Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Android HIGH 7.5
CVE-2020-26598

An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, and 9.0 software. The Network Management component could allow an unauthorized…

Mitigation only
Fix from $1,950 2020-10-06
Android HIGH 7.5
CVE-2020-26600

An issue was discovered on Samsung mobile devices with Q(10.0) software. Auto Hotspot allows attackers to obtain sensitive information. The Samsung I…

Mitigation only
Fix from $1,950 2020-10-06
Android HIGH 7.5
CVE-2020-26601

An issue was discovered in DirEncryptService on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. PendingIntent with an empty intent …

Mitigation only
Fix from $1,950 2020-10-06
Android HIGH 7.5
CVE-2020-26602

An issue was discovered in EthernetNetwork on Samsung mobile devices with O(8.1), P(9.0), Q(10.0), and R(11.0) software. PendingIntent allows sdcard …

Mitigation only
Fix from $1,950 2020-10-06
Android MEDIUM 5.3
CVE-2020-26599

An issue was discovered on Samsung mobile devices with Q(10.0) software. The DynamicLockscreen Terms and Conditions can be accepted without authentic…

Mitigation only
Fix from $1,600 2020-10-06
Tensorflow CRITICAL 9.8
CVE-2020-15208

In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, when determining the common dimension size of two tensors, TFLite uses a `D…

Fix: 1.15.4 / 2.0.3+
Fix from $2,300 2020-09-25
Tensorflow HIGH 8.6
CVE-2020-15212

In TensorFlow Lite before versions 2.2.1 and 2.3.1, models using segment sum can trigger writes outside of bounds of heap allocated buffers by insert…

Fix: 2.2.1 / 2.3.1+
Fix from $1,950 2020-09-25
Tensorflow HIGH 8.1
CVE-2020-15214

In TensorFlow Lite before versions 2.2.1 and 2.3.1, models using segment sum can trigger a write out bounds / segmentation fault if the segment ids a…

Fix: 2.2.1 / 2.3.1+
Fix from $1,950 2020-09-25
Tensorflow MEDIUM 6.5
CVE-2020-15210

In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, if a TFLite saved model uses the same tensor as both input and output of an…

Fix: 1.15.4 / 2.0.3+
Fix from $1,600 2020-09-25
Tensorflow MEDIUM 5.9
CVE-2020-15209

In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, a crafted TFLite model can force a node to have as input a tensor backed by…

Fix: 1.15.4 / 2.0.3+
Fix from $1,600 2020-09-25
Tensorflow CRITICAL 9.8
CVE-2020-15205

In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `data_splits` argument of `tf.raw_ops.StringNGrams` lacks validation. This a…

Fix: 1.15.4 / 2.0.3+
Fix from $2,300 2020-09-25
Tensorflow CRITICAL 9.0
CVE-2020-15202

In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `Shard` API in TensorFlow expects the last argument to be a function taking …

Fix: 1.15.4 / 2.0.3+
Fix from $2,300 2020-09-25
Tensorflow CRITICAL 9.0
CVE-2020-15207

In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, to mimic Python's indexing with negative values, TFLite uses `ResolveAxis` …

Fix: 1.15.4 / 2.0.3+
Fix from $2,300 2020-09-25
Tensorflow HIGH 7.5
CVE-2020-15203

In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, by controlling the `fill` argument of tf.strings.as_string, a malicious attacker…

Fix: 1.15.4 / 2.0.3+
Fix from $1,950 2020-09-25
Tensorflow HIGH 7.5
CVE-2020-15206

In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, changing the TensorFlow's `SavedModel` protocol buffer and altering the name of …

Fix: 1.15.4 / 2.0.3+
Fix from $1,950 2020-09-25
Tensorflow MEDIUM 5.9
CVE-2020-15199

In Tensorflow before version 2.3.1, the `RaggedCountSparseOutput` does not validate that the input arguments form a valid ragged tensor. In particula…

Patch available
Fix from $1,600 2020-09-25
Tensorflow MEDIUM 5.9
CVE-2020-15200

In Tensorflow before version 2.3.1, the `RaggedCountSparseOutput` implementation does not validate that the input arguments form a valid ragged tenso…

Patch available
Fix from $1,600 2020-09-25
Tensorflow MEDIUM 5.4
CVE-2020-15198

In Tensorflow before version 2.3.1, the `SparseCountSparseOutput` implementation does not validate that the input arguments form a valid sparse tenso…

Fix: 2.3.1+
Fix from $1,600 2020-09-25
Tensorflow MEDIUM 5.3
CVE-2020-15204

In eager mode, TensorFlow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1 does not set the session state. Hence, calling `tf.raw_ops.GetSession…

Fix: 1.15.4 / 2.0.3+
Fix from $1,600 2020-09-25
Tensorflow CRITICAL 9.9
CVE-2020-15196

In Tensorflow version 2.3.0, the `SparseCountSparseOutput` and `RaggedCountSparseOutput` implementations don't validate that the `weights` tensor has…

Patch available
Fix from $2,300 2020-09-25
Tensorflow HIGH 8.8
CVE-2020-15195

In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the implementation of `SparseFillEmptyRowsGrad` uses a double indexing pattern. …

Fix: 1.15.4 / 2.0.3+
Fix from $1,950 2020-09-25
Tensorflow HIGH 7.1
CVE-2020-15193

In Tensorflow before versions 2.2.1 and 2.3.1, the implementation of `dlpack.to_dlpack` can be made to use uninitialized memory resulting in further …

Patch available
Fix from $1,950 2020-09-25
Tensorflow MEDIUM 6.3
CVE-2020-15197

In Tensorflow before version 2.3.1, the `SparseCountSparseOutput` implementation does not validate that the input arguments form a valid sparse tenso…

Patch available
Fix from $1,600 2020-09-25
Tensorflow MEDIUM 5.3
CVE-2020-15190

In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `tf.raw_ops.Switch` operation takes as input a tensor and a boolean and outp…

Fix: 1.15.4 / 2.0.3+
Fix from $1,600 2020-09-25
Tensorflow MEDIUM 5.3
CVE-2020-15191

In Tensorflow before versions 2.2.1 and 2.3.1, if a user passes an invalid argument to `dlpack.to_dlpack` the expected validations will cause variabl…

Patch available
Fix from $1,600 2020-09-25
Tensorflow MEDIUM 5.3
CVE-2020-15194

In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `SparseFillEmptyRowsGrad` implementation has incomplete validation of the sh…

Fix: 1.15.4 / 2.0.3+
Fix from $1,600 2020-09-25
Chrome CRITICAL 9.6
CVE-2020-6573

Use after free in video in Google Chrome on Android prior to 85.0.4183.102 allowed a remote attacker who had compromised the renderer process to pote…

Fix: 85.0.4183.102+
Fix from $2,300 2020-09-21
Chrome HIGH 8.8
CVE-2020-6576

Use after free in offscreen canvas in Google Chrome prior to 85.0.4183.102 allowed a remote attacker to potentially exploit heap corruption via a cra…

Fix: 85.0.4183.102+
Fix from $1,950 2020-09-21
Chrome HIGH 8.3
CVE-2020-6575

Race in Mojo in Google Chrome prior to 85.0.4183.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sand…

Fix: 85.0.4183.102+
Fix from $1,950 2020-09-21
Chrome HIGH 7.8
CVE-2020-6574

Insufficient policy enforcement in installer in Google Chrome on OS X prior to 85.0.4183.102 allowed a local attacker to potentially achieve privileg…

Fix: 85.0.4183.102+
Fix from $1,950 2020-09-21