Vulnerabilidades em tensorflow

403 resultados
Análise Vexday

Com 401 CVEs catalogadas, o TensorFlow acumula um volume expressivo de vulnerabilidades registradas, embora o cenário operacional atual seja relativamente estável: nenhuma entrada consta no catálogo KEV da CISA, taxa abaixo da média geral do catálogo, e nenhuma CVE nova foi registrada nos últimos 90 dias. A falha mais prevalente por categoria é CWE-20 (validação inadequada de entrada), padrão consistente com frameworks de processamento de dados que expõem superfícies de ataque por meio de tensores e grafos malformados. A CVE mais perigosa no momento, CVE-2024-3660, apresenta EPSS de 0,0175, indicando probabilidade baixa de exploração em curto prazo, ainda que 6 vulnerabilidades de severidade crítica e a existência de ao menos um PoC público justifiquem atenção contínua ao processo de atualização e revisão de dependências em ambientes de produção.

CVE-2022-29199MEDIUMMissing validation causes denial of service in TensorFlow via `LoadAndRemapMatrix`EPSS 0.3%CVE-2022-29195MEDIUMMissing validation causes denial of service in TensorFlow via `StagePeek`EPSS 0.3%CVE-2022-29196MEDIUMMissing validation causes denial of service in TensorFlow via `Conv3DBackpropFilterV2`EPSS 0.3%CVE-2022-29207MEDIUMUndefined behavior when users supply invalid resource handles in TensorFlowEPSS 0.3%CVE-2022-29205MEDIUMSegfault due to missing support for quantized types in TensorFlowEPSS 0.3%CVE-2022-29198MEDIUMMissing validation causes denial of service in TensorFlow via `SparseTensorToCSRSparseMatrix`EPSS 0.3%CVE-2022-29197MEDIUMMissing validation causes denial of service in TensorFlow via `UnsortedSegmentJoin`EPSS 0.3%CVE-2022-29193MEDIUMMissing validation causes `TensorSummaryV2` in TensorFlow to crashEPSS 0.3%CVE-2022-29200MEDIUMMissing validation causes denial of service in TensorFlow via `LSTMBlockCell`EPSS 0.3%CVE-2022-29212MEDIUMCore dump when loading TFLite models with quantization in TensorFlowEPSS 0.3%CVE-2022-29202MEDIUMDenial of service in TensorFlow due to lack of validation in `tf.ragged.constant`EPSS 0.3%CVE-2021-41197MEDIUMCrashes due to overflow and `CHECK`-fail in ops with large tensor shapesEPSS 0.3%CVE-2022-29211MEDIUMSegfault in TensorFlow if `tf.histogram_fixed_width` is called with NaN valuesEPSS 0.3%CVE-2022-29213MEDIUMIncomplete validation in signal ops leads to crashes in TensorFlowEPSS 0.3%CVE-2021-29544LOWCHECK-fail in `QuantizeAndDequantizeV4Grad`EPSS 0.3%CVE-2023-25667MEDIUMTensorFlow vulnerable to segfault when opening multiframe gifEPSS 0.3%CVE-2021-29612LOWHeap buffer overflow in `BandedTriangularSolve`EPSS 0.3%CVE-2021-29591HIGHStack overflow due to looping TFLite subgraphEPSS 0.3%CVE-2026-2492HIGHTensorFlow HDF5 Library Uncontrolled Search Path Element Local Privilege Escalation VulnerabilityEPSS 0.3%CVE-2020-26266MEDIUMUninitialized memory access in Eigen types in TensorFlowEPSS 0.3%