Vulnerabilities in TensorFlow

403 results
Vexday analysis

TensorFlow apresenta um perfil de risco baixo com apenas 2 vulnerabilidades registradas na base, nenhuma sob exploração ativa conhecida e nenhuma classificada como crítica. A fraqueza dominante identificada é CWE-427 (validação imprópria de índices), sem atualizações de risco nos últimos 90 dias, indicando um cenário estável.

CVE-2021-37674MEDIUMIncomplete validation in `MaxPoolGrad` in TensorFlowEPSS 0.2%CVE-2021-37659HIGHOut of bounds read via null pointer dereference in TensorFlowEPSS 0.2%CVE-2021-37669MEDIUMCrash in NMS ops caused by integer conversion to unsigned in TensorFlowEPSS 0.2%CVE-2021-37651HIGHHeap buffer overflow in `FractionalAvgPoolGrad` in TensorFlowEPSS 0.2%CVE-2021-37663HIGHIncomplete validation in `QuantizeV2` in TensorFlowEPSS 0.2%CVE-2021-41208HIGHIncomplete validation in boosted trees codeEPSS 0.2%CVE-2021-37681HIGHNull pointer exception in TensorFlow LiteEPSS 0.2%CVE-2020-26270MEDIUMCHECK-fail in LSTM with zero-length input in TensorFlowEPSS 0.2%CVE-2021-37666HIGHReference binding to nullptr in `RaggedTensorToVariant` in TensorFlowEPSS 0.2%CVE-2021-37667HIGHReference binding to nullptr in unicode encoding in TensorFlowEPSS 0.2%CVE-2021-37686MEDIUMInfinite loop in TensorFlow LiteEPSS 0.2%CVE-2021-37652HIGHUse after free in boosted trees creation in TensorFlowEPSS 0.2%CVE-2021-37671HIGHReference binding to nullptr in map operations in TensorFlowEPSS 0.2%CVE-2021-37639HIGHNull pointer dereference and heap OOB read in TensorFlowEPSS 0.2%CVE-2021-37676HIGHReference binding to nullptr in shape inference in TensorFlowEPSS 0.2%CVE-2021-37685MEDIUMHeap OOB in TensorFlow LiteEPSS 0.2%CVE-2021-37692MEDIUMSegfault on strings tensors with mistmatched dimensions in TensorFlowEPSS 0.2%CVE-2021-37672MEDIUMHeap OOB in `SdcaOptimizerV2` in TensorFlowEPSS 0.2%CVE-2021-37670MEDIUMHeap OOB in `UpperBound` and `LowerBound` in TensorFlowEPSS 0.2%CVE-2021-37664HIGHHeap OOB in boosted trees in TensorFlowEPSS 0.2%