Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tensorflow HIGH 8.8
CVE-2022-23561

Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would cause a write outside of bounds of an array …

Fix: after 2.6.2
Fix from $1,950 2022-02-04
Tensorflow HIGH 8.8
CVE-2022-23562

Tensorflow is an Open Source Machine Learning Framework. The implementation of `Range` suffers from integer overflows. These can trigger undefined be…

Fix: after 2.6.2
Fix from $1,950 2022-02-04
Tensorflow MEDIUM 6.5
CVE-2022-23557

Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would trigger a division by zero in `BiasAndClamp`…

Fix: after 2.6.2
Fix from $1,600 2022-02-04
Tensorflow MEDIUM 6.5
CVE-2022-23564

Tensorflow is an Open Source Machine Learning Framework. When decoding a resource handle tensor from protobuf, a TensorFlow process can encounter cas…

Fix: after 2.6.2
Fix from $1,600 2022-02-04
Tensorflow MEDIUM 6.3
CVE-2022-23563

Tensorflow is an Open Source Machine Learning Framework. In multiple places, TensorFlow uses `tempfile.mktemp` to create temporary files. While this …

Fix: after 2.6.2
Fix from $1,600 2022-02-04
Tensorflow HIGH 8.8
CVE-2022-21740

Tensorflow is an Open Source Machine Learning Framework. The implementation of `SparseCountSparseOutput` is vulnerable to a heap overflow. The fix wi…

Fix: after 2.6.2
Fix from $1,950 2022-02-03
Tensorflow MEDIUM 6.5
CVE-2022-21741

Tensorflow is an Open Source Machine Learning Framework. ### Impact An attacker can craft a TFLite model that would trigger a division by zero in the…

Fix: after 2.6.2
Fix from $1,600 2022-02-03
Tensorflow MEDIUM 6.5
CVE-2022-21737

Tensorflow is an Open Source Machine Learning Framework. The implementation of `*Bincount` operations allows malicious users to cause denial of servi…

Fix: after 2.6.2
Fix from $1,600 2022-02-03
Tensorflow MEDIUM 6.5
CVE-2022-21738

Tensorflow is an Open Source Machine Learning Framework. The implementation of `SparseCountSparseOutput` can be made to crash a TensorFlow process by…

Fix: after 2.6.2
Fix from $1,600 2022-02-03
Tensorflow MEDIUM 6.5
CVE-2022-21739

Tensorflow is an Open Source Machine Learning Framework. The implementation of `QuantizedMaxPool` has an undefined behavior where user controlled inp…

Fix: after 2.6.2
Fix from $1,600 2022-02-03
Tensorflow MEDIUM 6.5
CVE-2022-21734

Tensorflow is an Open Source Machine Learning Framework. The implementation of `MapStage` is vulnerable a `CHECK`-fail if the key tensor is not a sca…

Fix: after 2.6.2
Fix from $1,600 2022-02-03
Tensorflow MEDIUM 6.5
CVE-2022-21735

Tensorflow is an Open Source Machine Learning Framework. The implementation of `FractionalMaxPool` can be made to crash a TensorFlow process via a di…

Fix: after 2.6.2
Fix from $1,600 2022-02-03
Tensorflow MEDIUM 6.5
CVE-2022-23569

Tensorflow is an Open Source Machine Learning Framework. Multiple operations in TensorFlow can be used to trigger a denial of service via `CHECK`-fai…

Fix: after 2.6.2
Fix from $1,600 2022-02-03
Tensorflow MEDIUM 6.5
CVE-2022-21725

Tensorflow is an Open Source Machine Learning Framework. The estimator for the cost of some convolution operations can be made to execute a division …

Fix: after 2.6.2
Fix from $1,600 2022-02-03
Tensorflow MEDIUM 6.5
CVE-2022-21729

Tensorflow is an Open Source Machine Learning Framework. The implementation of `UnravelIndex` is vulnerable to a division by zero caused by an intege…

