Vulnerabilidades em tensorflow

403 resultados
Análise Vexday

Com 401 CVEs catalogadas, o TensorFlow acumula um volume expressivo de vulnerabilidades registradas, embora o cenário operacional atual seja relativamente estável: nenhuma entrada consta no catálogo KEV da CISA, taxa abaixo da média geral do catálogo, e nenhuma CVE nova foi registrada nos últimos 90 dias. A falha mais prevalente por categoria é CWE-20 (validação inadequada de entrada), padrão consistente com frameworks de processamento de dados que expõem superfícies de ataque por meio de tensores e grafos malformados. A CVE mais perigosa no momento, CVE-2024-3660, apresenta EPSS de 0,0175, indicando probabilidade baixa de exploração em curto prazo, ainda que 6 vulnerabilidades de severidade crítica e a existência de ao menos um PoC público justifiquem atenção contínua ao processo de atualização e revisão de dependências em ambientes de produção.

CVE-2022-35990MEDIUM`CHECK` fail in `FakeQuantWithMinMaxVarsPerChannelGradient` in TensorFlowEPSS 0.5%CVE-2022-35969MEDIUM`CHECK` fail in `Conv2DBackpropInput` in TensorFlowEPSS 0.5%CVE-2022-35971MEDIUM`CHECK` fail in `FakeQuantWithMinMaxVars` in TensorFlowEPSS 0.5%CVE-2022-35965MEDIUMSegfault in `LowerBound` and `UpperBound` in TensorFlowEPSS 0.5%CVE-2022-36018MEDIUM`CHECK` fail in `RaggedTensorToVariant` in TensorFlowEPSS 0.5%CVE-2022-35959MEDIUM`CHECK` failures in `AvgPool3DGrad` in TensorFlowEPSS 0.5%CVE-2021-37678CRITICALArbitrary code execution due to YAML deserializationEPSS 0.4%CVE-2023-25665HIGHTensorFlow has Null Pointer Error in SparseSparseMaximumEPSS 0.4%CVE-2023-25661MEDIUMDenial of Service in TensorFlowEPSS 0.4%CVE-2022-41889MEDIUMSegfault via invalid attributes in `pywrap_tfe_src.cc` in TensorflowEPSS 0.4%CVE-2023-33976HIGHTensorFlow segfault in array_ops.upper_boundEPSS 0.4%CVE-2022-41911MEDIUMInvalid char to bool conversion when printing a tensor in TensorflowEPSS 0.4%CVE-2022-41910MEDIUMHeap out of bounds read in `QuantizeAndDequantizeV2` in TensorflowEPSS 0.4%CVE-2023-25664HIGHTensorFlow vulnerable to Heap Buffer Overflow in AvgPoolGrad EPSS 0.4%CVE-2022-41880MEDIUMThreadUnsafeUnigramCandidateSampler Heap out of bounds in TensorflowEPSS 0.4%CVE-2023-25660HIGHTensorFlow vulnerable to seg fault in `tf.raw_ops.Print`EPSS 0.4%CVE-2023-25659HIGHTensorFlow vulnerable to Out-of-Bounds Read in DynamicStitchEPSS 0.4%CVE-2023-25663HIGHTensorFlow has Null Pointer Error in TensorArrayConcatV2EPSS 0.4%CVE-2023-27579HIGHTensorFlow has Floating Point Exception in TFLite in conv kernelEPSS 0.4%CVE-2023-25674HIGHTensorFlow has Null Pointer Error in RandomShuffle with XLA enableEPSS 0.4%