CVE-2021-28550
CVEs:CVE-2021-28550
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 29 are already weaponised in the wild.
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
CVEs:CVE-2021-28550
Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by a Use After Free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arb...
CVEs:CVE-2021-28550
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| acrobat | affected | adobe | — | — |
| acrobat_dc | affected | adobe | — | — |
| acrobat_reader | affected | adobe | — | — |
| acrobat_reader_dc | affected | adobe | — | — |
Adobe Acrobat Reader use after free vulnerability could lead to arbitrary code execution
CVEs:CVE-2021-28550
CVEs:CVE-2021-30533
Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions via a crafted iframe.
CVEs:CVE-2021-30533
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-28663
The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a use-after-free. This affects Bifrost r0p0 through r28p0 before r29p0, Valhall r19p0 through r28p0 before r29...
CVEs:CVE-2021-28663
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| bifrost_gpu_kernel_driver | affected | arm | — | — |
| midgard_gpu_kernel_driver | affected | arm | — | — |
| valhall_gpu_kernel_driver | affected | arm | — | — |
The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a use-after-free. This affects Bifrost r0p0 through r28p0 before r29p0, Valhall r19p0 through r28p0 before r29p0, and Midgard r4p0 through r30p0.
CVEs:CVE-2021-28663
ASB-A-174259860
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve read/write access to read-only pages. This affects Bifrost r0p0 through r29p0 before r30p0, Valhall r19p0 thr...
CVEs:CVE-2021-28664
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| bifrost_gpu_kernel_driver | affected | arm | — | — |
| midgard_gpu_kernel_driver | affected | arm | — | — |
| valhall_gpu_kernel_driver | affected | arm | — | — |
The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve read/write access to read-only pages. This affects Bifrost r0p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r8p0 through r30p0 before r31p0.
CVEs:CVE-2021-28664
CVEs:CVE-2021-28664
ASB-A-174588870
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2021-30665
A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 7.4.1, iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6, iOS 12.5.3, macOS Big Sur 11.3.1. Processing maliciously crafted web content may lead to arbitrary co...
CVEs:CVE-2021-30665
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ipados | affected | apple | — | — |
| iphone_os | affected | apple | — | — |
| macos | affected | apple | — | — |
| tvos | affected | apple | — | — |
| watchos | affected | apple | — | — |
A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 7.4.1, iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6, iOS 12.5.3, macOS Big Sur 11.3.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
CVEs:CVE-2021-30665
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6, iOS 12.5.3, Safari 14.1.1, macOS Big Sur 11.3.1. Processing maliciously crafted web content may lead to arbitrary code exe...
CVEs:CVE-2021-30663
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ipados | affected | apple | — | — |
| iphone_os | affected | apple | — | — |
| macos | affected | apple | — | — |
| safari | affected | apple | — | — |
| tvos | affected | apple | — | — |
CVEs:CVE-2021-30663
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6, iOS 12.5.3, Safari 14.1.1, macOS Big Sur 11.3.1. Processing maliciously crafted web content may lead to arbitrary code execution.
CVEs:CVE-2021-30663
Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
CVEs:CVE-2021-1905
Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon ...