Fix: after 2.6.2
Fix from $1,600 2022-02-03
Tensorflow MEDIUM 6.5
CVE-2022-21736

Tensorflow is an Open Source Machine Learning Framework. The implementation of `SparseTensorSliceDataset` has an undefined behavior: under certain co…

Fix: after 2.6.2
Fix from $1,600 2022-02-03
Tensorflow MEDIUM 6.5
CVE-2022-23567

Tensorflow is an Open Source Machine Learning Framework. The implementations of `Sparse*Cwise*` ops are vulnerable to integer overflows. These can be…

Fix: after 2.6.2
Fix from $1,600 2022-02-03
Tensorflow MEDIUM 6.5
CVE-2022-23568

Tensorflow is an Open Source Machine Learning Framework. The implementation of `AddManySparseToTensorsMap` is vulnerable to an integer overflow which…

Fix: after 2.6.2
Fix from $1,600 2022-02-03
Tensorflow MEDIUM 6.5
CVE-2022-21731

Tensorflow is an Open Source Machine Learning Framework. The implementation of shape inference for `ConcatV2` can be used to trigger a denial of serv…

Fix: after 2.6.2
Fix from $1,600 2022-02-03
Tensorflow MEDIUM 6.5
CVE-2022-21732

Tensorflow is an Open Source Machine Learning Framework. The implementation of `ThreadPoolHandle` can be used to trigger a denial of service attack b…

Fix: after 2.6.2
Fix from $1,600 2022-02-03
Tensorflow MEDIUM 6.5
CVE-2022-21733

Tensorflow is an Open Source Machine Learning Framework. The implementation of `StringNGrams` can be used to trigger a denial of service attack by ca…

Fix: after 2.6.2
Fix from $1,600 2022-02-03
Tensorflow HIGH 8.1
CVE-2022-21728

Tensorflow is an Open Source Machine Learning Framework. The implementation of shape inference for `ReverseSequence` does not fully validate the valu…

Fix: after 2.6.2
Fix from $1,950 2022-02-03
Tensorflow HIGH 8.1
CVE-2022-21730

Tensorflow is an Open Source Machine Learning Framework. The implementation of `FractionalAvgPoolGrad` does not consider cases where the input tensor…

Fix: after 2.6.2
Fix from $1,950 2022-02-03
Tensorflow HIGH 8.8
CVE-2022-21726

Tensorflow is an Open Source Machine Learning Framework. The implementation of `Dequantize` does not fully validate the value of `axis` and can resul…

Fix: after 2.6.2
Fix from $1,950 2022-02-03
Tensorflow HIGH 8.8
CVE-2022-21727

Tensorflow is an Open Source Machine Learning Framework. The implementation of shape inference for `Dequantize` is vulnerable to an integer overflow …

Fix: after 2.6.2
Fix from $1,950 2022-02-03
Android MEDIUM 6.1
CVE-2022-23728

Attacker can reset the device with AT Command in the process of rebooting the device. The LG ID is LVE-SMP-210011.

Fix: 11.0+
Fix from $1,600 2022-01-21
Fuchsia CRITICAL 9.8
CVE-2021-22566

An incorrect setting of UXN bits within mmu_flags_to_s1_pte_attr lead to privileged executable pages being mapped as executable from an unprivileged …

Patch available
Fix from $2,300 2022-01-18
Android HIGH 7.8
CVE-2021-39630

In executeRequest of OverlayManagerService.java, there is a possible way to control fabricated overlays from adb shell due to a permissions bypass. T…

Mitigation only
Fix from $1,950 2022-01-14
Android HIGH 7.8
CVE-2021-39632

In inotify_cb of events.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privile…

Mitigation only
Fix from $1,950 2022-01-14
Android HIGH 7.8
CVE-2021-39634

In fs/eventpoll.c, there is a possible use after free. This could lead to local escalation of privilege with no additional execution privileges neede…

Patch available
Fix from $1,950 2022-01-14