Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tensorflow MEDIUM 5.5
CVE-2021-29519

TensorFlow is an end-to-end open source platform for machine learning. The API of `tf.raw_ops.SparseCross` allows combinations which would result in …

Fix: 2.1.4 / 2.2.3+
Fix from $1,600 2021-05-14
Tensorflow MEDIUM 5.5
CVE-2021-29521

TensorFlow is an end-to-end open source platform for machine learning. Specifying a negative dense shape in `tf.raw_ops.SparseCountSparseOutput` resu…

Fix: 2.3.3 / 2.4.2+
Fix from $1,600 2021-05-14
Tensorflow MEDIUM 5.5
CVE-2021-29522

TensorFlow is an end-to-end open source platform for machine learning. The `tf.raw_ops.Conv3DBackprop*` operations fail to validate that the input te…

Fix: 2.1.4 / 2.2.3+
Fix from $1,600 2021-05-14
Tensorflow MEDIUM 5.5
CVE-2021-29523

TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a denial of service via a `CHECK`-fail in `tf.raw_ops.…

Fix: 2.1.4 / 2.2.3+
Fix from $1,600 2021-05-14
Tensorflow MEDIUM 5.5
CVE-2021-29524

TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a division by 0 in `tf.raw_ops.Conv2DBackpropFilter`. …

Fix: 2.1.4 / 2.2.3+
Fix from $1,600 2021-05-14
Tensorflow MEDIUM 5.5
CVE-2021-29526

TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a division by 0 in `tf.raw_ops.Conv2D`. This is becaus…

Fix: 2.1.4 / 2.2.3+
Fix from $1,600 2021-05-14
Tensorflow MEDIUM 5.5
CVE-2021-29527

TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a division by 0 in `tf.raw_ops.QuantizedConv2D`. This …

Fix: 2.1.4 / 2.2.3+
Fix from $1,600 2021-05-14
Tensorflow MEDIUM 5.5
CVE-2021-29528

TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a division by 0 in `tf.raw_ops.QuantizedMul`. This is …

Fix: 2.1.4 / 2.2.3+
Fix from $1,600 2021-05-14
Tensorflow HIGH 7.8
CVE-2021-29512

TensorFlow is an end-to-end open source platform for machine learning. If the `splits` argument of `RaggedBincount` does not specify a valid `SparseT…

Fix: 2.3.3 / 2.4.2+
Fix from $1,950 2021-05-14
Tensorflow MEDIUM 5.5
CVE-2021-29554

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service via a FPE runtime error in `tf.raw_o…

Fix: 2.1.4 / 2.2.3+
Fix from $1,600 2021-05-14
Cloud Iot Device Sdk For Embedded C HIGH 7.8
CVE-2021-22547

In IoT Devices SDK, there is an implementation of calloc() that doesn't have a length check. An attacker could pass in memory objects larger than the…

Fix: 1.0.3+
Fix from $1,950 2021-05-04
Chrome HIGH 8.8
CVE-2021-21227

Insufficient data validation in V8 in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a craf…

Fix: 90.0.4430.93+
Fix from $1,950 2021-04-30
Chrome HIGH 8.8
CVE-2021-21230

Type confusion in V8 in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Fix: 90.0.4430.93+
Fix from $1,950 2021-04-30
Chrome HIGH 8.8
CVE-2021-21231

Insufficient data validation in V8 in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a craf…

Fix: 90.0.4430.93+
Fix from $1,950 2021-04-30
Chrome HIGH 8.8
CVE-2021-21232

Use after free in Dev Tools in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM…

Fix: 90.0.4430.93+
Fix from $1,950 2021-04-30
Chrome HIGH 8.8
CVE-2021-21233

Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via …

Fix: 90.0.4430.93+
Fix from $1,950 2021-04-30
Chrome MEDIUM 6.5
CVE-2021-21229

Incorrect security UI in downloads in Google Chrome on Android prior to 90.0.4430.93 allowed a remote attacker to perform domain spoofing via a craft…

Fix: 90.0.4430.93+
Fix from $1,600 2021-04-30
Chrome CRITICAL 9.6
CVE-2021-21201

Use after free in permissions in Google Chrome prior to 90.0.4430.72 allowed a remote attacker who had compromised the renderer process to potentiall…

Fix: 90.0.4430.72+
Fix from $2,300 2021-04-26
Chrome CRITICAL 9.6
CVE-2021-21223

Integer overflow in Mojo in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the renderer process to potentially per…

Fix: 90.0.4430.85+
Fix from $2,300 2021-04-26
Chrome CRITICAL 9.6
CVE-2021-21226

Use after free in navigation in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the renderer process to potentially…

Fix: 90.0.4430.85+
Fix from $2,300 2021-04-26
Chrome HIGH 8.8
CVE-2021-21203

Use after free in Blink in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pa…

Fix: 90.0.4430.72+
Fix from $1,950 2021-04-26
Chrome HIGH 8.8
CVE-2021-21204

Use after free in Blink in Google Chrome on OS X prior to 90.0.4430.72 allowed a remote attacker to potentially exploit heap corruption via a crafted…

Fix: 90.0.4430.72+
Fix from $1,950 2021-04-26
Chrome HIGH 8.8
CVE-2021-21206 KEVEPSS 9%

Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

Fix: 89.0.4389.128+
Fix from $1,950 2021-04-26
Chrome HIGH 8.8
CVE-2021-21213

Use after free in WebMIDI in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Fix: 90.0.4430.72+
Fix from $1,950 2021-04-26
Chrome HIGH 8.8
CVE-2021-21214

Use after free in Network API in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to potentially exploit heap corruption via a crafted C…

Fix: 90.0.4430.72+
Fix from $1,950 2021-04-26
Chrome HIGH 8.8
CVE-2021-21220 KEVEPSS 69%

Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corrup…

Fix: 89.0.4389.128+
Fix from $1,950 2021-04-26
Chrome HIGH 8.8
CVE-2021-21224 KEVEPSS 56%

Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML p…

Fix: 90.0.4430.85+
Fix from $1,950 2021-04-26
Chrome HIGH 8.8
CVE-2021-21225EPSS 7%

Out of bounds memory access in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to potentially exploit heap corruption via a craft…

Fix: 90.0.4430.85+
Fix from $1,950 2021-04-26
Chrome HIGH 8.6
CVE-2021-21202

Use after free in extensions in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install a malicious extension to pote…

Fix: 90.0.4430.72+
Fix from $1,950 2021-04-26
Chrome HIGH 8.6
CVE-2021-21207

Use after free in IndexedDB in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install a malicious extension to poten…

Fix: 90.0.4430.72+
Fix from $1,950 2021-04-26