CVEs:CVE-2021-1905
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| apq8009_firmware | affected | qualcomm | — | — |
| apq8009w_firmware | affected | qualcomm | — | — |
| apq8017_firmware | affected | qualcomm | — | — |
| apq8053_firmware | affected | qualcomm | — | — |
| apq8064au_firmware | affected | qualcomm | — | — |
| apq8096au_firmware | affected | qualcomm | — | — |
| aqt1000_firmware | affected | qualcomm | — | — |
| ar8031_firmware | affected | qualcomm | — | — |
| ar8035_firmware | affected | qualcomm | — | — |
| ar8151_firmware | affected | qualcomm | — | — |
| csra6620_firmware | affected | qualcomm | — | — |
| csra6640_firmware | affected | qualcomm | — | — |
| fsm10055_firmware | affected | qualcomm | — | — |
| fsm10056_firmware | affected | qualcomm | — | — |
| mdm9206_firmware | affected | qualcomm | — | — |
| mdm9607_firmware | affected | qualcomm | — | — |
| mdm9626_firmware | affected | qualcomm | — | — |
| mdm9628_firmware | affected | qualcomm | — | — |
| mdm9650_firmware | affected | qualcomm | — | — |
| msm8909w_firmware | affected | qualcomm | — | — |
| msm8917_firmware | affected | qualcomm | — | — |
| msm8953_firmware | affected | qualcomm | — | — |
| msm8996au_firmware | affected | qualcomm | — | — |
| pm215_firmware | affected | qualcomm | — | — |
| pm3003a_firmware | affected | qualcomm | — | — |
| pm4125_firmware | affected | qualcomm | — | — |
| pm4250_firmware | affected | qualcomm | — | — |
| pm439_firmware | affected | qualcomm | — | — |
| pm456_firmware | affected | qualcomm | — | — |
| pm6125_firmware | affected | qualcomm | — | — |
| pm6150a_firmware | affected | qualcomm | — | — |
| pm6150_firmware | affected | qualcomm | — | — |
| pm6150l_firmware | affected | qualcomm | — | — |
| pm6250_firmware | affected | qualcomm | — | — |
| pm6350_firmware | affected | qualcomm | — | — |
| pm640a_firmware | affected | qualcomm | — | — |
| pm640l_firmware | affected | qualcomm | — | — |
| pm640p_firmware | affected | qualcomm | — | — |
| pm660a_firmware | affected | qualcomm | — | — |
| pm660_firmware | affected | qualcomm | — | — |
| pm660l_firmware | affected | qualcomm | — | — |
| pm670a_firmware | affected | qualcomm | — | — |
| pm670_firmware | affected | qualcomm | — | — |
| pm670l_firmware | affected | qualcomm | — | — |
| pm7150a_firmware | affected | qualcomm | — | — |
| pm7150l_firmware | affected | qualcomm | — | — |
| pm7250b_firmware | affected | qualcomm | — | — |
| pm7250_firmware | affected | qualcomm | — | — |
| pm8004_firmware | affected | qualcomm | — | — |
| pm8005_firmware | affected | qualcomm | — | — |
| pm8008_firmware | affected | qualcomm | — | — |
| pm8009_firmware | affected | qualcomm | — | — |
| pm8150a_firmware | affected | qualcomm | — | — |
| pm8150b_firmware | affected | qualcomm | — | — |
| pm8150c_firmware | affected | qualcomm | — | — |
| pm8150_firmware | affected | qualcomm | — | — |
| pm8150l_firmware | affected | qualcomm | — | — |
| pm8250_firmware | affected | qualcomm | — | — |
| pm8350b_firmware | affected | qualcomm | — | — |
| pm8350bh_firmware | affected | qualcomm | — | — |
| pm8350c_firmware | affected | qualcomm | — | — |
| pm8350_firmware | affected | qualcomm | — | — |
| pm855a_firmware | affected | qualcomm | — | — |
| pm855b_firmware | affected | qualcomm | — | — |
| pm855_firmware | affected | qualcomm | — | — |
