Google Security Advisories · May 2021 — Google Security Advisories
1081 advisories 664 CVEs 29 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2021-05. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 29 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2021-28550

GoogleExploitedCISA KEV listedCRITICAL2021-05-12

Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by a Use After Free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arb...

CVEs:CVE-2021-28550

Affected products

ProductStatusVendorPackageEcosystem
acrobat affected adobe
acrobat_dc affected adobe
acrobat_reader affected adobe
acrobat_reader_dc affected adobe
Upstream advisory

CVE-2021-30533

GoogleExploitedCISA KEV listedCRITICAL2021-05-26

Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions via a crafted iframe.

CVEs:CVE-2021-30533

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-28663

GoogleExploitedCISA KEV listedCRITICAL2021-05-04

The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a use-after-free. This affects Bifrost r0p0 through r28p0 before r29p0, Valhall r19p0 through r28p0 before r29...

CVEs:CVE-2021-28663

Affected products

ProductStatusVendorPackageEcosystem
bifrost_gpu_kernel_driver affected arm
midgard_gpu_kernel_driver affected arm
valhall_gpu_kernel_driver affected arm
Upstream advisory

CVE-2021-28663

Project ZeroExploitedCISA KEV listed2021-05-04

The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a use-after-free. This affects Bifrost r0p0 through r28p0 before r29p0, Valhall r19p0 through r28p0 before r29p0, and Midgard r4p0 through r30p0.

CVEs:CVE-2021-28663

Upstream advisory

ASB-A-174259860

GoogleExploitedCISA KEV listedNONE2021-05-01

ASB-A-174259860

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-28664

GoogleExploitedCISA KEV listedHIGH2021-05-04

The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve read/write access to read-only pages. This affects Bifrost r0p0 through r29p0 before r30p0, Valhall r19p0 thr...

CVEs:CVE-2021-28664

Affected products

ProductStatusVendorPackageEcosystem
bifrost_gpu_kernel_driver affected arm
midgard_gpu_kernel_driver affected arm
valhall_gpu_kernel_driver affected arm
Upstream advisory

CVE-2021-28664

Project ZeroExploitedCISA KEV listed2021-05-04

The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve read/write access to read-only pages. This affects Bifrost r0p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r8p0 through r30p0 before r31p0.

CVEs:CVE-2021-28664

Upstream advisory

ASB-A-174588870

GoogleExploitedCISA KEV listedHIGH2021-05-01

ASB-A-174588870

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-30665

GoogleExploitedCISA KEV listedCRITICAL2021-05-04

A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 7.4.1, iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6, iOS 12.5.3, macOS Big Sur 11.3.1. Processing maliciously crafted web content may lead to arbitrary co...

CVEs:CVE-2021-30665

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2021-30665

Project ZeroExploitedCISA KEV listed2021-05-04

A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 7.4.1, iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6, iOS 12.5.3, macOS Big Sur 11.3.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

CVEs:CVE-2021-30665

Upstream advisory

CVE-2021-30663

GoogleExploitedCISA KEV listedCRITICAL2021-05-04

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6, iOS 12.5.3, Safari 14.1.1, macOS Big Sur 11.3.1. Processing maliciously crafted web content may lead to arbitrary code exe...

CVEs:CVE-2021-30663

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2021-30663

Project ZeroExploitedCISA KEV listed2021-05-04

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6, iOS 12.5.3, Safari 14.1.1, macOS Big Sur 11.3.1. Processing maliciously crafted web content may lead to arbitrary code execution.

CVEs:CVE-2021-30663

Upstream advisory

CVE-2021-1905

Project ZeroExploitedCISA KEV listed2021-05-04

Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVEs:CVE-2021-1905

Upstream advisory

CVE-2021-1905

GoogleExploitedCISA KEV listedCRITICAL2021-05-04

Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon ...

CVEs:CVE-2021-1905

Affected products

ProductStatusVendorPackageEcosystem
apq8009_firmware affected qualcomm
apq8009w_firmware affected qualcomm
apq8017_firmware affected qualcomm
apq8053_firmware affected qualcomm
apq8064au_firmware affected qualcomm
apq8096au_firmware affected qualcomm
aqt1000_firmware affected qualcomm
ar8031_firmware affected qualcomm
ar8035_firmware affected qualcomm
ar8151_firmware affected qualcomm
csra6620_firmware affected qualcomm
csra6640_firmware affected qualcomm
fsm10055_firmware affected qualcomm
fsm10056_firmware affected qualcomm
mdm9206_firmware affected qualcomm
mdm9607_firmware affected qualcomm
mdm9626_firmware affected qualcomm
mdm9628_firmware affected qualcomm
mdm9650_firmware affected qualcomm
msm8909w_firmware affected qualcomm
msm8917_firmware affected qualcomm
msm8953_firmware affected qualcomm
msm8996au_firmware affected qualcomm
pm215_firmware affected qualcomm
pm3003a_firmware affected qualcomm
pm4125_firmware affected qualcomm
pm4250_firmware affected qualcomm
pm439_firmware affected qualcomm
pm456_firmware affected qualcomm
pm6125_firmware affected qualcomm
pm6150a_firmware affected qualcomm
pm6150_firmware affected qualcomm
pm6150l_firmware affected qualcomm
pm6250_firmware affected qualcomm
pm6350_firmware affected qualcomm
pm640a_firmware affected qualcomm
pm640l_firmware affected qualcomm
pm640p_firmware affected qualcomm
pm660a_firmware affected qualcomm
pm660_firmware affected qualcomm
pm660l_firmware affected qualcomm
pm670a_firmware affected qualcomm
pm670_firmware affected qualcomm
pm670l_firmware affected qualcomm
pm7150a_firmware affected qualcomm
pm7150l_firmware affected qualcomm
pm7250b_firmware affected qualcomm
pm7250_firmware affected qualcomm
pm8004_firmware affected qualcomm
pm8005_firmware affected qualcomm
pm8008_firmware affected qualcomm
pm8009_firmware affected qualcomm
pm8150a_firmware affected qualcomm
pm8150b_firmware affected qualcomm
pm8150c_firmware affected qualcomm
pm8150_firmware affected qualcomm
pm8150l_firmware affected qualcomm
pm8250_firmware affected qualcomm
pm8350b_firmware affected qualcomm
pm8350bh_firmware affected qualcomm
pm8350c_firmware affected qualcomm
pm8350_firmware affected qualcomm
pm855a_firmware affected qualcomm
pm855b_firmware affected qualcomm
pm855_firmware affected qualcomm
pm855l_firmware affected qualcomm
pm855p_firmware affected qualcomm
pm8909_firmware affected qualcomm
pm8916_firmware affected qualcomm
pm8937_firmware affected qualcomm
pm8953_firmware affected qualcomm
pm8998_firmware affected qualcomm
pmc1000h_firmware affected qualcomm
pmd9607_firmware affected qualcomm
pmd9655_firmware affected qualcomm
pme605_firmware affected qualcomm
pmi632_firmware affected qualcomm
pmi8937_firmware affected qualcomm
pmi8952_firmware affected qualcomm
pmi8998_firmware affected qualcomm
pmk8002_firmware affected qualcomm
pmk8003_firmware affected qualcomm
pmk8350_firmware affected qualcomm
pmm6155au_firmware affected qualcomm
pmm8155au_firmware affected qualcomm
pmm8195au_firmware affected qualcomm
pmm855au_firmware affected qualcomm
pmm8920au_firmware affected qualcomm
pmm8996au_firmware affected qualcomm
pmr525_firmware affected qualcomm
pmr735a_firmware affected qualcomm
pmr735b_firmware affected qualcomm
pmw3100_firmware affected qualcomm
pmx20_firmware affected qualcomm
pmx24_firmware affected qualcomm
pmx50_firmware affected qualcomm
pmx55_firmware affected qualcomm
qat3514_firmware affected qualcomm
qat3516_firmware affected qualcomm
qat3518_firmware affected qualcomm
qat3519_firmware affected qualcomm
qat3522_firmware affected qualcomm
qat3550_firmware affected qualcomm
qat3555_firmware affected qualcomm
qat5515_firmware affected qualcomm
qat5516_firmware affected qualcomm
qat5522_firmware affected qualcomm
qat5533_firmware affected qualcomm
qat5568_firmware affected qualcomm
qbt1000_firmware affected qualcomm
qbt1500_firmware affected qualcomm
qbt2000_firmware affected qualcomm
qca4020_firmware affected qualcomm
qca6174a_firmware affected qualcomm
qca6174_firmware affected qualcomm
qca6310_firmware affected qualcomm
qca6320_firmware affected qualcomm
qca6335_firmware affected qualcomm
qca6390_firmware affected qualcomm
qca6391_firmware affected qualcomm
qca6420_firmware affected qualcomm
qca6421_firmware affected qualcomm
qca6426_firmware affected qualcomm
qca6430_firmware affected qualcomm
qca6431_firmware affected qualcomm
qca6436_firmware affected qualcomm
qca6564a_firmware affected qualcomm
qca6564au_firmware affected qualcomm
qca6564_firmware affected qualcomm
qca6574a_firmware affected qualcomm
qca6574au_firmware affected qualcomm
qca6574_firmware affected qualcomm
qca6584au_firmware affected qualcomm
qca6595au_firmware affected qualcomm
qca6696_firmware affected qualcomm
qca8337_firmware affected qualcomm
qca9367_firmware affected qualcomm
qca9377_firmware affected qualcomm
qca9379_firmware affected qualcomm
qcc1110_firmware affected qualcomm
qcm2290_firmware affected qualcomm
qcm4290_firmware affected qualcomm
qcm6125_firmware affected qualcomm
qcs2290_firmware affected qualcomm
qcs405_firmware affected qualcomm
qcs410_firmware affected qualcomm
qcs4290_firmware affected qualcomm
qcs603_firmware affected qualcomm
qcs605_firmware affected qualcomm
qcs610_firmware affected qualcomm
qcs6125_firmware affected qualcomm
qdm2301_firmware affected qualcomm
qdm2302_firmware affected qualcomm
qdm2305_firmware affected qualcomm
qdm2307_firmware affected qualcomm
qdm2308_firmware affected qualcomm
qdm2310_firmware affected qualcomm
qdm3301_firmware affected qualcomm
qdm4643_firmware affected qualcomm
qdm4650_firmware affected qualcomm
qdm5620_firmware affected qualcomm
qdm5621_firmware affected qualcomm
qdm5650_firmware affected qualcomm
qdm5652_firmware affected qualcomm
qdm5670_firmware affected qualcomm
qdm5671_firmware affected qualcomm
qdm5677_firmware affected qualcomm
qdm5679_firmware affected qualcomm
qet4100_firmware affected qualcomm
qet4101_firmware affected qualcomm
qet5100_firmware affected qualcomm
qet5100m_firmware affected qualcomm
qet6100_firmware affected qualcomm
qet6105_firmware affected qualcomm
qet6110_firmware affected qualcomm
qfe2101_firmware affected qualcomm
qfe2520_firmware affected qualcomm
qfe2550_firmware affected qualcomm
qfe3100_firmware affected qualcomm
qfe3340_firmware affected qualcomm
qfe4301_firmware affected qualcomm
qfe4302_firmware affected qualcomm
qfe4303_firmware affected qualcomm
qfe4305_firmware affected qualcomm
qfe4308_firmware affected qualcomm
qfe4309_firmware affected qualcomm
qfe4320_firmware affected qualcomm
qfe4373fc_firmware affected qualcomm
qfs2530_firmware affected qualcomm
qfs2580_firmware affected qualcomm
qfs2608_firmware affected qualcomm
qfs2630_firmware affected qualcomm
qln1020_firmware affected qualcomm
qln1030_firmware affected qualcomm
qln4640_firmware affected qualcomm
qln4642_firmware affected qualcomm
qln4650_firmware affected qualcomm
qln5020_firmware affected qualcomm
qln5030_firmware affected qualcomm
qln5040_firmware affected qualcomm
qpa2625_firmware affected qualcomm
qpa4340_firmware affected qualcomm
qpa4360_firmware affected qualcomm
qpa4361_firmware affected qualcomm
qpa5373_firmware affected qualcomm
qpa5460_firmware affected qualcomm
qpa5461_firmware affected qualcomm
qpa5580_firmware affected qualcomm
qpa5581_firmware affected qualcomm
qpa6560_firmware affected qualcomm
qpa8673_firmware affected qualcomm
qpa8675_firmware affected qualcomm
qpa8686_firmware affected qualcomm
qpa8801_firmware affected qualcomm
qpa8802_firmware affected qualcomm
qpa8803_firmware affected qualcomm
qpa8821_firmware affected qualcomm
qpa8842_firmware affected qualcomm
qpm2630_firmware affected qualcomm
qpm4621_firmware affected qualcomm
qpm4630_firmware affected qualcomm
qpm4640_firmware affected qualcomm
qpm4641_firmware affected qualcomm
qpm4650_firmware affected qualcomm
qpm5541_firmware affected qualcomm
qpm5577_firmware affected qualcomm
qpm5579_firmware affected qualcomm
qpm5620_firmware affected qualcomm
qpm5621_firmware affected qualcomm
qpm5641_firmware affected qualcomm
qpm5657_firmware affected qualcomm
qpm5658_firmware affected qualcomm
qpm5670_firmware affected qualcomm
qpm5677_firmware affected qualcomm
qpm5679_firmware affected qualcomm
qpm5870_firmware affected qualcomm
qpm5875_firmware affected qualcomm
qpm6325_firmware affected qualcomm
qpm6375_firmware affected qualcomm
qpm6582_firmware affected qualcomm
qpm6585_firmware affected qualcomm
qpm6621_firmware affected qualcomm
qpm6670_firmware affected qualcomm
qpm8820_firmware affected qualcomm
qpm8830_firmware affected qualcomm
qpm8870_firmware affected qualcomm
qpm8895_firmware affected qualcomm
qsm7250_firmware affected qualcomm
qsm8250_firmware affected qualcomm
qsw6310_firmware affected qualcomm
qsw8573_firmware affected qualcomm
qsw8574_firmware affected qualcomm
qtc410s_firmware affected qualcomm
qtc800h_firmware affected qualcomm
qtc800s_firmware affected qualcomm
qtc800t_firmware affected qualcomm
qtc801s_firmware affected qualcomm
qtm525_firmware affected qualcomm
qtm527_firmware affected qualcomm
qualcomm215_firmware affected qualcomm
rgr7640au_firmware affected qualcomm
rsw8577_firmware affected qualcomm
sa2150p_firmware affected qualcomm
sa515m_firmware affected qualcomm
sa6145p_firmware affected qualcomm
sa6150p_firmware affected qualcomm
sa6155_firmware affected qualcomm
sa6155p_firmware affected qualcomm
sa8150p_firmware affected qualcomm
sa8155_firmware affected qualcomm
sa8155p_firmware affected qualcomm
sa8195p_firmware affected qualcomm
sd205_firmware affected qualcomm
sd210_firmware affected qualcomm
sd429_firmware affected qualcomm
sd439_firmware affected qualcomm
sd450_firmware affected qualcomm
sd455_firmware affected qualcomm
sd460_firmware affected qualcomm
sd480_firmware affected qualcomm
sd632_firmware affected qualcomm
sd636_firmware affected qualcomm
sd660_firmware affected qualcomm
sd662_firmware affected qualcomm
sd665_firmware affected qualcomm
sd670_firmware affected qualcomm
sd675_firmware affected qualcomm
sd678_firmware affected qualcomm
sd6905g_firmware affected qualcomm
sd710_firmware affected qualcomm
sd720g_firmware affected qualcomm
sd730_firmware affected qualcomm
sd750g_firmware affected qualcomm
sd765_firmware affected qualcomm
sd765g_firmware affected qualcomm
sd768g_firmware affected qualcomm
sd835_firmware affected qualcomm
sd845_firmware affected qualcomm
sd855_firmware affected qualcomm
sd8655g_firmware affected qualcomm
sd870_firmware affected qualcomm
sd8885g_firmware affected qualcomm
sd888_firmware affected qualcomm
sd8c_firmware affected qualcomm
sd8cx_firmware affected qualcomm
sda429w_firmware affected qualcomm
sdm429w_firmware affected qualcomm
sdm630_firmware affected qualcomm
sdm830_firmware affected qualcomm
sdr051_firmware affected qualcomm
sdr052_firmware affected qualcomm
sdr425_firmware affected qualcomm
sdr660_firmware affected qualcomm
sdr660g_firmware affected qualcomm
sdr675_firmware affected qualcomm
sdr735_firmware affected qualcomm
sdr735g_firmware affected qualcomm
sdr8150_firmware affected qualcomm
sdr8250_firmware affected qualcomm
sdr845_firmware affected qualcomm
sdr865_firmware affected qualcomm
sdw2500_firmware affected qualcomm
sdw3100_firmware affected qualcomm
sdx20_firmware affected qualcomm
sdx20m_firmware affected qualcomm
sdx24_firmware affected qualcomm
sdx50m_firmware affected qualcomm
sdx55_firmware affected qualcomm
sdx55m_firmware affected qualcomm
sdxr1_firmware affected qualcomm
sdxr2_5g_firmware affected qualcomm
sm4125_firmware affected qualcomm
sm6250_firmware affected qualcomm
sm6250p_firmware affected qualcomm
sm7250p_firmware affected qualcomm
smb1350_firmware affected qualcomm
smb1351_firmware affected qualcomm
smb1354_firmware affected qualcomm
smb1355_firmware affected qualcomm
smb1357_firmware affected qualcomm
smb1358_firmware affected qualcomm
smb1360_firmware affected qualcomm
smb1380_firmware affected qualcomm
smb1381_firmware affected qualcomm
smb1390_firmware affected qualcomm
smb1395_firmware affected qualcomm
smb1396_firmware affected qualcomm
smb1398_firmware affected qualcomm
smb231_firmware affected qualcomm
smb2351_firmware affected qualcomm
smb358s_firmware affected qualcomm
smr525_firmware affected qualcomm
smr526_firmware affected qualcomm
smr545_firmware affected qualcomm
smr546_firmware affected qualcomm
wcd9326_firmware affected qualcomm
wcd9330_firmware affected qualcomm
wcd9335_firmware affected qualcomm
wcd9340_firmware affected qualcomm
wcd9341_firmware affected qualcomm
wcd9360_firmware affected qualcomm
wcd9370_firmware affected qualcomm
wcd9371_firmware affected qualcomm
wcd9375_firmware affected qualcomm
wcd9380_firmware affected qualcomm
wcd9385_firmware affected qualcomm
wcn3610_firmware affected qualcomm
wcn3615_firmware affected qualcomm
wcn3620_firmware affected qualcomm
wcn3660b_firmware affected qualcomm
wcn3660_firmware affected qualcomm
wcn3680b_firmware affected qualcomm
wcn3680_firmware affected qualcomm
wcn3910_firmware affected qualcomm
wcn3950_firmware affected qualcomm
wcn3980_firmware affected qualcomm
wcn3988_firmware affected qualcomm
wcn3990_firmware affected qualcomm
wcn3991_firmware affected qualcomm
wcn3998_firmware affected qualcomm
wcn3999_firmware affected qualcomm
wcn6850_firmware affected qualcomm
wcn6851_firmware affected qualcomm
wcn6855_firmware affected qualcomm
wcn6856_firmware affected qualcomm
wgr7640_firmware affected qualcomm
wsa8810_firmware affected qualcomm
wsa8815_firmware affected qualcomm
wsa8830_firmware affected qualcomm
wsa8835_firmware affected qualcomm
wtr2955_firmware affected qualcomm
wtr2965_firmware affected qualcomm
wtr3925_firmware affected qualcomm
wtr4905_firmware affected qualcomm
wtr5975_firmware affected qualcomm
wtr6955_firmware affected qualcomm
Upstream advisory

ASB-A-178809945

GoogleExploitedCISA KEV listed2021-05-01

ASB-A-178809945

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2021-1906

Project ZeroExploitedCISA KEV listed2021-05-04

Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVEs:CVE-2021-1906

Upstream advisory

CVE-2021-1906

GoogleExploitedCISA KEV listedMEDIUM2021-05-04

Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Vo...

