Vulnerabilidades em tensorflow

403 resultados
Análise Vexday

Com 401 CVEs catalogadas, o TensorFlow acumula um volume expressivo de vulnerabilidades registradas, embora o cenário operacional atual seja relativamente estável: nenhuma entrada consta no catálogo KEV da CISA, taxa abaixo da média geral do catálogo, e nenhuma CVE nova foi registrada nos últimos 90 dias. A falha mais prevalente por categoria é CWE-20 (validação inadequada de entrada), padrão consistente com frameworks de processamento de dados que expõem superfícies de ataque por meio de tensores e grafos malformados. A CVE mais perigosa no momento, CVE-2024-3660, apresenta EPSS de 0,0175, indicando probabilidade baixa de exploração em curto prazo, ainda que 6 vulnerabilidades de severidade crítica e a existência de ao menos um PoC público justifiquem atenção contínua ao processo de atualização e revisão de dependências em ambientes de produção.

CVE-2023-25674HIGHTensorFlow has Null Pointer Error in RandomShuffle with XLA enableEPSS 0.4%CVE-2023-25673HIGHTensorFlow has Floating Point Exception in TensorListSplit with XLA EPSS 0.4%CVE-2023-25676HIGHTensorFlow has null dereference on ParallelConcat with XLAEPSS 0.4%CVE-2023-25662HIGHTensorFlow vulnerable to integer overflow in EditDistanceEPSS 0.4%CVE-2023-25669HIGHTensorFlow has Floating Point Exception in AvgPoolGrad with XLAEPSS 0.4%CVE-2023-25670HIGHTensorFlow has Null Pointer Error in QuantizedMatMulWithBiasAndDequantizeEPSS 0.4%CVE-2022-29209MEDIUMType confusion leading to `CHECK`-failure based denial of service in TensorFlowEPSS 0.4%CVE-2023-25658HIGHTensorFlow vulnerable to Out-of-Bounds Read in GRUBlockCellGradEPSS 0.4%CVE-2023-25666HIGHTensorFlow has Floating Point Exception in AudioSpectrogram EPSS 0.4%CVE-2022-29208HIGHSegfault and Out-of-bounds Write write due to incomplete validation in TensorFlowEPSS 0.4%CVE-2022-41883MEDIUMOut of bounds segmentation fault due to unequal op inputs in TensorflowEPSS 0.4%CVE-2023-25672HIGHTensorFlow has Null Pointer Error in LookupTableImportV2EPSS 0.4%CVE-2022-41884MEDIUMSeg fault in `ndarray_tensor_bridge` due to zero and large inputs in TensorflowEPSS 0.4%CVE-2022-29191MEDIUMMissing validation causes denial of service via `GetSessionTensor` in TensorFlowEPSS 0.4%CVE-2022-29204MEDIUMMissing validation causes denial of service in TensorFlow via `Conv3DBackpropFilterV2`EPSS 0.3%CVE-2022-29192MEDIUMMissing validation crashes `QuantizeAndDequantizeV4Grad` in TensorFlowEPSS 0.3%CVE-2022-29206MEDIUMMissing validation results in undefined behavior in `SparseTensorDenseAdd` in TensorFlowEPSS 0.3%CVE-2022-29201MEDIUMMissing validation in `QuantizedConv2D` results in undefined behavior in TensorFlowEPSS 0.3%CVE-2022-29203MEDIUMInteger overflow in `SpaceToBatchND` in TensorFlowEPSS 0.3%CVE-2022-29194MEDIUMMissing validation causes denial of service via `DeleteSessionTensor` in TensorFlowEPSS 0.3%