| pm855l_firmware | affected | qualcomm | — | — |
| pm855p_firmware | affected | qualcomm | — | — |
| pm8909_firmware | affected | qualcomm | — | — |
| pm8916_firmware | affected | qualcomm | — | — |
| pm8937_firmware | affected | qualcomm | — | — |
| pm8953_firmware | affected | qualcomm | — | — |
| pm8998_firmware | affected | qualcomm | — | — |
| pmc1000h_firmware | affected | qualcomm | — | — |
| pmd9607_firmware | affected | qualcomm | — | — |
| pmd9655_firmware | affected | qualcomm | — | — |
| pme605_firmware | affected | qualcomm | — | — |
| pmi632_firmware | affected | qualcomm | — | — |
| pmi8937_firmware | affected | qualcomm | — | — |
| pmi8952_firmware | affected | qualcomm | — | — |
| pmi8998_firmware | affected | qualcomm | — | — |
| pmk8002_firmware | affected | qualcomm | — | — |
| pmk8003_firmware | affected | qualcomm | — | — |
| pmk8350_firmware | affected | qualcomm | — | — |
| pmm6155au_firmware | affected | qualcomm | — | — |
| pmm8155au_firmware | affected | qualcomm | — | — |
| pmm8195au_firmware | affected | qualcomm | — | — |
| pmm855au_firmware | affected | qualcomm | — | — |
| pmm8920au_firmware | affected | qualcomm | — | — |
| pmm8996au_firmware | affected | qualcomm | — | — |
| pmr525_firmware | affected | qualcomm | — | — |
| pmr735a_firmware | affected | qualcomm | — | — |
| pmr735b_firmware | affected | qualcomm | — | — |
| pmw3100_firmware | affected | qualcomm | — | — |
| pmx20_firmware | affected | qualcomm | — | — |
| pmx24_firmware | affected | qualcomm | — | — |
| pmx50_firmware | affected | qualcomm | — | — |
| pmx55_firmware | affected | qualcomm | — | — |
| qat3514_firmware | affected | qualcomm | — | — |
| qat3516_firmware | affected | qualcomm | — | — |
| qat3518_firmware | affected | qualcomm | — | — |
| qat3519_firmware | affected | qualcomm | — | — |
| qat3522_firmware | affected | qualcomm | — | — |
| qat3550_firmware | affected | qualcomm | — | — |
| qat3555_firmware | affected | qualcomm | — | — |
| qat5515_firmware | affected | qualcomm | — | — |
| qat5516_firmware | affected | qualcomm | — | — |
| qat5522_firmware | affected | qualcomm | — | — |
| qat5533_firmware | affected | qualcomm | — | — |
| qat5568_firmware | affected | qualcomm | — | — |
| qbt1000_firmware | affected | qualcomm | — | — |
| qbt1500_firmware | affected | qualcomm | — | — |
| qbt2000_firmware | affected | qualcomm | — | — |
| qca4020_firmware | affected | qualcomm | — | — |
| qca6174a_firmware | affected | qualcomm | — | — |
| qca6174_firmware | affected | qualcomm | — | — |
| qca6310_firmware | affected | qualcomm | — | — |
| qca6320_firmware | affected | qualcomm | — | — |
| qca6335_firmware | affected | qualcomm | — | — |
| qca6390_firmware | affected | qualcomm | — | — |
| qca6391_firmware | affected | qualcomm | — | — |
| qca6420_firmware | affected | qualcomm | — | — |
| qca6421_firmware | affected | qualcomm | — | — |
| qca6426_firmware | affected | qualcomm | — | — |
| qca6430_firmware | affected | qualcomm | — | — |
| qca6431_firmware | affected | qualcomm | — | — |
| qca6436_firmware | affected | qualcomm | — | — |
| qca6564a_firmware | affected | qualcomm | — | — |
| qca6564au_firmware | affected | qualcomm | — | — |
| qca6564_firmware | affected | qualcomm | — | — |
| qca6574a_firmware | affected | qualcomm | — | — |
| qca6574au_firmware | affected | qualcomm | — | — |