CVEs:CVE-2021-1906

Affected products

ProductStatusVendorPackageEcosystem
apq8009_firmware affected qualcomm
apq8009w_firmware affected qualcomm
apq8017_firmware affected qualcomm
apq8053_firmware affected qualcomm
apq8064au_firmware affected qualcomm
apq8096au_firmware affected qualcomm
aqt1000_firmware affected qualcomm
ar8031_firmware affected qualcomm
ar8035_firmware affected qualcomm
ar8151_firmware affected qualcomm
csra6620_firmware affected qualcomm
csra6640_firmware affected qualcomm
csrb31024_firmware affected qualcomm
fsm10055_firmware affected qualcomm
fsm10056_firmware affected qualcomm
mdm9150_firmware affected qualcomm
mdm9206_firmware affected qualcomm
mdm9250_firmware affected qualcomm
mdm9607_firmware affected qualcomm
mdm9626_firmware affected qualcomm
mdm9628_firmware affected qualcomm
mdm9650_firmware affected qualcomm
msm8909w_firmware affected qualcomm
msm8917_firmware affected qualcomm
msm8953_firmware affected qualcomm
msm8996au_firmware affected qualcomm
pm215_firmware affected qualcomm
pm3003a_firmware affected qualcomm
pm4125_firmware affected qualcomm
pm4250_firmware affected qualcomm
pm439_firmware affected qualcomm
pm456_firmware affected qualcomm
pm6125_firmware affected qualcomm
pm6150a_firmware affected qualcomm
pm6150_firmware affected qualcomm
pm6150l_firmware affected qualcomm
pm6250_firmware affected qualcomm
pm6350_firmware affected qualcomm
pm640a_firmware affected qualcomm
pm640l_firmware affected qualcomm
pm640p_firmware affected qualcomm
pm660a_firmware affected qualcomm
pm660_firmware affected qualcomm
pm660l_firmware affected qualcomm
pm670a_firmware affected qualcomm
pm670_firmware affected qualcomm
pm670l_firmware affected qualcomm
pm7150a_firmware affected qualcomm
pm7150l_firmware affected qualcomm
pm7250b_firmware affected qualcomm
pm7250_firmware affected qualcomm
pm7350c_firmware affected qualcomm
pm8004_firmware affected qualcomm
pm8005_firmware affected qualcomm
pm8008_firmware affected qualcomm
pm8009_firmware affected qualcomm
pm8150a_firmware affected qualcomm
pm8150b_firmware affected qualcomm
pm8150c_firmware affected qualcomm
pm8150_firmware affected qualcomm
pm8150l_firmware affected qualcomm
pm8250_firmware affected qualcomm
pm8350b_firmware affected qualcomm
pm8350bh_firmware affected qualcomm
pm8350bhs_firmware affected qualcomm
pm8350c_firmware affected qualcomm
pm8350_firmware affected qualcomm
pm855a_firmware affected qualcomm
pm855b_firmware affected qualcomm
pm855_firmware affected qualcomm
pm855l_firmware affected qualcomm
pm855p_firmware affected qualcomm
pm8909_firmware affected qualcomm
pm8916_firmware affected qualcomm
pm8937_firmware affected qualcomm
pm8953_firmware affected qualcomm
pm8998_firmware affected qualcomm
pmc1000h_firmware affected qualcomm
pmd9607_firmware affected qualcomm
pmd9655au_firmware affected qualcomm
pmd9655_firmware affected qualcomm
pme605_firmware affected qualcomm
pmi632_firmware affected qualcomm
pmi8937_firmware affected qualcomm
pmi8952_firmware affected qualcomm
pmi8998_firmware affected qualcomm
pmk7350_firmware affected qualcomm
pmk8002_firmware affected qualcomm
pmk8003_firmware affected qualcomm
pmk8350_firmware affected qualcomm
pmm6155au_firmware affected qualcomm
pmm8155au_firmware affected qualcomm
pmm8195au_firmware affected qualcomm
pmm855au_firmware affected qualcomm
pmm8996au_firmware affected qualcomm
pmr525_firmware affected qualcomm
pmr735a_firmware affected qualcomm
pmr735b_firmware affected qualcomm
pmx20_firmware affected qualcomm
pmx24_firmware affected qualcomm
pmx50_firmware affected qualcomm
pmx55_firmware affected qualcomm
qat3514_firmware affected qualcomm
qat3516_firmware affected qualcomm
qat3518_firmware affected qualcomm
qat3519_firmware affected qualcomm
qat3522_firmware affected qualcomm
qat3550_firmware affected qualcomm
qat3555_firmware affected qualcomm
qat5515_firmware affected qualcomm
qat5516_firmware affected qualcomm
qat5522_firmware affected qualcomm
qat5533_firmware affected qualcomm
qat5568_firmware affected qualcomm
qbt1000_firmware affected qualcomm
qbt1500_firmware affected qualcomm
qbt2000_firmware affected qualcomm
qca6174a_firmware affected qualcomm
qca6310_firmware affected qualcomm
qca6320_firmware affected qualcomm
qca6335_firmware affected qualcomm
qca6390_firmware affected qualcomm
qca6391_firmware affected qualcomm
qca6420_firmware affected qualcomm
qca6426_firmware affected qualcomm
qca6430_firmware affected qualcomm
qca6436_firmware affected qualcomm
qca6564a_firmware affected qualcomm
qca6564au_firmware affected qualcomm
qca6564_firmware affected qualcomm
qca6574a_firmware affected qualcomm
qca6574au_firmware affected qualcomm
qca6574_firmware affected qualcomm
qca6584au_firmware affected qualcomm
qca6595au_firmware affected qualcomm
qca6696_firmware affected qualcomm
qca8337_firmware affected qualcomm
qca9367_firmware affected qualcomm
qca9377_firmware affected qualcomm
qcm2290_firmware affected qualcomm
qcm4290_firmware affected qualcomm
qcm6125_firmware affected qualcomm
qcs2290_firmware affected qualcomm
qcs405_firmware affected qualcomm
qcs410_firmware affected qualcomm
qcs4290_firmware affected qualcomm
qcs603_firmware affected qualcomm
qcs605_firmware affected qualcomm
qcs610_firmware affected qualcomm
qcs6125_firmware affected qualcomm
qdm2301_firmware affected qualcomm
qdm2302_firmware affected qualcomm
qdm2305_firmware affected qualcomm
qdm2307_firmware affected qualcomm
qdm2308_firmware affected qualcomm
qdm2310_firmware affected qualcomm
qdm3301_firmware affected qualcomm
qdm3302_firmware affected qualcomm
qdm4643_firmware affected qualcomm
qdm4650_firmware affected qualcomm
qdm5579_firmware affected qualcomm
qdm5620_firmware affected qualcomm
qdm5621_firmware affected qualcomm
qdm5650_firmware affected qualcomm
qdm5652_firmware affected qualcomm
qdm5670_firmware affected qualcomm
qdm5671_firmware affected qualcomm
qdm5677_firmware affected qualcomm
qdm5679_firmware affected qualcomm
qet4100_firmware affected qualcomm
qet4101_firmware affected qualcomm
qet5100_firmware affected qualcomm
qet5100m_firmware affected qualcomm
qet6100_firmware affected qualcomm
qet6105_firmware affected qualcomm
qet6110_firmware affected qualcomm
qfe2101_firmware affected qualcomm
qfe2520_firmware affected qualcomm
qfe2550_firmware affected qualcomm
qfe3340_firmware affected qualcomm
qfe4301_firmware affected qualcomm
qfe4302_firmware affected qualcomm
qfe4303_firmware affected qualcomm
qfe4305_firmware affected qualcomm
qfe4308_firmware affected qualcomm
qfe4309_firmware affected qualcomm
qfe4320_firmware affected qualcomm
qfe4373fc_firmware affected qualcomm
qfs2530_firmware affected qualcomm
qfs2580_firmware affected qualcomm
qfs2608_firmware affected qualcomm
qfs2630_firmware affected qualcomm
qln1020_firmware affected qualcomm
qln1021aq_firmware affected qualcomm
qln1030_firmware affected qualcomm
qln1031_firmware affected qualcomm
qln1036aq_firmware affected qualcomm
qln4640_firmware affected qualcomm
qln4642_firmware affected qualcomm
qln4650_firmware affected qualcomm
qln5020_firmware affected qualcomm
qln5030_firmware affected qualcomm
qln5040_firmware affected qualcomm
qpa2625_firmware affected qualcomm
qpa4340_firmware affected qualcomm
qpa4360_firmware affected qualcomm
qpa4361_firmware affected qualcomm
qpa5373_firmware affected qualcomm
qpa5460_firmware affected qualcomm
qpa5461_firmware affected qualcomm
qpa5580_firmware affected qualcomm
qpa5581_firmware affected qualcomm
qpa6560_firmware affected qualcomm
qpa8673_firmware affected qualcomm
qpa8675_firmware affected qualcomm
qpa8686_firmware affected qualcomm
qpa8801_firmware affected qualcomm
qpa8802_firmware affected qualcomm
qpa8803_firmware affected qualcomm
qpa8821_firmware affected qualcomm
qpa8842_firmware affected qualcomm
qpm2630_firmware affected qualcomm
qpm4621_firmware affected qualcomm
qpm4630_firmware affected qualcomm
qpm4640_firmware affected qualcomm
qpm4641_firmware affected qualcomm
qpm4650_firmware affected qualcomm
qpm5541_firmware affected qualcomm
qpm5577_firmware affected qualcomm
qpm5579_firmware affected qualcomm
qpm5620_firmware affected qualcomm
qpm5621_firmware affected qualcomm
qpm5641_firmware affected qualcomm
qpm5657_firmware affected qualcomm
qpm5658_firmware affected qualcomm
qpm5670_firmware affected qualcomm
qpm5677_firmware affected qualcomm
qpm5679_firmware affected qualcomm
qpm5870_firmware affected qualcomm
qpm5875_firmware affected qualcomm
qpm6325_firmware affected qualcomm
qpm6375_firmware affected qualcomm
qpm6582_firmware affected qualcomm
qpm6585_firmware affected qualcomm
qpm6621_firmware affected qualcomm
qpm6670_firmware affected qualcomm
qpm8820_firmware affected qualcomm
qpm8830_firmware affected qualcomm
qpm8870_firmware affected qualcomm
qpm8895_firmware affected qualcomm
qsm7250_firmware affected qualcomm
qsw6310_firmware affected qualcomm
qsw8573_firmware affected qualcomm
qsw8574_firmware affected qualcomm
qtc410s_firmware affected qualcomm
qtc800h_firmware affected qualcomm
qtc800s_firmware affected qualcomm
qtc800t_firmware affected qualcomm
qtc801s_firmware affected qualcomm
qtm525_firmware affected qualcomm
qtm527_firmware affected qualcomm
qualcomm215_firmware affected qualcomm
rgr7640au_firmware affected qualcomm
rsw8577_firmware affected qualcomm
sa2150p_firmware affected qualcomm
sa415m_firmware affected qualcomm
sa515m_firmware affected qualcomm
sa6145p_firmware affected qualcomm
sa6150p_firmware affected qualcomm
sa6155_firmware affected qualcomm
sa6155p_firmware affected qualcomm
sa8150p_firmware affected qualcomm
sa8155_firmware affected qualcomm
sa8155p_firmware affected qualcomm
sa8195p_firmware affected qualcomm
sd205_firmware affected qualcomm
sd210_firmware affected qualcomm
sd429_firmware affected qualcomm
sd439_firmware affected qualcomm
sd450_firmware affected qualcomm
sd455_firmware affected qualcomm
sd460_firmware affected qualcomm
sd480_firmware affected qualcomm
sd632_firmware affected qualcomm
sd636_firmware affected qualcomm
sd660_firmware affected qualcomm
sd662_firmware affected qualcomm
sd665_firmware affected qualcomm
sd670_firmware affected qualcomm
sd675_firmware affected qualcomm
sd678_firmware affected qualcomm
sd6905g_firmware affected qualcomm
sd710_firmware affected qualcomm
sd720g_firmware affected qualcomm
sd730_firmware affected qualcomm
sd750g_firmware affected qualcomm
sd765_firmware affected qualcomm
sd765g_firmware affected qualcomm
sd768g_firmware affected qualcomm
sd835_firmware affected qualcomm
sd845_firmware affected qualcomm
sd855_firmware affected qualcomm
sd8655g_firmware affected qualcomm
sd870_firmware affected qualcomm
sd8885g_firmware affected qualcomm
sd888_firmware affected qualcomm
sd8c_firmware affected qualcomm
sd8cx_firmware affected qualcomm
sda429w_firmware affected qualcomm
sdm429w_firmware affected qualcomm
sdm630_firmware affected qualcomm
sdm830_firmware affected qualcomm
sdr051_firmware affected qualcomm
sdr052_firmware affected qualcomm
sdr425_firmware affected qualcomm
sdr660_firmware affected qualcomm
sdr660g_firmware affected qualcomm
sdr675_firmware affected qualcomm
sdr735_firmware affected qualcomm
sdr735g_firmware affected qualcomm
sdr8150_firmware affected qualcomm
sdr8250_firmware affected qualcomm
sdr865_firmware affected qualcomm
sdw3100_firmware affected qualcomm
sdx20_firmware affected qualcomm
sdx20m_firmware affected qualcomm
sdx24_firmware affected qualcomm
sdx50m_firmware affected qualcomm
sdx55_firmware affected qualcomm
sdx55m_firmware affected qualcomm
sdxr1_firmware affected qualcomm
sdxr25g_firmware affected qualcomm
sm4125_firmware affected qualcomm
sm6250_firmware affected qualcomm
sm6250p_firmware affected qualcomm
sm7250p_firmware affected qualcomm
sm7350_firmware affected qualcomm
smb1350_firmware affected qualcomm
smb1351_firmware affected qualcomm
smb1354_firmware affected qualcomm
smb1355_firmware affected qualcomm
smb1357_firmware affected qualcomm
smb1358_firmware affected qualcomm
smb1360_firmware affected qualcomm
smb1380_firmware affected qualcomm
smb1381_firmware affected qualcomm
smb1390_firmware affected qualcomm
smb1394_firmware affected qualcomm
smb1395_firmware affected qualcomm
smb1396_firmware affected qualcomm
smb1398_firmware affected qualcomm
smb231_firmware affected qualcomm
smb2351_firmware affected qualcomm
smb358s_firmware affected qualcomm
smr525_firmware affected qualcomm
smr526_firmware affected qualcomm
smr545_firmware affected qualcomm
smr546_firmware affected qualcomm
wcd9326_firmware affected qualcomm
wcd9330_firmware affected qualcomm
wcd9335_firmware affected qualcomm
wcd9340_firmware affected qualcomm
wcd9341_firmware affected qualcomm
wcd9360_firmware affected qualcomm
wcd9370_firmware affected qualcomm
wcd9371_firmware affected qualcomm
wcd9375_firmware affected qualcomm
wcd9380_firmware affected qualcomm
wcd9385_firmware affected qualcomm
wcn3610_firmware affected qualcomm
wcn3615_firmware affected qualcomm
wcn3620_firmware affected qualcomm
wcn3660b_firmware affected qualcomm
wcn3660_firmware affected qualcomm
wcn3680b_firmware affected qualcomm
wcn3680_firmware affected qualcomm
wcn3910_firmware affected qualcomm
wcn3950_firmware affected qualcomm
wcn3980_firmware affected qualcomm
wcn3988_firmware affected qualcomm
wcn3990_firmware affected qualcomm
wcn3991_firmware affected qualcomm
wcn3998_firmware affected qualcomm
wcn3999_firmware affected qualcomm
wcn6740_firmware affected qualcomm
wcn6850_firmware affected qualcomm
wcn6851_firmware affected qualcomm
wcn6855_firmware affected qualcomm
wcn6856_firmware affected qualcomm
wgr7640_firmware affected qualcomm
wsa8810_firmware affected qualcomm
wsa8815_firmware affected qualcomm
wsa8830_firmware affected qualcomm
wsa8835_firmware affected qualcomm
wtr2955_firmware affected qualcomm
wtr2965_firmware affected qualcomm
wtr3925_firmware affected qualcomm
wtr4905_firmware affected qualcomm
wtr5975_firmware affected qualcomm
wtr6955_firmware affected qualcomm
Upstream advisory

ASB-A-178810049

GoogleExploitedCISA KEV listed2021-05-01

ASB-A-178810049

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2021-30538

GoogleExploitedVulnCheck KEV listedCRITICAL2021-05-26

Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page.

CVEs:CVE-2021-30538

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

GHSA-pmqp-h87c-mr78

Open SourceWeaponized exploitHIGH2021-05-18

XML Entity Expansion and Improper Input Validation in Kubernetes API server

Affected products

ProductStatusVendorPackageEcosystem
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubernetes affected k8s.io k8s.io/kubernetes
kubernetes-dns-node-cache-1.17 affected chainguard kubernetes-dns-node-cache-1.17
Upstream advisory

GHSA-pmqp-h87c-mr78

Open SourceWeaponized exploitHIGH2021-05-18

XML Entity Expansion and Improper Input Validation in Kubernetes API server

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

GHSA-ffhg-7mh4-33c4

Open SourceWeaponized exploitHIGH2021-05-18

Improper Verification of Cryptographic Signature in golang.org/x/crypto

Affected products

ProductStatusVendorPackageEcosystem
x/crypto affected golang.org golang.org/x/crypto
Upstream advisory

GHSA-ffhg-7mh4-33c4

Open SourceWeaponized exploitHIGH2021-05-18

Improper Verification of Cryptographic Signature in golang.org/x/crypto

Affected products

ProductStatusVendorPackageEcosystem
dex-k8s-authenticator affected chainguard dex-k8s-authenticator
k3d affected chainguard k3d
k3d affected wolfi k3d
x/crypto affected golang.org golang.org/x/crypto
Upstream advisory

ASB-A-175451802

GoogleWeaponized exploitHIGH2021-05-01

ASB-A-175451802

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

RHSA-2021:2048

Open SourcePoC exploitMEDIUM2021-05-19

Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.3.7 security update on RHEL 8

Affected products

ProductStatusVendorPackageEcosystem
eap7-artemis-wildfly-integration affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-artemis-wildfly-integration
eap7-bouncycastle affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-bouncycastle
eap7-bouncycastle-mail affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-bouncycastle-mail
eap7-bouncycastle-pkix affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-bouncycastle-pkix
eap7-bouncycastle-prov affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-bouncycastle-prov
eap7-hal-console affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-hal-console
eap7-infinispan affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-infinispan
eap7-infinispan-cachestore-jdbc affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-infinispan-cachestore-jdbc
eap7-infinispan-cachestore-remote affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-infinispan-cachestore-remote
eap7-infinispan-client-hotrod affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-infinispan-client-hotrod
eap7-infinispan-commons affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-infinispan-commons
eap7-infinispan-core affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-infinispan-core
eap7-infinispan-hibernate-cache-commons affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-infinispan-hibernate-cache-commons
eap7-infinispan-hibernate-cache-spi affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-infinispan-hibernate-cache-spi
eap7-infinispan-hibernate-cache-v53 affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-infinispan-hibernate-cache-v53
eap7-ironjacamar affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-ironjacamar
eap7-ironjacamar-common-api affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-ironjacamar-common-api
eap7-ironjacamar-common-impl affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-ironjacamar-common-impl
eap7-ironjacamar-common-spi affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-ironjacamar-common-spi
eap7-ironjacamar-core-api affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-ironjacamar-core-api
eap7-ironjacamar-core-impl affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-ironjacamar-core-impl
eap7-ironjacamar-deployers-common affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-ironjacamar-deployers-common
eap7-ironjacamar-jdbc affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-ironjacamar-jdbc
eap7-ironjacamar-validator affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-ironjacamar-validator
eap7-jboss-genericjms affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-jboss-genericjms
eap7-jboss-marshalling affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-jboss-marshalling
eap7-jboss-marshalling-river affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-jboss-marshalling-river
eap7-jboss-server-migration affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-jboss-server-migration
eap7-jboss-server-migration-cli affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-jboss-server-migration-cli
eap7-jboss-server-migration-core affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-jboss-server-migration-core
eap7-jboss-server-migration-eap6.4 affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-jboss-server-migration-eap6.4
eap7-jboss-server-migration-eap6.4-to-eap7.3 affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-jboss-server-migration-eap6.4-to-eap7.3
eap7-jboss-server-migration-eap7.0 affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-jboss-server-migration-eap7.0
eap7-jboss-server-migration-eap7.1 affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-jboss-server-migration-eap7.1
eap7-jboss-server-migration-eap7.2 affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-jboss-server-migration-eap7.2
eap7-jboss-server-migration-eap7.2-to-eap7.3 affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-jboss-server-migration-eap7.2-to-eap7.3
eap7-jboss-server-migration-eap7.3-server affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-jboss-server-migration-eap7.3-server
eap7-jboss-server-migration-wildfly10.0 affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-jboss-server-migration-wildfly10.0
eap7-jboss-server-migration-wildfly10.1 affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-jboss-server-migration-wildfly10.1
eap7-jboss-server-migration-wildfly11.0 affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-jboss-server-migration-wildfly11.0
eap7-jboss-server-migration-wildfly12.0 affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-jboss-server-migration-wildfly12.0
eap7-jboss-server-migration-wildfly13.0-server affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-jboss-server-migration-wildfly13.0-server
eap7-jboss-server-migration-wildfly14.0-server affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-jboss-server-migration-wildfly14.0-server
eap7-jboss-server-migration-wildfly15.0-server affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-jboss-server-migration-wildfly15.0-server
eap7-jboss-server-migration-wildfly16.0-server affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-jboss-server-migration-wildfly16.0-server
eap7-jboss-server-migration-wildfly17.0-server affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-jboss-server-migration-wildfly17.0-server
eap7-jboss-server-migration-wildfly18.0-server affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-jboss-server-migration-wildfly18.0-server
eap7-jboss-server-migration-wildfly8.2 affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-jboss-server-migration-wildfly8.2
eap7-jboss-server-migration-wildfly9.0 affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-jboss-server-migration-wildfly9.0
eap7-jboss-weld-3.1-api affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-jboss-weld-3.1-api
eap7-jboss-weld-3.1-api-weld-api affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-jboss-weld-3.1-api-weld-api
eap7-jboss-weld-3.1-api-weld-spi affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-jboss-weld-3.1-api-weld-spi
eap7-jgroups-kubernetes affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-jgroups-kubernetes
eap7-mod_cluster affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-mod_cluster
eap7-netty affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-netty
eap7-netty-all affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-netty-all
eap7-resteasy affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-resteasy
eap7-resteasy-atom-provider affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-resteasy-atom-provider
eap7-resteasy-cdi affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-resteasy-cdi
eap7-resteasy-client affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-resteasy-client
eap7-resteasy-client-microprofile affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-resteasy-client-microprofile
eap7-resteasy-crypto affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-resteasy-crypto
eap7-resteasy-jackson2-provider affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-resteasy-jackson2-provider
eap7-resteasy-jackson-provider affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-resteasy-jackson-provider
eap7-resteasy-jaxb-provider affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-resteasy-jaxb-provider
eap7-resteasy-jaxrs affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-resteasy-jaxrs
eap7-resteasy-jettison-provider affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-resteasy-jettison-provider
eap7-resteasy-jose-jwt affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-resteasy-jose-jwt
eap7-resteasy-jsapi affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-resteasy-jsapi
eap7-resteasy-json-binding-provider affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-resteasy-json-binding-provider
eap7-resteasy-json-p-provider affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-resteasy-json-p-provider
eap7-resteasy-multipart-provider affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-resteasy-multipart-provider
eap7-resteasy-rxjava2 affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-resteasy-rxjava2
eap7-resteasy-spring affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-resteasy-spring
eap7-resteasy-validator-provider-11 affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-resteasy-validator-provider-11
eap7-resteasy-yaml-provider affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-resteasy-yaml-provider
eap7-undertow affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-undertow
eap7-velocity affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-velocity
eap7-velocity-engine-core affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-velocity-engine-core
eap7-weld-core affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-weld-core
eap7-weld-core-impl affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-weld-core-impl
eap7-weld-core-jsf affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-weld-core-jsf
eap7-weld-ejb affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-weld-ejb
eap7-weld-jta affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-weld-jta
eap7-weld-probe-core affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-weld-probe-core
eap7-weld-web affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-weld-web
eap7-wildfly affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-wildfly
eap7-wildfly-elytron affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-wildfly-elytron
eap7-wildfly-elytron-tool affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-wildfly-elytron-tool
eap7-wildfly-http-client affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-wildfly-http-client
eap7-wildfly-http-client-common affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-wildfly-http-client-common
eap7-wildfly-http-ejb-client affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-wildfly-http-ejb-client
eap7-wildfly-http-naming-client affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-wildfly-http-naming-client
eap7-wildfly-http-transaction-client affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-wildfly-http-transaction-client
eap7-wildfly-javadocs affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-wildfly-javadocs
eap7-wildfly-modules affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-wildfly-modules
eap7-xalan-j2 affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-xalan-j2
eap7-yasson affected Red Hat:jboss_enterprise_application_platform:7.3::el8 eap7-yasson
Upstream advisory

