Framework. The Grappler optimizer in TensorFlow can be used to cause a denial of service by altering a …

Fix: after 2.6.2
Fix from $1,600 2022-02-04
Tensorflow MEDIUM 6.5
CVE-2022-23580

Tensorflow is an Open Source Machine Learning Framework. During shape inference, TensorFlow can allocate a large vector based on a value from a tenso…

Fix: after 2.6.2
Fix from $1,600 2022-02-04
Tensorflow MEDIUM 6.5
CVE-2022-23581

Tensorflow is an Open Source Machine Learning Framework. The Grappler optimizer in TensorFlow can be used to cause a denial of service by altering a …

Fix: after 2.6.2
Fix from $1,600 2022-02-04
Tensorflow MEDIUM 6.5
CVE-2022-23582

Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a denial of service by altering a `SavedModel` such that `TensorB…

Fix: after 2.6.2
Fix from $1,600 2022-02-04
Tensorflow MEDIUM 6.5
CVE-2022-23583

Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a denial of service by altering a `SavedModel` such that any bina…

Fix: after 2.6.2
Fix from $1,600 2022-02-04
Tensorflow MEDIUM 6.5
CVE-2022-23584

Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a use after free behavior when decoding PNG images. After `png::C…

Fix: after 2.6.2
Fix from $1,600 2022-02-04
Tensorflow MEDIUM 6.5
CVE-2022-23585

Tensorflow is an Open Source Machine Learning Framework. When decoding PNG images TensorFlow can produce a memory leak if the image is invalid. After…

Fix: after 2.6.2
Fix from $1,600 2022-02-04
Tensorflow MEDIUM 6.5
CVE-2022-23586

Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a denial of service by altering a `SavedModel` such that assertio…

Fix: after 2.6.2
Fix from $1,600 2022-02-04
Tensorflow HIGH 8.8
CVE-2022-23558

Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would cause an integer overflow in `TfLiteIntArray…

Fix: after 2.6.2
Fix from $1,950 2022-02-04
Tensorflow HIGH 8.8
CVE-2022-23559

Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would cause an integer overflow in embedding looku…

Fix: after 2.6.2
Fix from $1,950 2022-02-04
Tensorflow HIGH 8.8
CVE-2022-23560

Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would allow limited reads and writes outside of ar…

Fix: after 2.6.2
Fix from $1,950 2022-02-04