| qca6574_firmware | affected | qualcomm | — | — |
| qca6584au_firmware | affected | qualcomm | — | — |
| qca6595au_firmware | affected | qualcomm | — | — |
| qca6696_firmware | affected | qualcomm | — | — |
| qca8337_firmware | affected | qualcomm | — | — |
| qca9367_firmware | affected | qualcomm | — | — |
| qca9377_firmware | affected | qualcomm | — | — |
| qca9379_firmware | affected | qualcomm | — | — |
| qcc1110_firmware | affected | qualcomm | — | — |
| qcm2290_firmware | affected | qualcomm | — | — |
| qcm4290_firmware | affected | qualcomm | — | — |
| qcm6125_firmware | affected | qualcomm | — | — |
| qcs2290_firmware | affected | qualcomm | — | — |
| qcs405_firmware | affected | qualcomm | — | — |
| qcs410_firmware | affected | qualcomm | — | — |
| qcs4290_firmware | affected | qualcomm | — | — |
| qcs603_firmware | affected | qualcomm | — | — |
| qcs605_firmware | affected | qualcomm | — | — |
| qcs610_firmware | affected | qualcomm | — | — |
| qcs6125_firmware | affected | qualcomm | — | — |
| qdm2301_firmware | affected | qualcomm | — | — |
| qdm2302_firmware | affected | qualcomm | — | — |
| qdm2305_firmware | affected | qualcomm | — | — |
| qdm2307_firmware | affected | qualcomm | — | — |
| qdm2308_firmware | affected | qualcomm | — | — |
| qdm2310_firmware | affected | qualcomm | — | — |
| qdm3301_firmware | affected | qualcomm | — | — |
| qdm4643_firmware | affected | qualcomm | — | — |
| qdm4650_firmware | affected | qualcomm | — | — |
| qdm5620_firmware | affected | qualcomm | — | — |
| qdm5621_firmware | affected | qualcomm | — | — |
| qdm5650_firmware | affected | qualcomm | — | — |
| qdm5652_firmware | affected | qualcomm | — | — |
| qdm5670_firmware | affected | qualcomm | — | — |
| qdm5671_firmware | affected | qualcomm | — | — |
| qdm5677_firmware | affected | qualcomm | — | — |
| qdm5679_firmware | affected | qualcomm | — | — |
| qet4100_firmware | affected | qualcomm | — | — |
| qet4101_firmware | affected | qualcomm | — | — |
| qet5100_firmware | affected | qualcomm | — | — |
| qet5100m_firmware | affected | qualcomm | — | — |
| qet6100_firmware | affected | qualcomm | — | — |
| qet6105_firmware | affected | qualcomm | — | — |
| qet6110_firmware | affected | qualcomm | — | — |
| qfe2101_firmware | affected | qualcomm | — | — |
| qfe2520_firmware | affected | qualcomm | — | — |
| qfe2550_firmware | affected | qualcomm | — | — |
| qfe3100_firmware | affected | qualcomm | — | — |
| qfe3340_firmware | affected | qualcomm | — | — |
| qfe4301_firmware | affected | qualcomm | — | — |
| qfe4302_firmware | affected | qualcomm | — | — |
| qfe4303_firmware | affected | qualcomm | — | — |
| qfe4305_firmware | affected | qualcomm | — | — |
| qfe4308_firmware | affected | qualcomm | — | — |
| qfe4309_firmware | affected | qualcomm | — | — |
| qfe4320_firmware | affected | qualcomm | — | — |
| qfe4373fc_firmware | affected | qualcomm | — | — |
| qfs2530_firmware | affected | qualcomm | — | — |
| qfs2580_firmware | affected | qualcomm | — | — |
| qfs2608_firmware | affected | qualcomm | — | — |
| qfs2630_firmware | affected | qualcomm | — | — |
| qln1020_firmware | affected | qualcomm | — | — |
| qln1030_firmware | affected | qualcomm | — | — |
| qln4640_firmware | affected | qualcomm | — | — |
| qln4642_firmware | affected | qualcomm | — | — |
| qln4650_firmware | affected | qualcomm | — | — |