RHSA-2021:2046

Open SourcePoC exploitMEDIUM2021-05-19

Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.3.7 security update on RHEL 6

Affected products

ProductStatusVendorPackageEcosystem
eap7-artemis-wildfly-integration affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-artemis-wildfly-integration
eap7-bouncycastle affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-bouncycastle
eap7-bouncycastle-mail affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-bouncycastle-mail
eap7-bouncycastle-pkix affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-bouncycastle-pkix
eap7-bouncycastle-prov affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-bouncycastle-prov
eap7-hal-console affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-hal-console
eap7-infinispan affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-infinispan
eap7-infinispan-cachestore-jdbc affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-infinispan-cachestore-jdbc
eap7-infinispan-cachestore-remote affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-infinispan-cachestore-remote
eap7-infinispan-client-hotrod affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-infinispan-client-hotrod
eap7-infinispan-commons affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-infinispan-commons
eap7-infinispan-core affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-infinispan-core
eap7-infinispan-hibernate-cache-commons affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-infinispan-hibernate-cache-commons
eap7-infinispan-hibernate-cache-spi affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-infinispan-hibernate-cache-spi
eap7-infinispan-hibernate-cache-v53 affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-infinispan-hibernate-cache-v53
eap7-ironjacamar affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-ironjacamar
eap7-ironjacamar-common-api affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-ironjacamar-common-api
eap7-ironjacamar-common-impl affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-ironjacamar-common-impl
eap7-ironjacamar-common-spi affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-ironjacamar-common-spi
eap7-ironjacamar-core-api affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-ironjacamar-core-api
eap7-ironjacamar-core-impl affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-ironjacamar-core-impl
eap7-ironjacamar-deployers-common affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-ironjacamar-deployers-common
eap7-ironjacamar-jdbc affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-ironjacamar-jdbc
eap7-ironjacamar-validator affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-ironjacamar-validator
eap7-jboss-genericjms affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-jboss-genericjms
eap7-jboss-marshalling affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-jboss-marshalling
eap7-jboss-marshalling-river affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-jboss-marshalling-river
eap7-jboss-server-migration affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-jboss-server-migration
eap7-jboss-server-migration-cli affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-jboss-server-migration-cli
eap7-jboss-server-migration-core affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-jboss-server-migration-core
eap7-jboss-server-migration-eap6.4 affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-jboss-server-migration-eap6.4
eap7-jboss-server-migration-eap6.4-to-eap7.3 affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-jboss-server-migration-eap6.4-to-eap7.3
eap7-jboss-server-migration-eap7.0 affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-jboss-server-migration-eap7.0
eap7-jboss-server-migration-eap7.1 affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-jboss-server-migration-eap7.1
eap7-jboss-server-migration-eap7.2 affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-jboss-server-migration-eap7.2
eap7-jboss-server-migration-eap7.2-to-eap7.3 affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-jboss-server-migration-eap7.2-to-eap7.3
eap7-jboss-server-migration-eap7.3-server affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-jboss-server-migration-eap7.3-server
eap7-jboss-server-migration-wildfly10.0 affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-jboss-server-migration-wildfly10.0
eap7-jboss-server-migration-wildfly10.1 affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-jboss-server-migration-wildfly10.1
eap7-jboss-server-migration-wildfly11.0 affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-jboss-server-migration-wildfly11.0
eap7-jboss-server-migration-wildfly12.0 affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-jboss-server-migration-wildfly12.0
eap7-jboss-server-migration-wildfly13.0-server affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-jboss-server-migration-wildfly13.0-server
eap7-jboss-server-migration-wildfly14.0-server affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-jboss-server-migration-wildfly14.0-server
eap7-jboss-server-migration-wildfly15.0-server affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-jboss-server-migration-wildfly15.0-server
eap7-jboss-server-migration-wildfly16.0-server affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-jboss-server-migration-wildfly16.0-server
eap7-jboss-server-migration-wildfly17.0-server affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-jboss-server-migration-wildfly17.0-server
eap7-jboss-server-migration-wildfly18.0-server affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-jboss-server-migration-wildfly18.0-server
eap7-jboss-server-migration-wildfly8.2 affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-jboss-server-migration-wildfly8.2
eap7-jboss-server-migration-wildfly9.0 affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-jboss-server-migration-wildfly9.0
eap7-jboss-weld-3.1-api affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-jboss-weld-3.1-api
eap7-jboss-weld-3.1-api-weld-api affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-jboss-weld-3.1-api-weld-api
eap7-jboss-weld-3.1-api-weld-spi affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-jboss-weld-3.1-api-weld-spi
eap7-jgroups-kubernetes affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-jgroups-kubernetes
eap7-mod_cluster affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-mod_cluster
eap7-netty affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-netty
eap7-netty-all affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-netty-all
eap7-resteasy affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-resteasy
eap7-resteasy-atom-provider affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-resteasy-atom-provider
eap7-resteasy-cdi affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-resteasy-cdi
eap7-resteasy-client affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-resteasy-client
eap7-resteasy-client-microprofile affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-resteasy-client-microprofile
eap7-resteasy-crypto affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-resteasy-crypto
eap7-resteasy-jackson2-provider affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-resteasy-jackson2-provider
eap7-resteasy-jackson-provider affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-resteasy-jackson-provider
eap7-resteasy-jaxb-provider affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-resteasy-jaxb-provider
eap7-resteasy-jaxrs affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-resteasy-jaxrs
eap7-resteasy-jettison-provider affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-resteasy-jettison-provider
eap7-resteasy-jose-jwt affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-resteasy-jose-jwt
eap7-resteasy-jsapi affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-resteasy-jsapi
eap7-resteasy-json-binding-provider affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-resteasy-json-binding-provider
eap7-resteasy-json-p-provider affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-resteasy-json-p-provider
eap7-resteasy-multipart-provider affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-resteasy-multipart-provider
eap7-resteasy-rxjava2 affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-resteasy-rxjava2
eap7-resteasy-spring affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-resteasy-spring
eap7-resteasy-validator-provider-11 affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-resteasy-validator-provider-11
eap7-resteasy-yaml-provider affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-resteasy-yaml-provider
eap7-undertow affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-undertow
eap7-velocity affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-velocity
eap7-velocity-engine-core affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-velocity-engine-core
eap7-weld-core affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-weld-core
eap7-weld-core-impl affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-weld-core-impl
eap7-weld-core-jsf affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-weld-core-jsf
eap7-weld-ejb affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-weld-ejb
eap7-weld-jta affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-weld-jta
eap7-weld-probe-core affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-weld-probe-core
eap7-weld-web affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-weld-web
eap7-wildfly affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-wildfly
eap7-wildfly-elytron affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-wildfly-elytron
eap7-wildfly-elytron-tool affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-wildfly-elytron-tool
eap7-wildfly-http-client affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-wildfly-http-client
eap7-wildfly-http-client-common affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-wildfly-http-client-common
eap7-wildfly-http-ejb-client affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-wildfly-http-ejb-client
eap7-wildfly-http-naming-client affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-wildfly-http-naming-client
eap7-wildfly-http-transaction-client affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-wildfly-http-transaction-client
eap7-wildfly-javadocs affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-wildfly-javadocs
eap7-wildfly-modules affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-wildfly-modules
eap7-xalan-j2 affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-xalan-j2
eap7-yasson affected Red Hat:jboss_enterprise_application_platform:7.3::el6 eap7-yasson
Upstream advisory

RHSA-2021:2047

Open SourcePoC exploitMEDIUM2021-05-19

Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.3.7 security update on RHEL 7

Affected products

ProductStatusVendorPackageEcosystem
eap7-artemis-wildfly-integration affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-artemis-wildfly-integration
eap7-bouncycastle affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-bouncycastle
eap7-bouncycastle-mail affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-bouncycastle-mail
eap7-bouncycastle-pkix affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-bouncycastle-pkix
eap7-bouncycastle-prov affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-bouncycastle-prov
eap7-hal-console affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-hal-console
eap7-infinispan affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-infinispan
eap7-infinispan-cachestore-jdbc affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-infinispan-cachestore-jdbc
eap7-infinispan-cachestore-remote affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-infinispan-cachestore-remote
eap7-infinispan-client-hotrod affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-infinispan-client-hotrod
eap7-infinispan-commons affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-infinispan-commons
eap7-infinispan-core affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-infinispan-core
eap7-infinispan-hibernate-cache-commons affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-infinispan-hibernate-cache-commons
eap7-infinispan-hibernate-cache-spi affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-infinispan-hibernate-cache-spi
eap7-infinispan-hibernate-cache-v53 affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-infinispan-hibernate-cache-v53
eap7-ironjacamar affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-ironjacamar
eap7-ironjacamar-common-api affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-ironjacamar-common-api
eap7-ironjacamar-common-impl affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-ironjacamar-common-impl
eap7-ironjacamar-common-spi affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-ironjacamar-common-spi
eap7-ironjacamar-core-api affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-ironjacamar-core-api
eap7-ironjacamar-core-impl affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-ironjacamar-core-impl
eap7-ironjacamar-deployers-common affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-ironjacamar-deployers-common
eap7-ironjacamar-jdbc affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-ironjacamar-jdbc
eap7-ironjacamar-validator affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-ironjacamar-validator
eap7-jboss-genericjms affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-jboss-genericjms
eap7-jboss-marshalling affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-jboss-marshalling
eap7-jboss-marshalling-river affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-jboss-marshalling-river
eap7-jboss-server-migration affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-jboss-server-migration
eap7-jboss-server-migration-cli affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-jboss-server-migration-cli
eap7-jboss-server-migration-core affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-jboss-server-migration-core
eap7-jboss-server-migration-eap6.4 affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-jboss-server-migration-eap6.4
eap7-jboss-server-migration-eap6.4-to-eap7.3 affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-jboss-server-migration-eap6.4-to-eap7.3
eap7-jboss-server-migration-eap7.0 affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-jboss-server-migration-eap7.0
eap7-jboss-server-migration-eap7.1 affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-jboss-server-migration-eap7.1
eap7-jboss-server-migration-eap7.2 affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-jboss-server-migration-eap7.2
eap7-jboss-server-migration-eap7.2-to-eap7.3 affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-jboss-server-migration-eap7.2-to-eap7.3
eap7-jboss-server-migration-eap7.3-server affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-jboss-server-migration-eap7.3-server
eap7-jboss-server-migration-wildfly10.0 affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-jboss-server-migration-wildfly10.0
eap7-jboss-server-migration-wildfly10.1 affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-jboss-server-migration-wildfly10.1
eap7-jboss-server-migration-wildfly11.0 affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-jboss-server-migration-wildfly11.0
eap7-jboss-server-migration-wildfly12.0 affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-jboss-server-migration-wildfly12.0
eap7-jboss-server-migration-wildfly13.0-server affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-jboss-server-migration-wildfly13.0-server
eap7-jboss-server-migration-wildfly14.0-server affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-jboss-server-migration-wildfly14.0-server
eap7-jboss-server-migration-wildfly15.0-server affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-jboss-server-migration-wildfly15.0-server
eap7-jboss-server-migration-wildfly16.0-server affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-jboss-server-migration-wildfly16.0-server
eap7-jboss-server-migration-wildfly17.0-server affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-jboss-server-migration-wildfly17.0-server
eap7-jboss-server-migration-wildfly18.0-server affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-jboss-server-migration-wildfly18.0-server
eap7-jboss-server-migration-wildfly8.2 affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-jboss-server-migration-wildfly8.2
eap7-jboss-server-migration-wildfly9.0 affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-jboss-server-migration-wildfly9.0
eap7-jboss-weld-3.1-api affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-jboss-weld-3.1-api
eap7-jboss-weld-3.1-api-weld-api affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-jboss-weld-3.1-api-weld-api
eap7-jboss-weld-3.1-api-weld-spi affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-jboss-weld-3.1-api-weld-spi
eap7-jgroups-kubernetes affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-jgroups-kubernetes
eap7-mod_cluster affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-mod_cluster
eap7-netty affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-netty
eap7-netty-all affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-netty-all
eap7-resteasy affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-resteasy
eap7-resteasy-atom-provider affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-resteasy-atom-provider
eap7-resteasy-cdi affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-resteasy-cdi
eap7-resteasy-client affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-resteasy-client
eap7-resteasy-client-microprofile affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-resteasy-client-microprofile
eap7-resteasy-crypto affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-resteasy-crypto
eap7-resteasy-jackson2-provider affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-resteasy-jackson2-provider
eap7-resteasy-jackson-provider affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-resteasy-jackson-provider
eap7-resteasy-jaxb-provider affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-resteasy-jaxb-provider
eap7-resteasy-jaxrs affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-resteasy-jaxrs
eap7-resteasy-jettison-provider affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-resteasy-jettison-provider
eap7-resteasy-jose-jwt affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-resteasy-jose-jwt
eap7-resteasy-jsapi affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-resteasy-jsapi
eap7-resteasy-json-binding-provider affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-resteasy-json-binding-provider
eap7-resteasy-json-p-provider affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-resteasy-json-p-provider
eap7-resteasy-multipart-provider affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-resteasy-multipart-provider
eap7-resteasy-rxjava2 affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-resteasy-rxjava2
eap7-resteasy-spring affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-resteasy-spring
eap7-resteasy-validator-provider-11 affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-resteasy-validator-provider-11
eap7-resteasy-yaml-provider affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-resteasy-yaml-provider
eap7-undertow affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-undertow
eap7-velocity affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-velocity
eap7-velocity-engine-core affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-velocity-engine-core
eap7-weld-core affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-weld-core
eap7-weld-core-impl affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-weld-core-impl
eap7-weld-core-jsf affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-weld-core-jsf
eap7-weld-ejb affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-weld-ejb
eap7-weld-jta affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-weld-jta
eap7-weld-probe-core affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-weld-probe-core
eap7-weld-web affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-weld-web
eap7-wildfly affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-wildfly
eap7-wildfly-elytron affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-wildfly-elytron
eap7-wildfly-elytron-tool affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-wildfly-elytron-tool
eap7-wildfly-http-client affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-wildfly-http-client
eap7-wildfly-http-client-common affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-wildfly-http-client-common
eap7-wildfly-http-ejb-client affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-wildfly-http-ejb-client
eap7-wildfly-http-naming-client affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-wildfly-http-naming-client
eap7-wildfly-http-transaction-client affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-wildfly-http-transaction-client
eap7-wildfly-javadocs affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-wildfly-javadocs
eap7-wildfly-java-jdk11 affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-wildfly-java-jdk11
eap7-wildfly-java-jdk8 affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-wildfly-java-jdk8
eap7-wildfly-modules affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-wildfly-modules
eap7-xalan-j2 affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-xalan-j2
eap7-yasson affected Red Hat:jboss_enterprise_application_platform:7.3::el7 eap7-yasson
Upstream advisory

DEBIAN-CVE-2021-33194

Open SourcePoC exploitHIGH2021-05-26

DEBIAN-CVE-2021-33194

Affected products

ProductStatusVendorPackageEcosystem
golang-golang-x-net affected Debian:14 golang-golang-x-net
golang-golang-x-net affected Debian:11 golang-golang-x-net
golang-golang-x-net affected Debian:12 golang-golang-x-net
golang-golang-x-net affected Debian:13 golang-golang-x-net
Upstream advisory

CVE-2021-33194

GooglePoC exploitHIGH2021-05-26

golang.org/x/net before v0.0.0-20210520170846-37e1c6afe023 allows attackers to cause a denial of service (infinite loop) via crafted ParseFragment input.

CVEs:CVE-2021-33194

Affected products

ProductStatusVendorPackageEcosystem
fedora affected fedoraproject
go affected golang
Upstream advisory

CVE-2021-33194

Open SourcePoC exploitHIGH2021-05-26

golang.org/x/net/html Infinite Loop vulnerability

CVEs:CVE-2021-33194

Affected products

ProductStatusVendorPackageEcosystem
x/net affected golang.org golang.org/x/net
Upstream advisory

RLSA-2021:1746

Open SourcePoC exploitCRITICAL2021-05-18

Moderate: go-toolset:rhel8 security, bug fix, and enhancement update

Affected products

ProductStatusVendorPackageEcosystem
delve affected Rocky Linux:8 delve
golang affected Rocky Linux:8 golang
go-toolset affected Rocky Linux:8 go-toolset
Upstream advisory

CVE-2021-25735

Open SourcePoC exploitMEDIUM2021-05-28

A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission based ...

CVEs:CVE-2021-25735

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
Upstream advisory

CVE-2021-25735

Open SourcePoC exploitMEDIUM2021-05-28

Access Restriction Bypass in kube-apiserver

CVEs:CVE-2021-25735

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

GHSA-g42g-737j-qx6j

Open SourcePoC exploitCRITICAL2021-05-28

Access Restriction Bypass in kube-apiserver

Affected products

ProductStatusVendorPackageEcosystem
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubernetes affected k8s.io k8s.io/kubernetes
kubernetes-dns-node-cache-1.17 affected chainguard kubernetes-dns-node-cache-1.17
Upstream advisory

GHSA-g42g-737j-qx6j

Open SourcePoC exploitCRITICAL2021-05-28

Access Restriction Bypass in kube-apiserver

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

CVE-2021-0474

Open SourcePoC exploitHIGH2021-05-04

In avrc_msg_cback of avrc_api.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: A...