| qln5020_firmware | affected | qualcomm | — | — |
| qln5030_firmware | affected | qualcomm | — | — |
| qln5040_firmware | affected | qualcomm | — | — |
| qpa2625_firmware | affected | qualcomm | — | — |
| qpa4340_firmware | affected | qualcomm | — | — |
| qpa4360_firmware | affected | qualcomm | — | — |
| qpa4361_firmware | affected | qualcomm | — | — |
| qpa5373_firmware | affected | qualcomm | — | — |
| qpa5460_firmware | affected | qualcomm | — | — |
| qpa5461_firmware | affected | qualcomm | — | — |
| qpa5580_firmware | affected | qualcomm | — | — |
| qpa5581_firmware | affected | qualcomm | — | — |
| qpa6560_firmware | affected | qualcomm | — | — |
| qpa8673_firmware | affected | qualcomm | — | — |
| qpa8675_firmware | affected | qualcomm | — | — |
| qpa8686_firmware | affected | qualcomm | — | — |
| qpa8801_firmware | affected | qualcomm | — | — |
| qpa8802_firmware | affected | qualcomm | — | — |
| qpa8803_firmware | affected | qualcomm | — | — |
| qpa8821_firmware | affected | qualcomm | — | — |
| qpa8842_firmware | affected | qualcomm | — | — |
| qpm2630_firmware | affected | qualcomm | — | — |
| qpm4621_firmware | affected | qualcomm | — | — |
| qpm4630_firmware | affected | qualcomm | — | — |
| qpm4640_firmware | affected | qualcomm | — | — |
| qpm4641_firmware | affected | qualcomm | — | — |
| qpm4650_firmware | affected | qualcomm | — | — |
| qpm5541_firmware | affected | qualcomm | — | — |
| qpm5577_firmware | affected | qualcomm | — | — |
| qpm5579_firmware | affected | qualcomm | — | — |
| qpm5620_firmware | affected | qualcomm | — | — |
| qpm5621_firmware | affected | qualcomm | — | — |
| qpm5641_firmware | affected | qualcomm | — | — |
| qpm5657_firmware | affected | qualcomm | — | — |
| qpm5658_firmware | affected | qualcomm | — | — |
| qpm5670_firmware | affected | qualcomm | — | — |
| qpm5677_firmware | affected | qualcomm | — | — |
| qpm5679_firmware | affected | qualcomm | — | — |
| qpm5870_firmware | affected | qualcomm | — | — |
| qpm5875_firmware | affected | qualcomm | — | — |
| qpm6325_firmware | affected | qualcomm | — | — |
| qpm6375_firmware | affected | qualcomm | — | — |
| qpm6582_firmware | affected | qualcomm | — | — |
| qpm6585_firmware | affected | qualcomm | — | — |
| qpm6621_firmware | affected | qualcomm | — | — |
| qpm6670_firmware | affected | qualcomm | — | — |
| qpm8820_firmware | affected | qualcomm | — | — |
| qpm8830_firmware | affected | qualcomm | — | — |
| qpm8870_firmware | affected | qualcomm | — | — |
| qpm8895_firmware | affected | qualcomm | — | — |
| qsm7250_firmware | affected | qualcomm | — | — |
| qsm8250_firmware | affected | qualcomm | — | — |
| qsw6310_firmware | affected | qualcomm | — | — |
| qsw8573_firmware | affected | qualcomm | — | — |
| qsw8574_firmware | affected | qualcomm | — | — |
| qtc410s_firmware | affected | qualcomm | — | — |
| qtc800h_firmware | affected | qualcomm | — | — |
| qtc800s_firmware | affected | qualcomm | — | — |
| qtc800t_firmware | affected | qualcomm | — | — |
| qtc801s_firmware | affected | qualcomm | — | — |
| qtm525_firmware | affected | qualcomm | — | — |
| qtm527_firmware | affected | qualcomm | — | — |
| qualcomm215_firmware | affected | qualcomm | — | — |
| rgr7640au_firmware | affected | qualcomm | — | — |
| rsw8577_firmware | affected | qualcomm | — | — |
| sa2150p_firmware | affected | qualcomm | — | — |