CVEs:CVE-2021-0474

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-6qfg-8799-r575

Open SourcePoC exploitMEDIUM2021-05-18

Kubernetes kubectl cp Vulnerable to Symlink Attack

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

GHSA-6qfg-8799-r575

Open SourcePoC exploitMEDIUM2021-05-18

Kubernetes kubectl cp Vulnerable to Symlink Attack

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

openSUSE-SU-2021:0762-1

Open SourcePoC exploitCRITICAL2021-05-22

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.2 chromium
Upstream advisory

DSA-4917-1

Open SourcePoC exploit2021-05-18

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:10 chromium
Upstream advisory

openSUSE-SU-2021:0742-1

Open SourcePoC exploitCRITICAL2021-05-16

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.2 chromium
Upstream advisory

CVE-2021-30517

GooglePoC exploitHIGH2021-05-11

Type confusion in V8 in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30517

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30513

GooglePoC exploitHIGH2021-05-11

Type confusion in V8 in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30513

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

GHSA-5rcv-m4m3-hfh7

Open SourcePoC exploitHIGH2021-05-18

golang.org/x/text Infinite loop

Affected products

ProductStatusVendorPackageEcosystem
x/text affected golang.org golang.org/x/text
Upstream advisory

GHSA-5rcv-m4m3-hfh7

Open SourcePoC exploitHIGH2021-05-18

golang.org/x/text Infinite loop

Affected products

ProductStatusVendorPackageEcosystem
dex-k8s-authenticator affected chainguard dex-k8s-authenticator
k3d affected chainguard k3d
k3d affected wolfi k3d
vt-cli affected wolfi vt-cli
vt-cli affected chainguard vt-cli
x/text affected golang.org golang.org/x/text
x/text affected golang.org
Upstream advisory

PUB-A-175769013

GooglePoC exploitHIGH2021-05-01

PUB-A-175769013

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

DSA-4911-1

Open SourcePoC exploit2021-05-03

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:10 chromium
Upstream advisory

CVE-2021-0466

Open SourcePoC exploitHIGH2021-05-04

In startIpClient of ClientModeImpl.java, there is a possible identifier which could be used to track a device. This could lead to remote information disclosure to a proximal attacker, with no additional execution privileges needed. User interaction is ...

CVEs:CVE-2021-0466

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-30516

GooglePoC exploitCRITICAL2021-05-11

Heap buffer overflow in History in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30516

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30518

GooglePoC exploitCRITICAL2021-05-11

Heap buffer overflow in Reader Mode in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30518

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30512

GooglePoC exploitCRITICAL2021-05-11

Use after free in Notifications in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30512

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30510

GooglePoC exploitCRITICAL2021-05-11

Use after free in Aura in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30510

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30515

GooglePoC exploitCRITICAL2021-05-11

Use after free in File API in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30515

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30507

GooglePoC exploitHIGH2021-05-11

Inappropriate implementation in Offline in Google Chrome on Android prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.

CVEs:CVE-2021-30507

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30514

GooglePoC exploitCRITICAL2021-05-11

Use after free in Autofill in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30514

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-0475

Open SourcePoC exploitHIGH2021-05-04

In on_l2cap_data_ind of btif_sock_l2cap.cc, there is possible memory corruption due to a use after free. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2021-0475

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-30508

GooglePoC exploitCRITICAL2021-05-11

Heap buffer overflow in Media Feeds in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to enable certain features in Chrome to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30508

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30519

GooglePoC exploitCRITICAL2021-05-11

Use after free in Payments in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious payments app to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30519

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30511

GooglePoC exploitHIGH2021-05-11

Out of bounds read in Tab Groups in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted HTML page.

CVEs:CVE-2021-30511

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30520

GooglePoC exploitCRITICAL2021-05-11

Use after free in Tab Strip in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30520

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30509

GooglePoC exploitCRITICAL2021-05-11

Out of bounds write in Tab Strip in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page and a crafted Chrome extension.

CVEs:CVE-2021-30509

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30506

GooglePoC exploitHIGH2021-05-11

Incorrect security UI in Web App Installs in Google Chrome on Android prior to 90.0.4430.212 allowed an attacker who convinced a user to install a web application to inject scripts or HTML into a privileged page via a crafted HTML page.

CVEs:CVE-2021-30506

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-0481

Open SourcePoC exploitHIGH2021-05-04

In onActivityResult of EditUserPhotoController.java, there is a possible access of unauthorized files due to an unexpected URI handler. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is...

CVEs:CVE-2021-0481

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-175769054

GooglePoC exploit2021-05-01

PUB-A-175769054

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2021-0472

Open SourcePoC exploitHIGH2021-05-04

In shouldLockKeyguard of LockTaskController.java, there is a possible way to exit App Pinning without a PIN due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction i...

CVEs:CVE-2021-0472

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0476

Open SourcePoC exploitHIGH2021-05-04

In FindOrCreatePeer of btif_av.cc, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: And...

CVEs:CVE-2021-0476

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-30522

GoogleCoalition ESS 30-63%CRITICAL2021-05-26

Use after free in WebAudio in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30522

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

GHSA-pp75-xfpw-37g9

Open SourceCoalition ESS < 30%HIGH2021-05-10

Prototype pollution in grpc and @grpc/grpc-js

Affected products

ProductStatusVendorPackageEcosystem
grpc affected npm grpc
grpc-js affected grpc @grpc/grpc-js
Upstream advisory

GHSA-pp75-xfpw-37g9

Open SourceCoalition ESS < 30%HIGH2021-05-10

Prototype pollution in grpc and @grpc/grpc-js

Affected products

ProductStatusVendorPackageEcosystem
grpc affected npm grpc
grpc-js affected grpc @grpc/grpc-js
Upstream advisory

DEBIAN-CVE-2021-31525

Open SourceCoalition ESS < 30%HIGH2021-05-27

DEBIAN-CVE-2021-31525

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-golang-x-net affected Debian:11 golang-golang-x-net
golang-golang-x-net affected Debian:12 golang-golang-x-net
golang-golang-x-net affected Debian:13 golang-golang-x-net
golang-golang-x-net affected Debian:14 golang-golang-x-net
Upstream advisory

CVE-2021-31525

Open SourceCoalition ESS < 30%MEDIUM2021-05-27

golang.org/x/net/http/httpguts vulnerable to Uncontrolled Recursion

CVEs:CVE-2021-31525

Affected products

ProductStatusVendorPackageEcosystem
x/net affected golang.org golang.org/x/net
Upstream advisory

CVE-2021-31525

GoogleCoalition ESS < 30%HIGH2021-05-27

net/http in Go before 1.15.12 and 1.16.x before 1.16.4 allows remote attackers to cause a denial of service (panic) via a large header to ReadRequest or ReadResponse. Server, Transport, and Client can each be affected in some configurations.

CVEs:CVE-2021-31525

Affected products

ProductStatusVendorPackageEcosystem
fedora affected fedoraproject
go affected golang
Upstream advisory

OESA-2021-1184

Open SourceCoalition ESS < 30%HIGH2021-05-15

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:20.03-LTS-SP1 golang
Upstream advisory

GO-2022-0621

Open SourceCoalition ESS < 30%HIGH2021-05-18

Exposure of sensitive information in k8s.io/kube-state-metrics

Affected products

ProductStatusVendorPackageEcosystem
kube-state-metrics affected k8s.io k8s.io/kube-state-metrics
Upstream advisory

CVE-2021-30531

GoogleCoalition ESS < 30%CRITICAL2021-05-26

Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page.

CVEs:CVE-2021-30531

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30540

GoogleCoalition ESS < 30%MEDIUM2021-05-26

Incorrect security UI in payments in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

CVEs:CVE-2021-30540

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30528

GoogleCoalition ESS < 30%CRITICAL2021-05-26

Use after free in WebAuthentication in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker who had compromised the renderer process of a user who had saved a credit card in their Google account to potentially exploit heap corruptio...

CVEs:CVE-2021-30528

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30521

GoogleCoalition ESS < 30%CRITICAL2021-05-26

Heap buffer overflow in Autofill in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.

CVEs:CVE-2021-30521

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-31982

Open SourceCoalition ESS < 30%HIGH2021-05-28

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

CVEs:CVE-2021-31982

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2021-30539

GoogleCoalition ESS < 30%CRITICAL2021-05-26

Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page.

CVEs:CVE-2021-30539

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30534

GoogleCoalition ESS < 30%CRITICAL2021-05-26

Insufficient policy enforcement in iFrameSandbox in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

CVEs:CVE-2021-30534

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30536

GoogleCoalition ESS < 30%HIGH2021-05-26

Out of bounds read in V8 in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page.

CVEs:CVE-2021-30536

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30530

GoogleCoalition ESS < 30%HIGH2021-05-26

Out of bounds memory access in WebAudio in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.

CVEs:CVE-2021-30530

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-31920

Open SourceCoalition ESS < 30%MEDIUM2021-05-27

Istio Authorization Bypass Vulnerability

CVEs:CVE-2021-31920

Affected products

ProductStatusVendorPackageEcosystem
istio affected istio.io istio.io/istio
Upstream advisory

CVE-2021-31920

Open SourceCoalition ESS < 30%MEDIUM2021-05-27

Istio before 1.8.6 and 1.9.x before 1.9.5 has a remotely exploitable vulnerability where an HTTP request path with multiple slashes or escaped slash characters (%2F or %5C) could potentially bypass an Istio authorization policy when path based authoriz...

CVEs:CVE-2021-31920

Affected products

ProductStatusVendorPackageEcosystem
istio affected istio
Upstream advisory

CVE-2021-30532

GoogleCoalition ESS < 30%CRITICAL2021-05-26

Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page.

CVEs:CVE-2021-30532

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30537

GoogleCoalition ESS < 30%CRITICAL2021-05-26

Insufficient policy enforcement in cookies in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass cookie policy via a crafted HTML page.

CVEs:CVE-2021-30537

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30535

GoogleCoalition ESS < 30%CRITICAL2021-05-26

Double free in ICU in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30535

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30523

GoogleCoalition ESS < 30%CRITICAL2021-05-26

Use after free in WebRTC in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption via a crafted SCTP packet.

CVEs:CVE-2021-30523

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30529

GoogleCoalition ESS < 30%CRITICAL2021-05-26

Use after free in Bookmarks in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30529

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30526

GoogleCoalition ESS < 30%CRITICAL2021-05-26

Out of bounds write in TabStrip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page.

CVEs:CVE-2021-30526

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30524

GoogleCoalition ESS < 30%CRITICAL2021-05-26

Use after free in TabStrip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30524

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30527

GoogleCoalition ESS < 30%CRITICAL2021-05-26

Use after free in WebUI in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30527

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-29499

Open SourceCoalition ESS < 30%CRITICAL2021-05-07

DEBIAN-CVE-2021-29499

Affected products

ProductStatusVendorPackageEcosystem
golang-github-sylabs-sif affected Debian:11 golang-github-sylabs-sif
golang-github-sylabs-sif affected Debian:12 golang-github-sylabs-sif
golang-github-sylabs-sif affected Debian:13 golang-github-sylabs-sif
golang-github-sylabs-sif affected Debian:14 golang-github-sylabs-sif
Upstream advisory

CVE-2021-30525

GoogleCoalition ESS < 30%CRITICAL2021-05-26

Use after free in TabGroups in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30525

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-31937

Open SourceCoalition ESS < 30%CRITICAL2021-05-28

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2021-31937

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

GHSA-5v95-v8c8-3rh6

GoogleCoalition ESS < 30%CRITICAL2021-05-21

Privilege escalation in rbac

Affected products

ProductStatusVendorPackageEcosystem
google/exposure-notifications-verification-server affected github.com github.com/google/exposure-notifications-verification-server
Upstream advisory

GHSA-5v95-v8c8-3rh6

GoogleCoalition ESS < 30%CRITICAL2021-05-21

Privilege escalation in rbac

Affected products

ProductStatusVendorPackageEcosystem
google/exposure-notifications-verification-server affected github.com github.com/google/exposure-notifications-verification-server
Upstream advisory

GHSA-fpm5-vv97-jfwg

Open SourceCoalition ESS < 30%CRITICAL2021-05-18

Uncontrolled Resource Consumption in firebase

Affected products

ProductStatusVendorPackageEcosystem
util affected firebase @firebase/util
Upstream advisory

GHSA-fpm5-vv97-jfwg

Open SourceCoalition ESS < 30%CRITICAL2021-05-18

Uncontrolled Resource Consumption in firebase

Affected products

ProductStatusVendorPackageEcosystem
util affected firebase @firebase/util
Upstream advisory

GHSA-vh5w-fg69-rc8m

GoogleCoalition ESS < 30%MEDIUM2021-05-07

Improper Input Validation in Google Closure Library

Affected products

ProductStatusVendorPackageEcosystem
google-closure-library affected npm google-closure-library
Upstream advisory

GHSA-vh5w-fg69-rc8m

GoogleCoalition ESS < 30%MEDIUM2021-05-07

Improper Input Validation in Google Closure Library

Affected products

ProductStatusVendorPackageEcosystem
google-closure-library affected npm google-closure-library
Upstream advisory

CVE-2021-0324

Open SourceCoalition ESS < 30%HIGH2021-05-04

Product: AndroidVersions: Android SoCAndroid ID: A-175402462

CVEs:CVE-2021-0324

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-175402462

GoogleCoalition ESS < 30%2021-05-01

ASB-A-175402462

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-0473

Open SourceCoalition ESS < 30%HIGH2021-05-04

In rw_t3t_process_error of rw_t3t.cc, there is a possible double free due to uninitialized data. This could lead to remote code execution over NFC with no additional execution privileges needed. User interaction is not needed for exploitation.Product: ...

CVEs:CVE-2021-0473

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-174904705

GoogleCoalition ESS < 30%HIGH2021-05-01

PUB-A-174904705

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2021-0480

Open SourceCoalition ESS < 30%MEDIUM2021-05-04

In createPendingIntent of SnoozeHelper.java, there is a possible broadcast intent containing a sensitive identifier. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploita...

CVEs:CVE-2021-0480

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-6g85-3hm8-83f9

Open SourceCoalition ESS < 30%HIGH2021-05-21

CHECK-fail in `QuantizeAndDequantizeV4Grad`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-6g85-3hm8-83f9

Open SourceCoalition ESS < 30%HIGH2021-05-21

CHECK-fail in `QuantizeAndDequantizeV4Grad`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-181

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-181

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-472

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-472

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-670

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-670

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29544

Open SourceCoalition ESS < 30%HIGH2021-05-14

CHECK-fail in `QuantizeAndDequantizeV4Grad`

CVEs:CVE-2021-29544

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29544

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-670

CVEs:CVE-2021-29544

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29544

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a denial of service via a `CHECK`-fail in `tf.raw_ops.QuantizeAndDequantizeV4Grad`. This is because the implementation does not validate the rank of the `inp...

CVEs:CVE-2021-29544

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

GHSA-2xgj-xhgf-ggjv

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap buffer overflow in `BandedTriangularSolve`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-2xgj-xhgf-ggjv

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap buffer overflow in `BandedTriangularSolve`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-249

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-249

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-540

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-540

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-738

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-738

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29612

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a heap buffer overflow in Eigen implementation of `tf.raw_ops.BandedTriangularSolve`. The implementation(https://github.com/tensorflow/tensorflow/blob/eccb7e...

CVEs:CVE-2021-29612

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29612

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

Heap buffer overflow in `BandedTriangularSolve`

CVEs:CVE-2021-29612

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29612

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-738

CVEs:CVE-2021-29612

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-cwv3-863g-39vx

Open SourceCoalition ESS < 30%HIGH2021-05-21

Stack overflow due to looping TFLite subgraph

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-cwv3-863g-39vx

Open SourceCoalition ESS < 30%HIGH2021-05-21

Stack overflow due to looping TFLite subgraph

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-228

Open SourceCoalition ESS < 30%HIGH2021-05-14

PYSEC-2021-228

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-519

Open SourceCoalition ESS < 30%HIGH2021-05-14

PYSEC-2021-519

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI
Upstream advisory

PYSEC-2021-717

Open SourceCoalition ESS < 30%HIGH2021-05-14

PYSEC-2021-717

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29591

Open SourceCoalition ESS < 30%HIGH2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. TFlite graphs must not have loops between nodes. However, this condition was not checked and an attacker could craft models that would result in infinite loop during evaluation. In ...

CVEs:CVE-2021-29591

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29591

Open SourceCoalition ESS < 30%HIGH2021-05-14

PYSEC-2021-717

CVEs:CVE-2021-29591

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29591

Open SourceCoalition ESS < 30%HIGH2021-05-14

Stack overflow due to looping TFLite subgraph

CVEs:CVE-2021-29591

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-jfp7-4j67-8r3q

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap buffer overflow caused by rounding

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-jfp7-4j67-8r3q

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap buffer overflow caused by rounding

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-166

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-166

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-457

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-457

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-655

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-655

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29529

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-655

CVEs:CVE-2021-29529

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29529

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a heap buffer overflow in `tf.raw_ops.QuantizedResizeBilinear` by manipulating input values so that float rounding results in off-by-one error in accessing i...

CVEs:CVE-2021-29529

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29529

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

Heap buffer overflow caused by rounding

CVEs:CVE-2021-29529

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-vvg4-vgrv-xfr7

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Incomplete validation in `tf.raw_ops.CTCLoss`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-vvg4-vgrv-xfr7

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Incomplete validation in `tf.raw_ops.CTCLoss`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-whr9-vfh2-7hm6

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Memory corruption in `DrawBoundingBoxesV2`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-whr9-vfh2-7hm6

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Memory corruption in `DrawBoundingBoxesV2`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-208

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-208

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-250

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-250

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-499

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-499

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-541

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-541

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-697

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-697

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-739

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-739

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29613

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. Incomplete validation in `tf.raw_ops.CTCLoss` allows an attacker to trigger an OOB read from heap. The fix will be included in TensorFlow 2.5.0. We will also cherrypick these commit...

CVEs:CVE-2021-29613

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29613

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

Incomplete validation in `tf.raw_ops.CTCLoss`

CVEs:CVE-2021-29613

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29613

Open SourceCoalition ESS < 30%MEDIUM2021-05-14

PYSEC-2021-739

CVEs:CVE-2021-29613

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29571

Open SourceCoalition ESS < 30%MEDIUM2021-05-14

PYSEC-2021-697

CVEs:CVE-2021-29571

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29571

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

Memory corruption in `DrawBoundingBoxesV2`

CVEs:CVE-2021-29571

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29571

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.MaxPoolGradWithArgmax` can cause reads outside of bounds of heap allocated data if attacker supplies specially crafted inputs. The implementation(h...

CVEs:CVE-2021-29571

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

GHSA-cjc7-49v2-jp64

Open SourceCoalition ESS < 30%HIGH2021-05-21

Incomplete validation in `SparseAdd`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-cjc7-49v2-jp64

Open SourceCoalition ESS < 30%HIGH2021-05-21

Incomplete validation in `SparseAdd`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-rgvq-pcvf-hx75

Open SourceCoalition ESS < 30%HIGH2021-05-21

Heap OOB and null pointer dereference in `RaggedTensorToTensor`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-rgvq-pcvf-hx75

Open SourceCoalition ESS < 30%HIGH2021-05-21

Heap OOB and null pointer dereference in `RaggedTensorToTensor`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-244

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-244

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-245

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-245

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-246

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-246

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-535

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-535

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-536

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-536

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-537

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-537

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-733

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-733

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-734

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-734

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-735

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-735

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29607

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. Incomplete validation in `SparseAdd` results in allowing attackers to exploit undefined behavior (dereferencing null pointers) as well as write outside of bounds of heap allocated d...

CVEs:CVE-2021-29607

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29607

Open SourceCoalition ESS < 30%HIGH2021-05-14

Incomplete validation in `SparseSparseMinimum`

CVEs:CVE-2021-29607

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29607

Open SourceCoalition ESS < 30%MEDIUM2021-05-14

PYSEC-2021-733

CVEs:CVE-2021-29607

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29608

Open SourceCoalition ESS < 30%HIGH2021-05-14

Heap OOB and null pointer dereference in `RaggedTensorToTensor`

CVEs:CVE-2021-29608

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29608

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. Due to lack of validation in `tf.raw_ops.RaggedTensorToTensor`, an attacker can exploit an undefined behavior if input arguments are empty. The implementation(https://github.com/ten...

CVEs:CVE-2021-29608

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29608

Open SourceCoalition ESS < 30%MEDIUM2021-05-14

PYSEC-2021-734

CVEs:CVE-2021-29608

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29609

Open SourceCoalition ESS < 30%MEDIUM2021-05-14

PYSEC-2021-735

CVEs:CVE-2021-29609

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29609

Open SourceCoalition ESS < 30%HIGH2021-05-14

Incomplete validation in `SparseAdd`

CVEs:CVE-2021-29609

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29609

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. Incomplete validation in `SparseAdd` results in allowing attackers to exploit undefined behavior (dereferencing null pointers) as well as write outside of bounds of heap allocated d...

CVEs:CVE-2021-29609

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

GHSA-xcwj-wfcm-m23c

Open SourceCoalition ESS < 30%HIGH2021-05-21

Invalid validation in `SparseMatrixSparseCholesky`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-xcwj-wfcm-m23c

Open SourceCoalition ESS < 30%HIGH2021-05-21

Invalid validation in `SparseMatrixSparseCholesky`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-167

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-167

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-458

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-458

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-656

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-656

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29530

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a null pointer dereference by providing an invalid `permutation` to `tf.raw_ops.SparseMatrixSparseCholesky`. This is because the implementation(https://githu...

CVEs:CVE-2021-29530

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29530

Open SourceCoalition ESS < 30%HIGH2021-05-14

Invalid validation in `SparseMatrixSparseCholesky`

CVEs:CVE-2021-29530

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29530

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-656

CVEs:CVE-2021-29530

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-xqfj-cr6q-pc8w

Open SourceCoalition ESS < 30%HIGH2021-05-21

Crash in `tf.transpose` with complex inputs

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-xqfj-cr6q-pc8w

Open SourceCoalition ESS < 30%HIGH2021-05-21

Crash in `tf.transpose` with complex inputs

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-mmq6-q8r3-48fm

Open SourceCoalition ESS < 30%HIGH2021-05-21

Crash in `tf.strings.substr` due to `CHECK`-fail

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-mmq6-q8r3-48fm

Open SourceCoalition ESS < 30%HIGH2021-05-21

Crash in `tf.strings.substr` due to `CHECK`-fail

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-254

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-254

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-255

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-255

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-545

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-545

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-546

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-546

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-743

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-743

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-744

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-744

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29617

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-743

CVEs:CVE-2021-29617

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29617

Open SourceCoalition ESS < 30%HIGH2021-05-14

Crash in `tf.strings.substr` due to `CHECK`-fail

CVEs:CVE-2021-29617

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29617

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service via `CHECK`-fail in `tf.strings.substr` with invalid arguments. The fix will be included in TensorFlow 2.5.0. We will also cherrypick this ...

CVEs:CVE-2021-29617

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29618

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-744

CVEs:CVE-2021-29618

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29618

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. Passing a complex argument to `tf.transpose` at the same time as passing `conjugate=True` argument results in a crash. The fix will be included in TensorFlow 2.5.0. We will also che...

CVEs:CVE-2021-29618

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29618

Open SourceCoalition ESS < 30%HIGH2021-05-14

Crash in `tf.transpose` with complex inputs

CVEs:CVE-2021-29618

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-wcv5-qrj6-9pfm

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap buffer overflow in `Conv3DBackprop*`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-wcv5-qrj6-9pfm

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap buffer overflow in `Conv3DBackprop*`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-157

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-157

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-448

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-448

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-646

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-646

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29520

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

Heap buffer overflow in `Conv3DBackprop*`

CVEs:CVE-2021-29520

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29520

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. Missing validation between arguments to `tf.raw_ops.Conv3DBackprop*` operations can result in heap buffer overflows. This is because the implementation(https://github.com/tensorflow...

CVEs:CVE-2021-29520

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29520

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-646

CVEs:CVE-2021-29520

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-8pmx-p244-g88h

Open SourceCoalition ESS < 30%HIGH2021-05-21

Interpreter crash from `tf.io.decode_raw`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-8pmx-p244-g88h

Open SourceCoalition ESS < 30%HIGH2021-05-21

Interpreter crash from `tf.io.decode_raw`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-251

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-251

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-542

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-542

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-740

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-740

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29614

Open SourceCoalition ESS < 30%HIGH2021-05-14

Interpreter crash from `tf.io.decode_raw`

CVEs:CVE-2021-29614

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29614

Open SourceCoalition ESS < 30%HIGH2021-05-14

PYSEC-2021-740

CVEs:CVE-2021-29614

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29614

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.io.decode_raw` produces incorrect results and crashes the Python interpreter when combining `fixed_length` and wider datatypes. The implementation of the p...

CVEs:CVE-2021-29614

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

GHSA-jf7h-7m85-w2v2

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Integer overflow in TFLite memory allocation

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-jf7h-7m85-w2v2

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Integer overflow in TFLite memory allocation

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-242

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-242

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-533

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-533

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-731

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-731

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29605

Open SourceCoalition ESS < 30%HIGH2021-05-14

PYSEC-2021-731

CVEs:CVE-2021-29605

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29605

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

Integer overflow in TFLite memory allocation

CVEs:CVE-2021-29605

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29605

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The TFLite code for allocating `TFLiteIntArray`s is vulnerable to an integer overflow issue(https://github.com/tensorflow/tensorflow/blob/4ceffae632721e52bf3501b736e4fe9d1221cdfa/te...

CVEs:CVE-2021-29605

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

GHSA-vqw6-72r7-fgw7

Open SourceCoalition ESS < 30%HIGH2021-05-21

OOB read in `MatrixTriangularSolve`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-vqw6-72r7-fgw7

Open SourceCoalition ESS < 30%HIGH2021-05-21

OOB read in `MatrixTriangularSolve`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-393f-2jr3-cp69

Open SourceCoalition ESS < 30%HIGH2021-05-21

CHECK-fail in DrawBoundingBoxes

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-393f-2jr3-cp69

Open SourceCoalition ESS < 30%HIGH2021-05-21

CHECK-fail in DrawBoundingBoxes

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-170

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-170

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-188

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-188

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-461

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-461

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-479

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-479

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-659

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-659

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-677

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-677

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29533

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a denial of service via a `CHECK` failure by passing an empty image to `tf.raw_ops.DrawBoundingBoxes`. This is because the implementation(https://github.com/...

CVEs:CVE-2021-29533

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29533

Open SourceCoalition ESS < 30%HIGH2021-05-14

CHECK-fail in DrawBoundingBoxes

CVEs:CVE-2021-29533

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29533

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-659

CVEs:CVE-2021-29533

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29551

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-677

CVEs:CVE-2021-29551

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29551

Open SourceCoalition ESS < 30%HIGH2021-05-14

OOB read in `MatrixTriangularSolve`

CVEs:CVE-2021-29551

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29551

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The implementation of `MatrixTriangularSolve`(https://github.com/tensorflow/tensorflow/blob/8cae746d8449c7dda5298327353d68613f16e798/tensorflow/core/kernels/linalg/matrix_triangular...

CVEs:CVE-2021-29551

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-22547

GoogleCoalition ESS < 30%HIGH2021-05-04

In IoT Devices SDK, there is an implementation of calloc() that doesn't have a length check. An attacker could pass in memory objects larger than the buffer and wrap around to have a smaller buffer than required, allowing the attacker access to the oth...

CVEs:CVE-2021-22547

Affected products

ProductStatusVendorPackageEcosystem
cloud_iot_device_sdk_for_embedded_c affected google
Upstream advisory

GHSA-h4pc-gx2w-f2xv

Open SourceCoalition ESS < 30%HIGH2021-05-21

Heap OOB read in TFLite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-h4pc-gx2w-f2xv

Open SourceCoalition ESS < 30%HIGH2021-05-21

Heap OOB read in TFLite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-jjr8-m8g8-p6wv

Open SourceCoalition ESS < 30%MEDIUM2021-05-21

Null pointer dereference in TFLite's `Reshape` operator

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-jjr8-m8g8-p6wv

Open SourceCoalition ESS < 30%MEDIUM2021-05-21

Null pointer dereference in TFLite's `Reshape` operator

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-xgc3-m89p-vr3x

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap buffer overflow in `Conv2DBackpropFilter`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-xgc3-m89p-vr3x

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap buffer overflow in `Conv2DBackpropFilter`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-177

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-177

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-229

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-229

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-243

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-243

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-468

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-468

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-520

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-520

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI
Upstream advisory

PYSEC-2021-534

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-534

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-666

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-666

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-718

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-718

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-732

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-732

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29592

Open SourceCoalition ESS < 30%MEDIUM2021-05-14

Null pointer dereference in TFLite's `Reshape` operator

CVEs:CVE-2021-29592

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29592

Open SourceCoalition ESS < 30%MEDIUM2021-05-14

PYSEC-2021-718

CVEs:CVE-2021-29592

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29592

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The fix for CVE-2020-15209(https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15209) missed the case when the target shape of `Reshape` operator is given by the elements of a 1...

CVEs:CVE-2021-29592

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29606

Open SourceCoalition ESS < 30%HIGH2021-05-14

PYSEC-2021-732

CVEs:CVE-2021-29606

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29606

Open SourceCoalition ESS < 30%HIGH2021-05-14

Heap OOB read in TFLite

CVEs:CVE-2021-29606

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29606

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. A specially crafted TFLite model could trigger an OOB read on heap in the TFLite implementation of `Split_V`(https://github.com/tensorflow/tensorflow/blob/c59c37e7b2d563967da813fa50...

CVEs:CVE-2021-29606

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29540

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow to occur in `Conv2DBackpropFilter`. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/1b0296c3b8dd9bd948f...

CVEs:CVE-2021-29540

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29540

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

Heap buffer overflow in `Conv2DBackpropFilter`

CVEs:CVE-2021-29540

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29540

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-666

CVEs:CVE-2021-29540

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-79fv-9865-4qcv

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap buffer overflow in `MaxPoolGrad`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-79fv-9865-4qcv

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap buffer overflow in `MaxPoolGrad`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-216

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-216

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-507

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-507

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-705

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-705

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29579

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

Heap buffer overflow in `MaxPoolGrad`

CVEs:CVE-2021-29579

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29579

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-705

CVEs:CVE-2021-29579

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29579

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.MaxPoolGrad` is vulnerable to a heap buffer overflow. The implementation(https://github.com/tensorflow/tensorflow/blob/ab1e644b48c82cb71493f4362b4d...

CVEs:CVE-2021-29579

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

GHSA-9xh4-23q4-v6wr

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap buffer overflow and undefined behavior in `FusedBatchNorm`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-9xh4-23q4-v6wr

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap buffer overflow and undefined behavior in `FusedBatchNorm`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-6f89-8j54-29xf

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap buffer overflow in `FractionalAvgPoolGrad`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-6f89-8j54-29xf

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap buffer overflow in `FractionalAvgPoolGrad`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-v6r6-84gr-92rm

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap buffer overflow in `AvgPool3DGrad`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-v6r6-84gr-92rm

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap buffer overflow in `AvgPool3DGrad`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-7cqx-92hp-x6wh

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap buffer overflow in `MaxPool3DGradGrad`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-7cqx-92hp-x6wh

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap buffer overflow in `MaxPool3DGradGrad`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-mqh2-9wrp-vx84

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap buffer overflow in `SparseSplit`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-mqh2-9wrp-vx84

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap buffer overflow in `SparseSplit`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-8c89-2vwr-chcq

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap buffer overflow in `QuantizedResizeBilinear`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-8c89-2vwr-chcq

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap buffer overflow in `QuantizedResizeBilinear`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-2gfx-95x2-5v3x

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap buffer overflow in `QuantizedReshape`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-2gfx-95x2-5v3x

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap buffer overflow in `QuantizedReshape`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-m3f9-w3p3-p669

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap buffer overflow in `QuantizedMul`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-m3f9-w3p3-p669

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap buffer overflow in `QuantizedMul`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-8h46-5m9h-7553

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap out of bounds write in `RaggedBinCount`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-8h46-5m9h-7553

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap out of bounds write in `RaggedBinCount`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-4278-2v5v-65r4

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap buffer overflow in `RaggedBinCount`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-4278-2v5v-65r4

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap buffer overflow in `RaggedBinCount`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-151

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-151

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-172

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-172

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-173

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-173

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-174

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-174

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-195

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-195

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-213

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-213

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-214

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-214

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-215

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-215

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-220

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-220

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-442

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-442

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-463

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-463

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-464

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-464

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-465

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-465

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-486

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-486

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-504

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-504

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-505

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-505

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-506

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-506

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-511

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-511

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-640

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-640

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-661

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-661

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-662

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-662

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-663

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-663

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-684

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-684

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-702

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-702

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-703

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-703

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-704

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-704

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-709

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-709

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29514

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

Heap out of bounds write in `RaggedBinCount`

CVEs:CVE-2021-29514

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29514

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-640

CVEs:CVE-2021-29514

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29514

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. If the `splits` argument of `RaggedBincount` does not specify a valid `SparseTensor`(https://www.tensorflow.org/api_docs/python/tf/sparse/SparseTensor), then an attacker can trigger...

CVEs:CVE-2021-29514

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29558

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow in `tf.raw_ops.SparseSplit`. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/699bff5d961f0abfde8fa3f876...

CVEs:CVE-2021-29558

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29558

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

Heap buffer overflow in `SparseSplit`

CVEs:CVE-2021-29558

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29558

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-684

CVEs:CVE-2021-29558

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29576

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

Heap buffer overflow in `MaxPool3DGradGrad`

CVEs:CVE-2021-29576

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29576

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-702

CVEs:CVE-2021-29576

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29576

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.MaxPool3DGradGrad` is vulnerable to a heap buffer overflow. The implementation(https://github.com/tensorflow/tensorflow/blob/596c05a159b6fbb9e39ca1...

CVEs:CVE-2021-29576

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29577

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.AvgPool3DGrad` is vulnerable to a heap buffer overflow. The implementation(https://github.com/tensorflow/tensorflow/blob/d80ffba9702dc19d1fac74fc4b...

CVEs:CVE-2021-29577

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29577

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

Heap buffer overflow in `AvgPool3DGrad`

CVEs:CVE-2021-29577

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29577

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-703

CVEs:CVE-2021-29577

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29578

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.FractionalAvgPoolGrad` is vulnerable to a heap buffer overflow. The implementation(https://github.com/tensorflow/tensorflow/blob/dcba796a28364d6d7f...

CVEs:CVE-2021-29578

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29578

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-704

CVEs:CVE-2021-29578

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29578

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

Heap buffer overflow in `FractionalAvgPoolGrad`

CVEs:CVE-2021-29578

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29583

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-709

CVEs:CVE-2021-29583

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29583

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

Heap buffer overflow and undefined behavior in `FusedBatchNorm`

CVEs:CVE-2021-29583

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29583

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.FusedBatchNorm` is vulnerable to a heap buffer overflow. If the tensors are empty, the same implementation can trigger undefined behavior by derefe...

CVEs:CVE-2021-29583

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

PYSEC-2021-149

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-149

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-440

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-440

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-638

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-638

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29535

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow in `QuantizedMul` by passing in invalid thresholds for the quantization. This is because the implementation(https://github.com/tensorflo...

CVEs:CVE-2021-29535

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29535

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-661

CVEs:CVE-2021-29535

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29535

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

Heap buffer overflow in `QuantizedMul`

CVEs:CVE-2021-29535

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29536

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

Heap buffer overflow in `QuantizedReshape`

CVEs:CVE-2021-29536

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29536

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow in `QuantizedReshape` by passing in invalid thresholds for the quantization. This is because the implementation(https://github.com/tenso...

CVEs:CVE-2021-29536

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29536

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-662

CVEs:CVE-2021-29536

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29537

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-663

CVEs:CVE-2021-29537

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29537

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow in `QuantizedResizeBilinear` by passing in invalid thresholds for the quantization. This is because the implementation(https://github.co...

CVEs:CVE-2021-29537

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29537

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

Heap buffer overflow in `QuantizedResizeBilinear`

CVEs:CVE-2021-29537

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29512

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. If the `splits` argument of `RaggedBincount` does not specify a valid `SparseTensor`(https://www.tensorflow.org/api_docs/python/tf/sparse/SparseTensor), then an attacker can trigger...

CVEs:CVE-2021-29512

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29512

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-638

CVEs:CVE-2021-29512

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29512

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

Heap buffer overflow in `RaggedBinCount`

CVEs:CVE-2021-29512

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-97wf-p777-86jq

Open SourceCoalition ESS < 30%LOW2021-05-21

Division by zero in TFLite's implementation of Split

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-97wf-p777-86jq

Open SourceCoalition ESS < 30%LOW2021-05-21

Division by zero in TFLite's implementation of Split

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-236

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-236

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-527

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-527

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-725

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-725

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29599

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The implementation of the `Split` TFLite operator is vulnerable to a division by zero error(https://github.com/tensorflow/tensorflow/blob/e2752089ef7ce9bcf3db0ec618ebd23ea119d0c7/te...

CVEs:CVE-2021-29599

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29599

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-725

CVEs:CVE-2021-29599

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29599

Open SourceCoalition ESS < 30%LOW2021-05-14

Division by zero in TFLite's implementation of Split

CVEs:CVE-2021-29599

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-8gv3-57p6-g35r

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap buffer overflow in `RaggedTensorToTensor`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-8gv3-57p6-g35r

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap buffer overflow in `RaggedTensorToTensor`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-197

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-197

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-488

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-488

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-686

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-686

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29560

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow in `tf.raw_ops.RaggedTensorToTensor`. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/d94227d43aa125ad8...

CVEs:CVE-2021-29560

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29560

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-686

CVEs:CVE-2021-29560

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29560

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

Heap buffer overflow in `RaggedTensorToTensor`

CVEs:CVE-2021-29560

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-4hvv-7x94-7vq8

Open SourceCoalition ESS < 30%LOW2021-05-21

Null dereference in Grappler's `TrySimplify`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-4hvv-7x94-7vq8

Open SourceCoalition ESS < 30%LOW2021-05-21

Null dereference in Grappler's `TrySimplify`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-253

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-253

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-544

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-544

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-742

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-742

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29616

Open SourceCoalition ESS < 30%LOW2021-05-14

Null dereference in Grappler's `TrySimplify`

CVEs:CVE-2021-29616

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29616

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The implementation of TrySimplify(https://github.com/tensorflow/tensorflow/blob/c22d88d6ff33031aa113e48aa3fc9aa74ed79595/tensorflow/core/grappler/optimizers/arithmetic_optimizer.cc#...

CVEs:CVE-2021-29616

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29616

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-742

CVEs:CVE-2021-29616

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-qw5h-7f53-xrp6

Open SourceCoalition ESS < 30%HIGH2021-05-21

Stack overflow in `ParseAttrValue` with nested tensors

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-qw5h-7f53-xrp6

Open SourceCoalition ESS < 30%HIGH2021-05-21

Stack overflow in `ParseAttrValue` with nested tensors

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-252

Open SourceCoalition ESS < 30%HIGH2021-05-14

PYSEC-2021-252

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-543

Open SourceCoalition ESS < 30%HIGH2021-05-14

PYSEC-2021-543

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-741

Open SourceCoalition ESS < 30%HIGH2021-05-14

PYSEC-2021-741

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29615

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-741

CVEs:CVE-2021-29615

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29615

Open SourceCoalition ESS < 30%HIGH2021-05-14

Stack overflow in `ParseAttrValue` with nested tensors

CVEs:CVE-2021-29615

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29615

Open SourceCoalition ESS < 30%HIGH2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The implementation of `ParseAttrValue`(https://github.com/tensorflow/tensorflow/blob/c22d88d6ff33031aa113e48aa3fc9aa74ed79595/tensorflow/core/framework/attr_value_util.cc#L397-L453)...

CVEs:CVE-2021-29615

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

GHSA-452g-f7fp-9jf7

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Type confusion during tensor casts lead to dereferencing null pointers

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-452g-f7fp-9jf7

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Type confusion during tensor casts lead to dereferencing null pointers

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-150

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-150

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-441

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-441

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-639

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-639

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29513

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

Type confusion during tensor casts lead to dereferencing null pointers

CVEs:CVE-2021-29513

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29513

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-639

CVEs:CVE-2021-29513

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29513

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. Calling TF operations with tensors of non-numeric types when the operations expect numeric tensors result in null pointer dereferences. The conversion from Python array to C++ array...

CVEs:CVE-2021-29513

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

GHSA-9rpc-5v9q-5r7f

Open SourceCoalition ESS < 30%HIGH2021-05-21

Incomplete validation in `SparseReshape`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-9rpc-5v9q-5r7f

Open SourceCoalition ESS < 30%HIGH2021-05-21

Incomplete validation in `SparseReshape`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-248

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-248

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-539

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-539

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-737

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-737

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29611

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-737

CVEs:CVE-2021-29611

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29611

Open SourceCoalition ESS < 30%HIGH2021-05-14

Incomplete validation in `SparseReshape`

CVEs:CVE-2021-29611

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29611

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. Incomplete validation in `SparseReshape` results in a denial of service based on a `CHECK`-failure. The implementation(https://github.com/tensorflow/tensorflow/blob/e87b51ce05c3eb17...

CVEs:CVE-2021-29611

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

GHSA-mq5c-prh3-3f3h

Open SourceCoalition ESS < 30%HIGH2021-05-21

Invalid validation in `QuantizeAndDequantizeV2`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-mq5c-prh3-3f3h

Open SourceCoalition ESS < 30%HIGH2021-05-21

Invalid validation in `QuantizeAndDequantizeV2`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-crch-j389-5f84

Open SourceCoalition ESS < 30%LOW2021-05-21

Heap OOB write in TFLite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-crch-j389-5f84

Open SourceCoalition ESS < 30%LOW2021-05-21

Heap OOB write in TFLite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-j8qh-3xrq-c825

Open SourceCoalition ESS < 30%LOW2021-05-21

Division by zero in TFLite's implementation of `OneHot`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-j8qh-3xrq-c825

Open SourceCoalition ESS < 30%LOW2021-05-21

Division by zero in TFLite's implementation of `OneHot`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-pmpr-55fj-r229

Open SourceCoalition ESS < 30%LOW2021-05-21

Division by zero in TFLite's implementation of `SVDF`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-pmpr-55fj-r229

Open SourceCoalition ESS < 30%LOW2021-05-21

Division by zero in TFLite's implementation of `SVDF`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-v52p-hfjf-wg88

Open SourceCoalition ESS < 30%LOW2021-05-21

Division by zero in TFLite's implementation of `SpaceToBatchNd`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-v52p-hfjf-wg88

Open SourceCoalition ESS < 30%LOW2021-05-21

Division by zero in TFLite's implementation of `SpaceToBatchNd`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-4vrf-ff7v-hpgr

Open SourceCoalition ESS < 30%LOW2021-05-21

Division by zero in TFLite's implementation of `EmbeddingLookup`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-4vrf-ff7v-hpgr

Open SourceCoalition ESS < 30%LOW2021-05-21

Division by zero in TFLite's implementation of `EmbeddingLookup`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-vf94-36g5-69v8

Open SourceCoalition ESS < 30%LOW2021-05-21

Division by zero in TFLite's implementation of `DepthToSpace`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-vf94-36g5-69v8

Open SourceCoalition ESS < 30%LOW2021-05-21

Division by zero in TFLite's implementation of `DepthToSpace`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-3qgw-p4fm-x7gf

Open SourceCoalition ESS < 30%LOW2021-05-21

Division by zero in TFLite's convolution code

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-3qgw-p4fm-x7gf

Open SourceCoalition ESS < 30%LOW2021-05-21

Division by zero in TFLite's convolution code

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-cfx7-2xpc-8w4h

Open SourceCoalition ESS < 30%LOW2021-05-21

Division by zero in TFLite's implementation of `BatchToSpaceNd`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-cfx7-2xpc-8w4h

Open SourceCoalition ESS < 30%LOW2021-05-21

Division by zero in TFLite's implementation of `BatchToSpaceNd`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-3w67-q784-6w7c

Open SourceCoalition ESS < 30%LOW2021-05-21

Division by zero in TFLite's implementation of `GatherNd`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-3w67-q784-6w7c

Open SourceCoalition ESS < 30%LOW2021-05-21

Division by zero in TFLite's implementation of `GatherNd`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-vfr4-x8j2-3rf9

Open SourceCoalition ESS < 30%LOW2021-05-21

Division by zero in TFLite's implementation of `TransposeConv`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-vfr4-x8j2-3rf9

Open SourceCoalition ESS < 30%LOW2021-05-21

Division by zero in TFLite's implementation of `TransposeConv`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-j7rm-8ww4-xx2g

Open SourceCoalition ESS < 30%LOW2021-05-21

Division by zero in TFLite's implementation of `SpaceToDepth`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-j7rm-8ww4-xx2g

Open SourceCoalition ESS < 30%LOW2021-05-21

Division by zero in TFLite's implementation of `SpaceToDepth`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-26j7-6w8w-7922

Open SourceCoalition ESS < 30%LOW2021-05-21

Division by zero in optimized pooling implementations in TFLite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-26j7-6w8w-7922

Open SourceCoalition ESS < 30%LOW2021-05-21

Division by zero in optimized pooling implementations in TFLite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-mv78-g7wq-mhp4

Open SourceCoalition ESS < 30%LOW2021-05-21

Division by zero in padding computation in TFLite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-mv78-g7wq-mhp4

Open SourceCoalition ESS < 30%LOW2021-05-21

Division by zero in padding computation in TFLite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-828x-qc2p-wprq

Open SourceCoalition ESS < 30%HIGH2021-05-21

Undefined behavior in `MaxPool3DGradGrad`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-828x-qc2p-wprq

Open SourceCoalition ESS < 30%HIGH2021-05-21

Undefined behavior in `MaxPool3DGradGrad`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-pvrc-hg3f-58r6

Open SourceCoalition ESS < 30%HIGH2021-05-21

Heap OOB access in `Dilation2DBackpropInput`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-pvrc-hg3f-58r6

Open SourceCoalition ESS < 30%HIGH2021-05-21

Heap OOB access in `Dilation2DBackpropInput`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-m34j-p8rj-wjxq

Open SourceCoalition ESS < 30%HIGH2021-05-21

Division by 0 in `QuantizedBiasAdd`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-m34j-p8rj-wjxq

Open SourceCoalition ESS < 30%HIGH2021-05-21

Division by 0 in `QuantizedBiasAdd`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-xm2v-8rrw-w9pm

Open SourceCoalition ESS < 30%HIGH2021-05-21

Division by 0 in `Conv2DBackpropInput`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-xm2v-8rrw-w9pm

Open SourceCoalition ESS < 30%HIGH2021-05-21

Division by 0 in `Conv2DBackpropInput`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-62gx-355r-9fhg

Open SourceCoalition ESS < 30%LOW2021-05-21

Session operations in eager mode lead to null pointer dereferences

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-62gx-355r-9fhg

Open SourceCoalition ESS < 30%LOW2021-05-21

Session operations in eager mode lead to null pointer dereferences

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-hc6c-75p4-hmq4

Open SourceCoalition ESS < 30%HIGH2021-05-21

Reference binding to null pointer in `MatrixDiag*` ops

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-hc6c-75p4-hmq4

Open SourceCoalition ESS < 30%HIGH2021-05-21

Reference binding to null pointer in `MatrixDiag*` ops

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-152

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-152

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-155

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-155

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-162

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-162

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-183

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-183

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-203

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-203

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-211

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-211

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-222

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-222

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-223

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-223

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-224

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-224

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-225

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-225

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-226

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-226

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-230

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-230

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-231

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-231

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-232

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-232

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-233

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-233

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-234

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-234

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-235

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-235

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-237

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-237

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-240

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-240

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-247

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-247

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-443

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-443

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-446

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-446

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-453

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-453

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-474

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-474

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-494

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-494

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-502

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-502

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-513

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-513

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-514

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-514

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-515

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-515

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-516

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-516

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-517

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-517

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-521

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-521

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-522

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-522

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-523

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-523

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-524

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-524

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-525

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-525

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-526

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-526

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-528

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-528

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-531

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-531

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-538

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-538

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-641

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-641

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-644

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-644

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-651

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-651

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-672

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-672

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-692

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-692

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-700

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-700

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-711

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-711

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-712

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-712

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-713

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-713

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-714

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-714

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-715

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-715

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-719

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-719

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-720

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-720

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-721

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-721

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-722

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-722

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-723

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-723

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-724

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-724

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-726

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-726

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-729

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-729

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-736

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-736

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29515

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The implementation of `MatrixDiag*` operations(https://github.com/tensorflow/tensorflow/blob/4c4f420e68f1cfaf8f4b6e8e3eb857e9e4c3ff33/tensorflow/core/kernels/linalg/matrix_diag_op.c...

CVEs:CVE-2021-29515

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29515

Open SourceCoalition ESS < 30%HIGH2021-05-14

Reference binding to null pointer in `MatrixDiag*` ops

CVEs:CVE-2021-29515

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29515

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-641

CVEs:CVE-2021-29515

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29518

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-644

CVEs:CVE-2021-29518

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29518

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. In eager mode (default in TF 2.0 and later), session operations are invalid. However, users could still call the raw ops associated with them and trigger a null pointer dereference....

CVEs:CVE-2021-29518

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29518

Open SourceCoalition ESS < 30%LOW2021-05-14

Session operations in eager mode lead to null pointer dereferences

CVEs:CVE-2021-29518

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29585

Open SourceCoalition ESS < 30%LOW2021-05-14

Division by zero in padding computation in TFLite

CVEs:CVE-2021-29585

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29585

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The TFLite computation for size of output after padding, `ComputeOutSize`(https://github.com/tensorflow/tensorflow/blob/0c9692ae7b1671c983569e5d3de5565843d500cf/tensorflow/lite/kern...

CVEs:CVE-2021-29585

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29585

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-711

CVEs:CVE-2021-29585

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29586

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-712

CVEs:CVE-2021-29586

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29586

Open SourceCoalition ESS < 30%LOW2021-05-14

Division by zero in optimized pooling implementations in TFLite

CVEs:CVE-2021-29586

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29586

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. Optimized pooling implementations in TFLite fail to check that the stride arguments are not 0 before calling `ComputePaddingHeightWidth`(https://github.com/tensorflow/tensorflow/blo...

CVEs:CVE-2021-29586

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29587

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-713

CVEs:CVE-2021-29587

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29587

Open SourceCoalition ESS < 30%LOW2021-05-14

Division by zero in TFLite's implementation of `SpaceToDepth`

CVEs:CVE-2021-29587

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29587

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The `Prepare` step of the `SpaceToDepth` TFLite operator does not check for 0 before division(https://github.com/tensorflow/tensorflow/blob/5f7975d09eac0f10ed8a17dbb6f5964977725adc/...

CVEs:CVE-2021-29587

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29588

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-714

CVEs:CVE-2021-29588

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29588

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The optimized implementation of the `TransposeConv` TFLite operator is [vulnerable to a division by zero error](https://github.com/tensorflow/tensorflow/blob/0d45ea1ca641b21b73bcf9c...

CVEs:CVE-2021-29588

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29588

Open SourceCoalition ESS < 30%LOW2021-05-14

Division by zero in TFLite's implementation of `TransposeConv`

CVEs:CVE-2021-29588

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29589

Open SourceCoalition ESS < 30%LOW2021-05-14

Division by zero in TFLite's implementation of `GatherNd`

CVEs:CVE-2021-29589

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29589

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The reference implementation of the `GatherNd` TFLite operator is vulnerable to a division by zero error(https://github.com/tensorflow/tensorflow/blob/0d45ea1ca641b21b73bcf9c00e0179...

CVEs:CVE-2021-29589

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29589

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-715

CVEs:CVE-2021-29589

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29593

Open SourceCoalition ESS < 30%LOW2021-05-14

Division by zero in TFLite's implementation of `BatchToSpaceNd`

CVEs:CVE-2021-29593

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29593

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The implementation of the `BatchToSpaceNd` TFLite operator is vulnerable to a division by zero error(https://github.com/tensorflow/tensorflow/blob/b5ed552fe55895aee8bd8b191f744a0699...

CVEs:CVE-2021-29593

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29593

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-719

CVEs:CVE-2021-29593

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29594

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. TFLite's convolution code(https://github.com/tensorflow/tensorflow/blob/09c73bca7d648e961dd05898292d91a8322a9d45/tensorflow/lite/kernels/conv.cc) has multiple division where the div...

CVEs:CVE-2021-29594

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29594

Open SourceCoalition ESS < 30%LOW2021-05-14

Division by zero in TFLite's convolution code

CVEs:CVE-2021-29594

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29594

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-720

CVEs:CVE-2021-29594

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29595

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-721

CVEs:CVE-2021-29595

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29595

Open SourceCoalition ESS < 30%LOW2021-05-14

Division by zero in TFLite's implementation of `DepthToSpace`

CVEs:CVE-2021-29595

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29595

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The implementation of the `DepthToSpace` TFLite operator is vulnerable to a division by zero error(https://github.com/tensorflow/tensorflow/blob/0d45ea1ca641b21b73bcf9c00e0179cda284...

CVEs:CVE-2021-29595

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29596

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The implementation of the `EmbeddingLookup` TFLite operator is vulnerable to a division by zero error(https://github.com/tensorflow/tensorflow/blob/e4b29809543b250bc9b19678ec4776299...

CVEs:CVE-2021-29596

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29596

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-722

CVEs:CVE-2021-29596

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29596

Open SourceCoalition ESS < 30%LOW2021-05-14

Division by zero in TFLite's implementation of `EmbeddingLookup`

CVEs:CVE-2021-29596

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29597

Open SourceCoalition ESS < 30%LOW2021-05-14

Division by zero in TFLite's implementation of `SpaceToBatchNd`

CVEs:CVE-2021-29597

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29597

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The implementation of the `SpaceToBatchNd` TFLite operator is [vulnerable to a division by zero error](https://github.com/tensorflow/tensorflow/blob/412c7d9bb8f8a762c5b266c9e73bfa16...

CVEs:CVE-2021-29597

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29597

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-723

CVEs:CVE-2021-29597

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29598

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-724

CVEs:CVE-2021-29598

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29598

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The implementation of the `SVDF` TFLite operator is vulnerable to a division by zero error(https://github.com/tensorflow/tensorflow/blob/7f283ff806b2031f407db64c4d3edcda8fb9f9f5/ten...

CVEs:CVE-2021-29598

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29598

Open SourceCoalition ESS < 30%LOW2021-05-14

Division by zero in TFLite's implementation of `SVDF`

CVEs:CVE-2021-29598

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29600

Open SourceCoalition ESS < 30%LOW2021-05-14

Division by zero in TFLite's implementation of `OneHot`

CVEs:CVE-2021-29600

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29600

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-726

CVEs:CVE-2021-29600

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29600

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The implementation of the `OneHot` TFLite operator is vulnerable to a division by zero error(https://github.com/tensorflow/tensorflow/blob/f61c57bd425878be108ec787f4d96390579fb83e/t...

CVEs:CVE-2021-29600

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29603

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-729

CVEs:CVE-2021-29603

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29603

Open SourceCoalition ESS < 30%LOW2021-05-14

Heap OOB write in TFLite

CVEs:CVE-2021-29603

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29603

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. A specially crafted TFLite model could trigger an OOB write on heap in the TFLite implementation of `ArgMin`/`ArgMax`(https://github.com/tensorflow/tensorflow/blob/102b211d892f3abc1...

CVEs:CVE-2021-29603

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29610

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-736

CVEs:CVE-2021-29610

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29610

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The validation in `tf.raw_ops.QuantizeAndDequantizeV2` allows invalid values for `axis` argument:. The validation(https://github.com/tensorflow/tensorflow/blob/eccb7ec454e6617738554...

CVEs:CVE-2021-29610

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29610

Open SourceCoalition ESS < 30%HIGH2021-05-14

Invalid validation in `QuantizeAndDequantizeV2`

CVEs:CVE-2021-29610

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29566

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can write outside the bounds of heap allocated arrays by passing invalid arguments to `tf.raw_ops.Dilation2DBackpropInput`. This is because the implementation(https://gi...

CVEs:CVE-2021-29566

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29566

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-692

CVEs:CVE-2021-29566

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29566

Open SourceCoalition ESS < 30%HIGH2021-05-14

Heap OOB access in `Dilation2DBackpropInput`

CVEs:CVE-2021-29566

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29574

Open SourceCoalition ESS < 30%HIGH2021-05-14

Undefined behavior in `MaxPool3DGradGrad`

CVEs:CVE-2021-29574

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29574

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.MaxPool3DGradGrad` exhibits undefined behavior by dereferencing null pointers backing attacker-supplied empty tensors. The implementation(https://g...

CVEs:CVE-2021-29574

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29574

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-700

CVEs:CVE-2021-29574

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29525

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-651

CVEs:CVE-2021-29525

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29525

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a division by 0 in `tf.raw_ops.Conv2DBackpropInput`. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/b40060c9f697b044e310791...

CVEs:CVE-2021-29525

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29525

Open SourceCoalition ESS < 30%HIGH2021-05-14

Division by 0 in `Conv2DBackpropInput`

CVEs:CVE-2021-29525

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29546

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-672

CVEs:CVE-2021-29546

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29546

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger an integer division by zero undefined behavior in `tf.raw_ops.QuantizedBiasAdd`. This is because the implementation of the Eigen kernel(https://github.com/te...

CVEs:CVE-2021-29546

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29546

Open SourceCoalition ESS < 30%HIGH2021-05-14

Division by 0 in `QuantizedBiasAdd`

CVEs:CVE-2021-29546

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-0605

Open SourceCoalition ESS < 30%MEDIUM2021-05-18

In pfkey_dump of af_key.c, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure in the kernel with System execution privileges needed. User interaction is not needed for exploitation.Prod...

CVEs:CVE-2021-0605

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-24x6-8c7m-hv3f

Open SourceCoalition ESS < 30%LOW2021-05-21

Heap OOB read in TFLite's implementation of `Minimum` or `Maximum`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-24x6-8c7m-hv3f

Open SourceCoalition ESS < 30%LOW2021-05-21

Heap OOB read in TFLite's implementation of `Minimum` or `Maximum`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-c45w-2wxr-pp53

Open SourceCoalition ESS < 30%HIGH2021-05-21

Heap OOB read in `tf.raw_ops.Dequantize`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-c45w-2wxr-pp53

Open SourceCoalition ESS < 30%HIGH2021-05-21

Heap OOB read in `tf.raw_ops.Dequantize`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-6qgm-fv6v-rfpv

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Overflow/denial of service in `tf.raw_ops.ReverseSequence`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-6qgm-fv6v-rfpv

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Overflow/denial of service in `tf.raw_ops.ReverseSequence`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-3h8m-483j-7xxm

Open SourceCoalition ESS < 30%HIGH2021-05-21

Heap out of bounds read in `RequantizationRange`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-3h8m-483j-7xxm

Open SourceCoalition ESS < 30%HIGH2021-05-21

Heap out of bounds read in `RequantizationRange`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-59q2-x2qc-4c97

Open SourceCoalition ESS < 30%HIGH2021-05-21

Heap OOB access in unicode ops

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-59q2-x2qc-4c97

Open SourceCoalition ESS < 30%HIGH2021-05-21

Heap OOB access in unicode ops

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-h9px-9vqg-222h

Open SourceCoalition ESS < 30%LOW2021-05-21

Heap OOB in `QuantizeAndDequantizeV3`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-h9px-9vqg-222h

Open SourceCoalition ESS < 30%LOW2021-05-21

Heap OOB in `QuantizeAndDequantizeV3`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-4hrh-9vmp-2jgg

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap buffer overflow in `StringNGrams`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-4hrh-9vmp-2jgg

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap buffer overflow in `StringNGrams`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-j47f-4232-hvv8

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap out of bounds read in `RaggedCross`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-j47f-4232-hvv8

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap out of bounds read in `RaggedCross`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-4vf2-4xcg-65cx

Open SourceCoalition ESS < 30%HIGH2021-05-21

Division by 0 in `Conv2D`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-4vf2-4xcg-65cx

Open SourceCoalition ESS < 30%HIGH2021-05-21

Division by 0 in `Conv2D`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-84mw-34w6-2q43

Open SourceCoalition ESS < 30%HIGH2021-05-21

Null pointer dereference via invalid Ragged Tensors

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-84mw-34w6-2q43

Open SourceCoalition ESS < 30%HIGH2021-05-21

Null pointer dereference via invalid Ragged Tensors

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-153

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-153

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-163

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-163

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-169

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-169

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-179

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-179

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-190

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-190

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-196

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-196

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-206

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-206

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-212

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-212

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-219

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-219

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-227

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-227

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-444

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-444

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-454

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-454

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-460

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-460

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-470

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-470

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-481

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-481

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-487

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-487

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-497

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-497

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-503

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-503

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-510

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-510

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-518

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-518

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-642

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-642

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-652

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-652

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-658

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-658

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-668

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-668

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-679

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-679

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-685

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-685

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-695

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-695

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-701

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-701

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-708

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-708

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-716

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-716

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29516

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. Calling `tf.raw_ops.RaggedTensorToVariant` with arguments specifying an invalid ragged tensor results in a null pointer dereference. The implementation of `RaggedTensorToVariant` op...

CVEs:CVE-2021-29516

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29516

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-642

CVEs:CVE-2021-29516

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29516

Open SourceCoalition ESS < 30%HIGH2021-05-14

Null pointer dereference via invalid Ragged Tensors

CVEs:CVE-2021-29516

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29590

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-716

CVEs:CVE-2021-29590

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29590

Open SourceCoalition ESS < 30%LOW2021-05-14

Heap OOB read in TFLite's implementation of `Minimum` or `Maximum`

CVEs:CVE-2021-29590

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29590

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The implementations of the `Minimum` and `Maximum` TFLite operators can be used to read data outside of bounds of heap allocated objects, if any of the two input tensor arguments ar...

CVEs:CVE-2021-29590

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29559

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-685

CVEs:CVE-2021-29559

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29559

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can access data outside of bounds of heap allocated array in `tf.raw_ops.UnicodeEncode`. This is because the implementation(https://github.com/tensorflow/tensorflow/blob...

CVEs:CVE-2021-29559

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29559

Open SourceCoalition ESS < 30%HIGH2021-05-14

Heap OOB access in unicode ops

CVEs:CVE-2021-29559

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29569

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.MaxPoolGradWithArgmax` can cause reads outside of bounds of heap allocated data if attacker supplies specially crafted inputs. The implementation(h...

CVEs:CVE-2021-29569

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29569

Open SourceCoalition ESS < 30%HIGH2021-05-14

Heap out of bounds read in `RequantizationRange`

CVEs:CVE-2021-29569

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29569

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-695

CVEs:CVE-2021-29569

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29575

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-701

CVEs:CVE-2021-29575

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29575

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.ReverseSequence` allows for stack overflow and/or `CHECK`-fail based denial of service. The implementation(https://github.com/tensorflow/tensorflow...

CVEs:CVE-2021-29575

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29575

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

Overflow/denial of service in `tf.raw_ops.ReverseSequence`

CVEs:CVE-2021-29575

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29582

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-708

CVEs:CVE-2021-29582

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29582

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. Due to lack of validation in `tf.raw_ops.Dequantize`, an attacker can trigger a read from outside of bounds of heap allocated data. The implementation(https://github.com/tensorflow/...

CVEs:CVE-2021-29582

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29582

Open SourceCoalition ESS < 30%HIGH2021-05-14

Heap OOB read in `tf.raw_ops.Dequantize`

CVEs:CVE-2021-29582

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29526

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a division by 0 in `tf.raw_ops.Conv2D`. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/988087bd83f144af14087fe4fecee2d250d9...

CVEs:CVE-2021-29526

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29526

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-652

CVEs:CVE-2021-29526

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29526

Open SourceCoalition ESS < 30%HIGH2021-05-14

Division by 0 in `Conv2D`

CVEs:CVE-2021-29526

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29532

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can force accesses outside the bounds of heap allocated arrays by passing in invalid tensor values to `tf.raw_ops.RaggedCross`. This is because the implementation(https:...

CVEs:CVE-2021-29532

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29532

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-658

CVEs:CVE-2021-29532

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29532

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

Heap out of bounds read in `RaggedCross`

CVEs:CVE-2021-29532

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29542

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow by passing crafted inputs to `tf.raw_ops.StringNGrams`. This is because the implementation(https://github.com/tensorflow/tensorflow/blob...

CVEs:CVE-2021-29542

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29542

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-668

CVEs:CVE-2021-29542

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29542

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

Heap buffer overflow in `StringNGrams`

CVEs:CVE-2021-29542

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29553

Open SourceCoalition ESS < 30%LOW2021-05-14

Heap OOB in `QuantizeAndDequantizeV3`

CVEs:CVE-2021-29553

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29553

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can read data outside of bounds of heap allocated buffer in `tf.raw_ops.QuantizeAndDequantizeV3`. This is because the implementation(https://github.com/tensorflow/tensor...

CVEs:CVE-2021-29553

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29553

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-679

CVEs:CVE-2021-29553

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-4p4p-www8-8fv9

Open SourceCoalition ESS < 30%HIGH2021-05-21

Reference binding to null in `ParameterizedTruncatedNormal`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-4p4p-www8-8fv9

Open SourceCoalition ESS < 30%HIGH2021-05-21

Reference binding to null in `ParameterizedTruncatedNormal`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-205

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-205

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-496

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-496

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-694

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-694

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29568

Open SourceCoalition ESS < 30%HIGH2021-05-14

Reference binding to null in `ParameterizedTruncatedNormal`

CVEs:CVE-2021-29568

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29568

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger undefined behavior by binding to null pointer in `tf.raw_ops.ParameterizedTruncatedNormal`. This is because the implementation(https://github.com/tensorflow/...

CVEs:CVE-2021-29568

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29568

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-694

CVEs:CVE-2021-29568

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-wvjw-p9f5-vq28

Open SourceCoalition ESS < 30%LOW2021-05-21

Segfault in `tf.raw_ops.SparseCountSparseOutput`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-wvjw-p9f5-vq28

Open SourceCoalition ESS < 30%LOW2021-05-21

Segfault in `tf.raw_ops.SparseCountSparseOutput`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-256

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-256

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-547

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-547

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-745

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-745

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29619

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-745

CVEs:CVE-2021-29619

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29619

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. Passing invalid arguments (e.g., discovered via fuzzing) to `tf.raw_ops.SparseCountSparseOutput` results in segfault. The fix will be included in TensorFlow 2.5.0. We will also cher...

CVEs:CVE-2021-29619

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29619

Open SourceCoalition ESS < 30%LOW2021-05-14

Segfault in `tf.raw_ops.SparseCountSparseOutput`

CVEs:CVE-2021-29619

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-9c84-4hx6-xmm4

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Integer overflow in TFLite concatentation

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-9c84-4hx6-xmm4

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Integer overflow in TFLite concatentation

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-238

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-238

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-529

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-529

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-727

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-727

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29601

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

Integer overflow in TFLite concatentation

CVEs:CVE-2021-29601

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29601

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The TFLite implementation of concatenation is vulnerable to an integer overflow issue(https://github.com/tensorflow/tensorflow/blob/7b7352a724b690b11bfaae2cd54bc3907daf6285/tensorfl...

CVEs:CVE-2021-29601

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29601

Open SourceCoalition ESS < 30%MEDIUM2021-05-14

PYSEC-2021-727

CVEs:CVE-2021-29601

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-8rm6-75mf-7r7r

Open SourceCoalition ESS < 30%LOW2021-05-21

Division by zero in TFLite's implementation of hashtable lookup

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-8rm6-75mf-7r7r

Open SourceCoalition ESS < 30%LOW2021-05-21

Division by zero in TFLite's implementation of hashtable lookup

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-rf3h-xgv5-2q39

Open SourceCoalition ESS < 30%LOW2021-05-21

Division by zero in TFLite's implementation of `DepthwiseConv`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-rf3h-xgv5-2q39

Open SourceCoalition ESS < 30%LOW2021-05-21

Division by zero in TFLite's implementation of `DepthwiseConv`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-xvjm-fvxx-q3hv

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

CHECK-fail due to integer overflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-xvjm-fvxx-q3hv

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

CHECK-fail due to integer overflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-vq2r-5xvm-3hc3

Open SourceCoalition ESS < 30%HIGH2021-05-21

Segfault in `CTCBeamSearchDecoder`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-vq2r-5xvm-3hc3

Open SourceCoalition ESS < 30%HIGH2021-05-21

Segfault in `CTCBeamSearchDecoder`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-x8h6-xgqx-jqgp

Open SourceCoalition ESS < 30%HIGH2021-05-21

Undefined behavior and `CHECK`-fail in `FractionalMaxPoolGrad`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-x8h6-xgqx-jqgp

Open SourceCoalition ESS < 30%HIGH2021-05-21

Undefined behavior and `CHECK`-fail in `FractionalMaxPoolGrad`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-9vpm-rcf4-9wqw

Open SourceCoalition ESS < 30%HIGH2021-05-21

Division by 0 in `MaxPoolGradWithArgmax`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-9vpm-rcf4-9wqw

Open SourceCoalition ESS < 30%HIGH2021-05-21

Division by 0 in `MaxPoolGradWithArgmax`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-5gqf-456p-4836

Open SourceCoalition ESS < 30%HIGH2021-05-21

Reference binding to nullptr in `SdcaOptimizer`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-5gqf-456p-4836

Open SourceCoalition ESS < 30%HIGH2021-05-21

Reference binding to nullptr in `SdcaOptimizer`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-wp3c-xw9g-gpcg

Open SourceCoalition ESS < 30%HIGH2021-05-21

Lack of validation in `SparseDenseCwiseMul`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-wp3c-xw9g-gpcg

Open SourceCoalition ESS < 30%HIGH2021-05-21

Lack of validation in `SparseDenseCwiseMul`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-r6pg-pjwc-j585

Open SourceCoalition ESS < 30%HIGH2021-05-21

Null pointer dereference in `SparseFillEmptyRows`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-r6pg-pjwc-j585

Open SourceCoalition ESS < 30%HIGH2021-05-21

Null pointer dereference in `SparseFillEmptyRows`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-75f6-78jr-4656

Open SourceCoalition ESS < 30%HIGH2021-05-21

Null pointer dereference in `EditDistance`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-75f6-78jr-4656

Open SourceCoalition ESS < 30%HIGH2021-05-21

Null pointer dereference in `EditDistance`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-ph87-fvjr-v33w

Open SourceCoalition ESS < 30%HIGH2021-05-21

CHECK-fail in `tf.raw_ops.RFFT`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-ph87-fvjr-v33w

Open SourceCoalition ESS < 30%HIGH2021-05-21

CHECK-fail in `tf.raw_ops.RFFT`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-36vm-xw34-x4pj

Open SourceCoalition ESS < 30%HIGH2021-05-21

CHECK-fail in `tf.raw_ops.IRFFT`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-36vm-xw34-x4pj

Open SourceCoalition ESS < 30%HIGH2021-05-21

CHECK-fail in `tf.raw_ops.IRFFT`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-gvm4-h8j3-rjrq

Open SourceCoalition ESS < 30%HIGH2021-05-21

CHECK-fail in `LoadAndRemapMatrix`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-gvm4-h8j3-rjrq

Open SourceCoalition ESS < 30%HIGH2021-05-21

CHECK-fail in `LoadAndRemapMatrix`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-xw93-v57j-fcgh

Open SourceCoalition ESS < 30%HIGH2021-05-21

Division by 0 in `SparseMatMul`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-xw93-v57j-fcgh

Open SourceCoalition ESS < 30%HIGH2021-05-21

Division by 0 in `SparseMatMul`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-fxqh-cfjm-fp93

Open SourceCoalition ESS < 30%HIGH2021-05-21

Division by 0 in `Reverse`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-fxqh-cfjm-fp93

Open SourceCoalition ESS < 30%HIGH2021-05-21

Division by 0 in `Reverse`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-r35g-4525-29fq

Open SourceCoalition ESS < 30%HIGH2021-05-21

Division by 0 in `FusedBatchNorm`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-r35g-4525-29fq

Open SourceCoalition ESS < 30%HIGH2021-05-21

Division by 0 in `FusedBatchNorm`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-qg48-85hg-mqc5

Open SourceCoalition ESS < 30%HIGH2021-05-21

Division by 0 in `DenseCountSparseOutput`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-qg48-85hg-mqc5

Open SourceCoalition ESS < 30%HIGH2021-05-21

Division by 0 in `DenseCountSparseOutput`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-jhq9-wm9m-cf89

Open SourceCoalition ESS < 30%HIGH2021-05-21

CHECK-failure in `UnsortedSegmentJoin`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-jhq9-wm9m-cf89

Open SourceCoalition ESS < 30%HIGH2021-05-21

CHECK-failure in `UnsortedSegmentJoin`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-f78g-q7r4-9wcv

Open SourceCoalition ESS < 30%HIGH2021-05-21

Division by 0 in `FractionalAvgPool`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-f78g-q7r4-9wcv

Open SourceCoalition ESS < 30%HIGH2021-05-21

Division by 0 in `FractionalAvgPool`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-x83m-p7pv-ch8v

Open SourceCoalition ESS < 30%HIGH2021-05-21

Division by 0 in `QuantizedAdd`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-x83m-p7pv-ch8v

Open SourceCoalition ESS < 30%HIGH2021-05-21

Division by 0 in `QuantizedAdd`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-p45v-v4pw-77jr

Open SourceCoalition ESS < 30%HIGH2021-05-21

Division by 0 in `QuantizedBatchNormWithGlobalNormalization`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-p45v-v4pw-77jr

Open SourceCoalition ESS < 30%HIGH2021-05-21

Division by 0 in `QuantizedBatchNormWithGlobalNormalization`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-4fg4-p75j-w5xj

Open SourceCoalition ESS < 30%HIGH2021-05-21

Heap out of bounds in `QuantizedBatchNormWithGlobalNormalization`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-4fg4-p75j-w5xj

Open SourceCoalition ESS < 30%HIGH2021-05-21

Heap out of bounds in `QuantizedBatchNormWithGlobalNormalization`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-hmg3-c7xj-6qwm

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap buffer overflow in `SparseTensorToCSRSparseMatrix`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-hmg3-c7xj-6qwm

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Heap buffer overflow in `SparseTensorToCSRSparseMatrix`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-fphq-gw9m-ghrv

Open SourceCoalition ESS < 30%HIGH2021-05-21

CHECK-fail in `CTCGreedyDecoder`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-fphq-gw9m-ghrv

Open SourceCoalition ESS < 30%HIGH2021-05-21

CHECK-fail in `CTCGreedyDecoder`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-xqfj-35wv-m3cr

Open SourceCoalition ESS < 30%HIGH2021-05-21

Null pointer dereference in `StringNGrams`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-xqfj-35wv-m3cr

Open SourceCoalition ESS < 30%HIGH2021-05-21

Null pointer dereference in `StringNGrams`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-g4h2-gqm3-c9wq

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Segfault in tf.raw_ops.ImmutableConst

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-g4h2-gqm3-c9wq

Open SourceCoalition ESS < 30%CRITICAL2021-05-21

Segfault in tf.raw_ops.ImmutableConst

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-j8qc-5fqr-52fp

Open SourceCoalition ESS < 30%HIGH2021-05-21

Division by zero in `Conv2DBackpropFilter`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-j8qc-5fqr-52fp

Open SourceCoalition ESS < 30%HIGH2021-05-21

Division by zero in `Conv2DBackpropFilter`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-6j9c-grc6-5m6g

Open SourceCoalition ESS < 30%HIGH2021-05-21

CHECK-fail in SparseConcat

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-6j9c-grc6-5m6g

Open SourceCoalition ESS < 30%HIGH2021-05-21

CHECK-fail in SparseConcat

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-3qxp-qjq7-w4hf

Open SourceCoalition ESS < 30%HIGH2021-05-21

CHECK-fail in tf.raw_ops.EncodePng

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-3qxp-qjq7-w4hf

Open SourceCoalition ESS < 30%HIGH2021-05-21

CHECK-fail in tf.raw_ops.EncodePng

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-6f84-42vf-ppwp

Open SourceCoalition ESS < 30%HIGH2021-05-21

Division by 0 in `QuantizedMul`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-6f84-42vf-ppwp

Open SourceCoalition ESS < 30%HIGH2021-05-21

Division by 0 in `QuantizedMul`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-x4g7-fvjj-prg8

Open SourceCoalition ESS < 30%HIGH2021-05-21

Division by 0 in `QuantizedConv2D`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-x4g7-fvjj-prg8

Open SourceCoalition ESS < 30%HIGH2021-05-21

Division by 0 in `QuantizedConv2D`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-r4pj-74mg-8868

Open SourceCoalition ESS < 30%HIGH2021-05-21

Division by 0 in `Conv2DBackpropFilter`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-r4pj-74mg-8868

Open SourceCoalition ESS < 30%HIGH2021-05-21

Division by 0 in `Conv2DBackpropFilter`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-2cpx-427x-q2c6

Open SourceCoalition ESS < 30%HIGH2021-05-21

CHECK-fail in AddManySparseToTensorsMap

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-2cpx-427x-q2c6

Open SourceCoalition ESS < 30%HIGH2021-05-21

CHECK-fail in AddManySparseToTensorsMap

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-c968-pq7h-7fxv

Open SourceCoalition ESS < 30%HIGH2021-05-21

Division by 0 in `Conv3DBackprop*`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-c968-pq7h-7fxv

Open SourceCoalition ESS < 30%HIGH2021-05-21

Division by 0 in `Conv3DBackprop*`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-hr84-fqvp-48mm

Open SourceCoalition ESS < 30%HIGH2021-05-21

Segfault in SparseCountSparseOutput

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-hr84-fqvp-48mm

Open SourceCoalition ESS < 30%HIGH2021-05-21

Segfault in SparseCountSparseOutput

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-772j-h9xw-ffp5

Open SourceCoalition ESS < 30%MEDIUM2021-05-21

CHECK-fail in SparseCross due to type confusion

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-772j-h9xw-ffp5

Open SourceCoalition ESS < 30%MEDIUM2021-05-21

CHECK-fail in SparseCross due to type confusion

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-772p-x54p-hjrv

Open SourceCoalition ESS < 30%HIGH2021-05-21

Division by zero in `Conv3D`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-772p-x54p-hjrv

Open SourceCoalition ESS < 30%HIGH2021-05-21

Division by zero in `Conv3D`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-154

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-154

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-156

Open SourceCoalition ESS < 30%HIGH2021-05-14

PYSEC-2021-156

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-158

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-158

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-159

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-159

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-160

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-160

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-161

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-161

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-164

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-164

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-165

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-165

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-168

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-168

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-171

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-171

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-175

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-175

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-176

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-176

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-178

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-178

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-180

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-180

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-182

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-182

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-184

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-184

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-185

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-185

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-186

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-186

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-187

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-187

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-189

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-189

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-192

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-192

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-193

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-193

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-194

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-194

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-198

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-198

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-199

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-199

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-200

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-200

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-201

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-201

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-202

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-202

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-204

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-204

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-209

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-209

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-210

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-210

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-217

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-217

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-218

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-218

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-221

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-221

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-239

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-239

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-241

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-241

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-445

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-445

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-447

Open SourceCoalition ESS < 30%HIGH2021-05-14

PYSEC-2021-447

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-449

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-449

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-450

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-450

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-451

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-451

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-452

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-452

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-455

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-455

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-456

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-456

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-459

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-459

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-462

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-462

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-466

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-466

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-467

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-467

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-469

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-469

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-471

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-471

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-473

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-473

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-475

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-475

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-476

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-476

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-477

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-477

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-478

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-478

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-480

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-480

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-483

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-483

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-484

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-484

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-485

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-485

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-489

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-489

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-490

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-490

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-491

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-491

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-492

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-492

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-493

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-493

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-495

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-495

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-500

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-500

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-501

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-501

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-508

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-508

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-509

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-509

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-512

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-512

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-530

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-530

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-532

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-532

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-643

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-643

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-645

Open SourceCoalition ESS < 30%HIGH2021-05-14

PYSEC-2021-645

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-647

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-647

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-648

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-648

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-649

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-649

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-650

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-650

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-653

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-653

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-654

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-654

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-657

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-657

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-660

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-660

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-664

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-664

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-665

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-665

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-667

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-667

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-669

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-669

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-671

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-671

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-673

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-673

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-674

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-674

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-675

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-675

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-676

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-676

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-678

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-678

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-681

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-681

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-682

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-682

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-683

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-683

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-687

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-687

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-688

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-688

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-689

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-689

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-690

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-690

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-691

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-691

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-693

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-693

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-698

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-698

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-699

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-699

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-706

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-706

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-707

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-707

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-710

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-710

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-728

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-728

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-730

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-730

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29517

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-643

CVEs:CVE-2021-29517

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29517

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. A malicious user could trigger a division by 0 in `Conv3D` implementation. The implementation(https://github.com/tensorflow/tensorflow/blob/42033603003965bffac51ae171b51801565e002d/...

CVEs:CVE-2021-29517

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29517

Open SourceCoalition ESS < 30%HIGH2021-05-14

Division by zero in `Conv3D`

CVEs:CVE-2021-29517

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29519

Open SourceCoalition ESS < 30%HIGH2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The API of `tf.raw_ops.SparseCross` allows combinations which would result in a `CHECK`-failure and denial of service. This is because the implementation(https://github.com/tensorfl...

CVEs:CVE-2021-29519

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29519

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-645

CVEs:CVE-2021-29519

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29519

Open SourceCoalition ESS < 30%MEDIUM2021-05-14

CHECK-fail in SparseCross due to type confusion

CVEs:CVE-2021-29519

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29521

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-647

CVEs:CVE-2021-29521

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29521

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. Specifying a negative dense shape in `tf.raw_ops.SparseCountSparseOutput` results in a segmentation fault being thrown out from the standard library as `std::vector` invariants are ...

CVEs:CVE-2021-29521

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29521

Open SourceCoalition ESS < 30%HIGH2021-05-14

Segfault in SparseCountSparseOutput

CVEs:CVE-2021-29521

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29522

Open SourceCoalition ESS < 30%HIGH2021-05-14

Division by 0 in `Conv3DBackprop*`

CVEs:CVE-2021-29522

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29522

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The `tf.raw_ops.Conv3DBackprop*` operations fail to validate that the input tensors are not empty. In turn, this would result in a division by 0. This is because the implementation(...

CVEs:CVE-2021-29522

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29522

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-648

CVEs:CVE-2021-29522

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29523

Open SourceCoalition ESS < 30%HIGH2021-05-14

CHECK-fail in AddManySparseToTensorsMap

CVEs:CVE-2021-29523

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29523

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-649

CVEs:CVE-2021-29523

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29523

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a denial of service via a `CHECK`-fail in `tf.raw_ops.AddManySparseToTensorsMap`. This is because the implementation(https://github.com/tensorflow/tensorflow...

CVEs:CVE-2021-29523

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29524

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a division by 0 in `tf.raw_ops.Conv2DBackpropFilter`. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/496c2630e51c1a478f095b...

CVEs:CVE-2021-29524

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29524

Open SourceCoalition ESS < 30%HIGH2021-05-14

Division by 0 in `Conv2DBackpropFilter`

CVEs:CVE-2021-29524

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29524

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-650

CVEs:CVE-2021-29524

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29602

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-728

CVEs:CVE-2021-29602

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29602

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The implementation of the `DepthwiseConv` TFLite operator is vulnerable to a division by zero error(https://github.com/tensorflow/tensorflow/blob/1a8e885b864c818198a5b2c0cbbeca5a1e8...

CVEs:CVE-2021-29602

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29602

Open SourceCoalition ESS < 30%LOW2021-05-14

Division by zero in TFLite's implementation of `DepthwiseConv`

CVEs:CVE-2021-29602

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29604

Open SourceCoalition ESS < 30%LOW2021-05-14

Division by zero in TFLite's implementation of hashtable lookup

CVEs:CVE-2021-29604

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29604

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The TFLite implementation of hashtable lookup is vulnerable to a division by zero error(https://github.com/tensorflow/tensorflow/blob/1a8e885b864c818198a5b2c0cbbeca5a1e833bc8/tensor...

CVEs:CVE-2021-29604

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29604

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-730

CVEs:CVE-2021-29604

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29555

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service via a FPE runtime error in `tf.raw_ops.FusedBatchNorm`. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/82...

CVEs:CVE-2021-29555

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29555

Open SourceCoalition ESS < 30%HIGH2021-05-14

Division by 0 in `FusedBatchNorm`

CVEs:CVE-2021-29555

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29555

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-681

CVEs:CVE-2021-29555

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29556

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-682

CVEs:CVE-2021-29556

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29556

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service via a FPE runtime error in `tf.raw_ops.Reverse`. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/36229ea9e...

CVEs:CVE-2021-29556

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29556

Open SourceCoalition ESS < 30%HIGH2021-05-14

Division by 0 in `Reverse`

CVEs:CVE-2021-29556

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29557

Open SourceCoalition ESS < 30%HIGH2021-05-14

Division by 0 in `SparseMatMul`

CVEs:CVE-2021-29557

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29557

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-683

CVEs:CVE-2021-29557

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29557

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service via a FPE runtime error in `tf.raw_ops.SparseMatMul`. The division by 0 occurs deep in Eigen code because the `b` tensor is empty. The fix ...

CVEs:CVE-2021-29557

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29561

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-687

CVEs:CVE-2021-29561

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29561

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service by exploiting a `CHECK`-failure coming from `tf.raw_ops.LoadAndRemapMatrix`. This is because the implementation(https://github.com/tensorfl...

CVEs:CVE-2021-29561

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29561

Open SourceCoalition ESS < 30%HIGH2021-05-14

CHECK-fail in `LoadAndRemapMatrix`

CVEs:CVE-2021-29561

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29562

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service by exploiting a `CHECK`-failure coming from the implementation of `tf.raw_ops.IRFFT`. The fix will be included in TensorFlow 2.5.0. We will...

CVEs:CVE-2021-29562

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29562

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-688

CVEs:CVE-2021-29562

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29562

Open SourceCoalition ESS < 30%HIGH2021-05-14

CHECK-fail in `tf.raw_ops.IRFFT`

CVEs:CVE-2021-29562

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29563

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-689

CVEs:CVE-2021-29563

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29563

Open SourceCoalition ESS < 30%HIGH2021-05-14

CHECK-fail in `tf.raw_ops.RFFT`

CVEs:CVE-2021-29563

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29563

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service by exploiting a `CHECK`-failure coming from the implementation of `tf.raw_ops.RFFT`. Eigen code operating on an empty matrix can trigger on...

CVEs:CVE-2021-29563

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29564

Open SourceCoalition ESS < 30%HIGH2021-05-14

Null pointer dereference in `EditDistance`

CVEs:CVE-2021-29564

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29564

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a null pointer dereference in the implementation of `tf.raw_ops.EditDistance`. This is because the implementation(https://github.com/tensorflow/tensorflow/bl...

CVEs:CVE-2021-29564

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29564

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-690

CVEs:CVE-2021-29564

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29565

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-691

CVEs:CVE-2021-29565

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29565

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a null pointer dereference in the implementation of `tf.raw_ops.SparseFillEmptyRows`. This is because of missing validation(https://github.com/tensorflow/ten...

CVEs:CVE-2021-29565

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29565

Open SourceCoalition ESS < 30%HIGH2021-05-14

Null pointer dereference in `SparseFillEmptyRows`

CVEs:CVE-2021-29565

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29567

Open SourceCoalition ESS < 30%HIGH2021-05-14

Lack of validation in `SparseDenseCwiseMul`

CVEs:CVE-2021-29567

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29567

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-693

CVEs:CVE-2021-29567

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29567

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. Due to lack of validation in `tf.raw_ops.SparseDenseCwiseMul`, an attacker can trigger denial of service via `CHECK`-fails or accesses to outside the bounds of heap allocated data. ...

CVEs:CVE-2021-29567

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29572

Open SourceCoalition ESS < 30%HIGH2021-05-14

Reference binding to nullptr in `SdcaOptimizer`

CVEs:CVE-2021-29572

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29572

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-698

CVEs:CVE-2021-29572

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29572

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.SdcaOptimizer` triggers undefined behavior due to dereferencing a null pointer. The implementation(https://github.com/tensorflow/tensorflow/blob/60...

CVEs:CVE-2021-29572

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29573

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.MaxPoolGradWithArgmax` is vulnerable to a division by 0. The implementation(https://github.com/tensorflow/tensorflow/blob/279bab6efa22752a2827621b7...

CVEs:CVE-2021-29573

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29573

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-699

CVEs:CVE-2021-29573

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29573

Open SourceCoalition ESS < 30%HIGH2021-05-14

Division by 0 in `MaxPoolGradWithArgmax`

CVEs:CVE-2021-29573

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29580

Open SourceCoalition ESS < 30%HIGH2021-05-14

Undefined behavior and `CHECK`-fail in `FractionalMaxPoolGrad`

CVEs:CVE-2021-29580

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29580

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-706

CVEs:CVE-2021-29580

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29580

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.FractionalMaxPoolGrad` triggers an undefined behavior if one of the input tensors is empty. The code is also vulnerable to a denial of service atta...

CVEs:CVE-2021-29580

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29581

Open SourceCoalition ESS < 30%HIGH2021-05-14

Segfault in `CTCBeamSearchDecoder`

CVEs:CVE-2021-29581

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29581

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. Due to lack of validation in `tf.raw_ops.CTCBeamSearchDecoder`, an attacker can trigger denial of service via segmentation faults. The implementation(https://github.com/tensorflow/t...

CVEs:CVE-2021-29581

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29581

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-707

CVEs:CVE-2021-29581

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29584

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a denial of service via a `CHECK`-fail in caused by an integer overflow in constructing a new tensor shape. This is because the implementation(https://github...

CVEs:CVE-2021-29584

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29584

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

CHECK-fail due to integer overflow

CVEs:CVE-2021-29584

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29584

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-710

CVEs:CVE-2021-29584

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-191

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-191

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-482

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-482

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-680

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-680

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29527

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a division by 0 in `tf.raw_ops.QuantizedConv2D`. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/00e9a4d67d76703fa1aee33dac5...

CVEs:CVE-2021-29527

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29527

Open SourceCoalition ESS < 30%HIGH2021-05-14

Division by 0 in `QuantizedConv2D`

CVEs:CVE-2021-29527

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29527

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-653

CVEs:CVE-2021-29527

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29528

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a division by 0 in `tf.raw_ops.QuantizedMul`. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/55900e961ed4a23b43839202491215...

CVEs:CVE-2021-29528

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29528

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-654

CVEs:CVE-2021-29528

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29528

Open SourceCoalition ESS < 30%HIGH2021-05-14

Division by 0 in `QuantizedMul`

CVEs:CVE-2021-29528

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29531

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-657

CVEs:CVE-2021-29531

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29531

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a `CHECK` fail in PNG encoding by providing an empty input tensor as the pixel data. This is because the implementation(https://github.com/tensorflow/tensorf...

CVEs:CVE-2021-29531

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29531

Open SourceCoalition ESS < 30%HIGH2021-05-14

CHECK-fail in tf.raw_ops.EncodePng

CVEs:CVE-2021-29531

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29534

Open SourceCoalition ESS < 30%HIGH2021-05-14

CHECK-fail in SparseConcat

CVEs:CVE-2021-29534

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29534

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a denial of service via a `CHECK`-fail in `tf.raw_ops.SparseConcat`. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/b432a38...

CVEs:CVE-2021-29534

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29534

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-660

CVEs:CVE-2021-29534

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29538

Open SourceCoalition ESS < 30%HIGH2021-05-14

Division by zero in `Conv2DBackpropFilter`

CVEs:CVE-2021-29538

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29538

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-664

CVEs:CVE-2021-29538

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29538

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a division by zero to occur in `Conv2DBackpropFilter`. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/1b0296c3b8dd9bd948f924a...

CVEs:CVE-2021-29538

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29539

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-665

CVEs:CVE-2021-29539

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29539

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. Calling `tf.raw_ops.ImmutableConst`(https://www.tensorflow.org/api_docs/python/tf/raw_ops/ImmutableConst) with a `dtype` of `tf.resource` or `tf.variant` results in a segfault in th...

CVEs:CVE-2021-29539

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29539

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

Segfault in tf.raw_ops.ImmutableConst

CVEs:CVE-2021-29539

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29541

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-667

CVEs:CVE-2021-29541

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29541

Open SourceCoalition ESS < 30%HIGH2021-05-14

Null pointer dereference in `StringNGrams`

CVEs:CVE-2021-29541

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29541

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a dereference of a null pointer in `tf.raw_ops.StringNGrams`. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/1cdd4da1428221...

CVEs:CVE-2021-29541

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29543

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-669

CVEs:CVE-2021-29543

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29543

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a denial of service via a `CHECK`-fail in `tf.raw_ops.CTCGreedyDecoder`. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/161...

CVEs:CVE-2021-29543

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29543

Open SourceCoalition ESS < 30%HIGH2021-05-14

CHECK-fail in `CTCGreedyDecoder`

CVEs:CVE-2021-29543

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29545

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-671

CVEs:CVE-2021-29545

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29545

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

Heap buffer overflow in `SparseTensorToCSRSparseMatrix`

CVEs:CVE-2021-29545

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29545

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a denial of service via a `CHECK`-fail in converting sparse tensors to CSR Sparse matrices. This is because the implementation(https://github.com/tensorflow/...

CVEs:CVE-2021-29545

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29547

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a segfault and denial of service via accessing data outside of bounds in `tf.raw_ops.QuantizedBatchNormWithGlobalNormalization`. This is because the implementa...

CVEs:CVE-2021-29547

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29547

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-673

CVEs:CVE-2021-29547

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29547

Open SourceCoalition ESS < 30%HIGH2021-05-14

Heap out of bounds in `QuantizedBatchNormWithGlobalNormalization`

CVEs:CVE-2021-29547

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29548

Open SourceCoalition ESS < 30%HIGH2021-05-14

Division by 0 in `QuantizedBatchNormWithGlobalNormalization`

CVEs:CVE-2021-29548

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29548

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-674

CVEs:CVE-2021-29548

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29548

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a runtime division by zero error and denial of service in `tf.raw_ops.QuantizedBatchNormWithGlobalNormalization`. This is because the implementation(https://gi...

CVEs:CVE-2021-29548

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29549

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a runtime division by zero error and denial of service in `tf.raw_ops.QuantizedBatchNormWithGlobalNormalization`. This is because the implementation(https://gi...

CVEs:CVE-2021-29549

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29549

Open SourceCoalition ESS < 30%HIGH2021-05-14

Division by 0 in `QuantizedAdd`

CVEs:CVE-2021-29549

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29549

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-675

CVEs:CVE-2021-29549

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29550

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-676

CVEs:CVE-2021-29550

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29550

Open SourceCoalition ESS < 30%HIGH2021-05-14

Division by 0 in `FractionalAvgPool`

CVEs:CVE-2021-29550

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29550

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a runtime division by zero error and denial of service in `tf.raw_ops.FractionalAvgPool`. This is because the implementation(https://github.com/tensorflow/tens...

CVEs:CVE-2021-29550

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29552

Open SourceCoalition ESS < 30%HIGH2021-05-14

CHECK-failure in `UnsortedSegmentJoin`

CVEs:CVE-2021-29552

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29552

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service by controlling the values of `num_segments` tensor argument for `UnsortedSegmentJoin`. This is because the implementation(https://github.co...

CVEs:CVE-2021-29552

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29552

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-678

CVEs:CVE-2021-29552

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29554

Open SourceCoalition ESS < 30%HIGH2021-05-14

Division by 0 in `DenseCountSparseOutput`

CVEs:CVE-2021-29554

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29554

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-680

CVEs:CVE-2021-29554

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29554

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service via a FPE runtime error in `tf.raw_ops.DenseCountSparseOutput`. This is because the implementation(https://github.com/tensorflow/tensorflow...

CVEs:CVE-2021-29554

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-0485

Open SourceCoalition ESS < 30%HIGH2021-05-04

In getMinimalSize of PipBoundsAlgorithm.java, there is a possible bypass of restrictions on background processes due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interact...

CVEs:CVE-2021-0485

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-179040600

GoogleCoalition ESS < 30%2021-05-01

ASB-A-179040600

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

GHSA-545v-42p7-98fq

Open SourceCoalition ESS < 30%HIGH2021-05-21

Heap out of bounds read in `MaxPoolGradWithArgmax`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-545v-42p7-98fq

Open SourceCoalition ESS < 30%HIGH2021-05-21

Heap out of bounds read in `MaxPoolGradWithArgmax`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-207

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-207

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-498

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-498

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-696

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

PYSEC-2021-696

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29570

Open SourceCoalition ESS < 30%HIGH2021-05-14

Heap out of bounds read in `MaxPoolGradWithArgmax`

CVEs:CVE-2021-29570

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-29570

Open SourceCoalition ESS < 30%CRITICAL2021-05-14

TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.MaxPoolGradWithArgmax` can cause reads outside of bounds of heap allocated data if attacker supplies specially crafted inputs. The implementation(h...

CVEs:CVE-2021-29570

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-29570

Open SourceCoalition ESS < 30%LOW2021-05-14

PYSEC-2021-696

CVEs:CVE-2021-29570

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

ASB-A-179039763

GoogleCoalition ESS < 30%2021-05-01

ASB-A-179039763

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2021-0477

Open SourceCoalition ESS < 30%HIGH2021-05-04

In notifyScreenshotError of ScreenshotNotificationsController.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not ne...

CVEs:CVE-2021-0477

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0490

Open SourceCoalition ESS < 30%HIGH2021-05-04

In memory management driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product...

CVEs:CVE-2021-0490

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-183464868

GoogleCoalition ESS < 30%HIGH2021-05-01

ASB-A-183464868

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-172354397

GoogleCoalition ESS < 30%2021-05-01

PUB-A-172354397

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-0482

Open SourceCoalition ESS < 30%HIGH2021-05-04

In BinderDiedCallback of MediaCodec.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Pro...

CVEs:CVE-2021-0482

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0484

Open SourceCoalition ESS < 30%MEDIUM2021-05-04

In readVector of IMediaPlayer.cpp, there is a possible read of uninitialized heap data due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2021-0484

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0492

Open SourceCoalition ESS < 30%HIGH2021-05-04

In memory management driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product...

CVEs:CVE-2021-0492

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0493

Open SourceCoalition ESS < 30%HIGH2021-05-04

In memory management driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product...

CVEs:CVE-2021-0493

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0495

Open SourceCoalition ESS < 30%HIGH2021-05-04

In memory management driver, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: An...

CVEs:CVE-2021-0495

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-183459078

GoogleCoalition ESS < 30%HIGH2021-05-01

ASB-A-183459078

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-183459083

GoogleCoalition ESS < 30%HIGH2021-05-01

ASB-A-183459083

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-183461317

GoogleCoalition ESS < 30%HIGH2021-05-01

ASB-A-183461317

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-0489

Open SourceCoalition ESS < 30%HIGH2021-05-04

In memory management driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product...

CVEs:CVE-2021-0489

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0494

Open SourceCoalition ESS < 30%HIGH2021-05-04

In memory management driver, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: A...

CVEs:CVE-2021-0494

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-183461318

GoogleCoalition ESS < 30%HIGH2021-05-01

ASB-A-183461318

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-183464866

GoogleCoalition ESS < 30%HIGH2021-05-01

ASB-A-183464866

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-0467

Open SourceCoalition ESS < 30%HIGH2021-05-04

In Chromecast bootROM, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege in the bootloader, with physical USB access, with no additional execution privileges needed. User interact...

CVEs:CVE-2021-0467

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-174490700

GoogleCoalition ESS < 30%HIGH2021-05-01

ASB-A-174490700

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-0496

Open SourceCoalition ESS < 30%HIGH2021-05-04

In memory management driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi...

CVEs:CVE-2021-0496

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0497

Open SourceCoalition ESS < 30%HIGH2021-05-04

In memory management driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi...

CVEs:CVE-2021-0497

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0498

Open SourceCoalition ESS < 30%HIGH2021-05-04

In memory management driver, there is a possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...

CVEs:CVE-2021-0498

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-183461320

GoogleCoalition ESS < 30%HIGH2021-05-01

ASB-A-183461320

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-183461321

GoogleCoalition ESS < 30%HIGH2021-05-01

ASB-A-183461321

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-183467912

GoogleCoalition ESS < 30%HIGH2021-05-01

ASB-A-183467912

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-0491

Open SourceCoalition ESS < 30%HIGH2021-05-04

In memory management driver, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation...

CVEs:CVE-2021-0491

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-183461315

GoogleCoalition ESS < 30%NONE2021-05-01

ASB-A-183461315

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-0487

Open SourceCoalition ESS < 30%HIGH2021-05-04

In onCreate of CalendarDebugActivity.java, there is a possible way to export calendar data to the sdcard without user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. Us...

CVEs:CVE-2021-0487

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-2jx2-76rc-2v7v

Open SourceEPSS <= 49%CRITICAL2021-05-12

Kubernetes Privilege Escalation

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

GHSA-2jx2-76rc-2v7v

Open SourceEPSS <= 49%CRITICAL2021-05-12

Kubernetes Privilege Escalation

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

GHSA-58v3-j75h-xr49

Open SourceEPSS <= 49%MEDIUM2021-05-18

Improper Input Validation in libseccomp-golang

Affected products

ProductStatusVendorPackageEcosystem
seccomp/libseccomp-golang affected github.com github.com/seccomp/libseccomp-golang
Upstream advisory

GHSA-58v3-j75h-xr49

Open SourceEPSS <= 49%MEDIUM2021-05-18

Improper Input Validation in libseccomp-golang

Affected products

ProductStatusVendorPackageEcosystem
seccomp/libseccomp-golang affected github.com github.com/seccomp/libseccomp-golang
Upstream advisory

GHSA-3wxm-m9m4-cprj

GoogleAll remainingNONE2021-05-21

Import of incorrectly embargoed keys could cause early publication

Affected products

ProductStatusVendorPackageEcosystem
google/exposure-notifications-server affected github.com github.com/google/exposure-notifications-server
Upstream advisory

GHSA-3wxm-m9m4-cprj

GoogleAll remainingNONE2021-05-21

Import of incorrectly embargoed keys could cause early publication

Affected products

ProductStatusVendorPackageEcosystem
github.com/google/exposure-notifications-server affected Go github.com/google/exposure-notifications-server
google/exposure-notifications-server affected github.com github.com/google/exposure-notifications-server
google/exposure-notifications-server affected github.com github.com/google/exposure-notifications-server
Upstream advisory

ALBA-2021:1937

Open SourceAll remainingHIGH2021-05-18

protobuf-c bug fix and enhancement update

Affected products

ProductStatusVendorPackageEcosystem
protobuf-c affected AlmaLinux:8 protobuf-c
protobuf-c-compiler affected AlmaLinux:8 protobuf-c-compiler
protobuf-c-devel affected AlmaLinux:8 protobuf-c-devel
Upstream advisory

ALBA-2021:1897

GoogleAll remainingHIGH2021-05-18

maven:3.6 bug fix and enhancement update

Affected products

ProductStatusVendorPackageEcosystem
aopalliance affected AlmaLinux:8 aopalliance
apache-commons-cli affected AlmaLinux:8 apache-commons-cli
apache-commons-codec affected AlmaLinux:8 apache-commons-codec
apache-commons-io affected AlmaLinux:8 apache-commons-io
apache-commons-lang3 affected AlmaLinux:8 apache-commons-lang3
atinject affected AlmaLinux:8 atinject
cdi-api affected AlmaLinux:8 cdi-api
geronimo-annotation affected AlmaLinux:8 geronimo-annotation
google-guice affected AlmaLinux:8 google-guice
guava affected AlmaLinux:8 guava
httpcomponents-core affected AlmaLinux:8 httpcomponents-core
jansi affected AlmaLinux:8 jansi
jcl-over-slf4j affected AlmaLinux:8 jcl-over-slf4j
jsoup affected AlmaLinux:8 jsoup
jsr-305 affected AlmaLinux:8 jsr-305
maven-resolver affected AlmaLinux:8 maven-resolver
maven-shared-utils affected AlmaLinux:8 maven-shared-utils
maven-wagon affected AlmaLinux:8 maven-wagon
plexus-cipher affected AlmaLinux:8 plexus-cipher
plexus-classworlds affected AlmaLinux:8 plexus-classworlds
plexus-containers-component-annotations affected AlmaLinux:8 plexus-containers-component-annotations
plexus-interpolation affected AlmaLinux:8 plexus-interpolation
plexus-sec-dispatcher affected AlmaLinux:8 plexus-sec-dispatcher
plexus-utils affected AlmaLinux:8 plexus-utils
sisu affected AlmaLinux:8 sisu
slf4j affected AlmaLinux:8 slf4j
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.