| sa515m_firmware | affected | qualcomm | — | — |
| sa6145p_firmware | affected | qualcomm | — | — |
| sa6150p_firmware | affected | qualcomm | — | — |
| sa6155_firmware | affected | qualcomm | — | — |
| sa6155p_firmware | affected | qualcomm | — | — |
| sa8150p_firmware | affected | qualcomm | — | — |
| sa8155_firmware | affected | qualcomm | — | — |
| sa8155p_firmware | affected | qualcomm | — | — |
| sa8195p_firmware | affected | qualcomm | — | — |
| sd205_firmware | affected | qualcomm | — | — |
| sd210_firmware | affected | qualcomm | — | — |
| sd429_firmware | affected | qualcomm | — | — |
| sd439_firmware | affected | qualcomm | — | — |
| sd450_firmware | affected | qualcomm | — | — |
| sd455_firmware | affected | qualcomm | — | — |
| sd460_firmware | affected | qualcomm | — | — |
| sd480_firmware | affected | qualcomm | — | — |
| sd632_firmware | affected | qualcomm | — | — |
| sd636_firmware | affected | qualcomm | — | — |
| sd660_firmware | affected | qualcomm | — | — |
| sd662_firmware | affected | qualcomm | — | — |
| sd665_firmware | affected | qualcomm | — | — |
| sd670_firmware | affected | qualcomm | — | — |
| sd675_firmware | affected | qualcomm | — | — |
| sd678_firmware | affected | qualcomm | — | — |
| sd6905g_firmware | affected | qualcomm | — | — |
| sd710_firmware | affected | qualcomm | — | — |
| sd720g_firmware | affected | qualcomm | — | — |
| sd730_firmware | affected | qualcomm | — | — |
| sd750g_firmware | affected | qualcomm | — | — |
| sd765_firmware | affected | qualcomm | — | — |
| sd765g_firmware | affected | qualcomm | — | — |
| sd768g_firmware | affected | qualcomm | — | — |
| sd835_firmware | affected | qualcomm | — | — |
| sd845_firmware | affected | qualcomm | — | — |
| sd855_firmware | affected | qualcomm | — | — |
| sd8655g_firmware | affected | qualcomm | — | — |
| sd870_firmware | affected | qualcomm | — | — |
| sd8885g_firmware | affected | qualcomm | — | — |
| sd888_firmware | affected | qualcomm | — | — |
| sd8c_firmware | affected | qualcomm | — | — |
| sd8cx_firmware | affected | qualcomm | — | — |
| sda429w_firmware | affected | qualcomm | — | — |
| sdm429w_firmware | affected | qualcomm | — | — |
| sdm630_firmware | affected | qualcomm | — | — |
| sdm830_firmware | affected | qualcomm | — | — |
| sdr051_firmware | affected | qualcomm | — | — |
| sdr052_firmware | affected | qualcomm | — | — |
| sdr425_firmware | affected | qualcomm | — | — |
| sdr660_firmware | affected | qualcomm | — | — |
| sdr660g_firmware | affected | qualcomm | — | — |
| sdr675_firmware | affected | qualcomm | — | — |
| sdr735_firmware | affected | qualcomm | — | — |
| sdr735g_firmware | affected | qualcomm | — | — |
| sdr8150_firmware | affected | qualcomm | — | — |
| sdr8250_firmware | affected | qualcomm | — | — |
| sdr845_firmware | affected | qualcomm | — | — |
| sdr865_firmware | affected | qualcomm | — | — |
| sdw2500_firmware | affected | qualcomm | — | — |
| sdw3100_firmware | affected | qualcomm | — | — |
| sdx20_firmware | affected | qualcomm | — | — |
| sdx20m_firmware | affected | qualcomm | — | — |
| sdx24_firmware | affected | qualcomm | — | — |
| sdx50m_firmware | affected | qualcomm | — | — |
| sdx55_firmware | affected | qualcomm | — | — |
| sdx55m_firmware | affected | qualcomm | — | — |
| sdxr1_firmware | affected | qualcomm | — | — |
| sdxr2_5g_firmware | affected | qualcomm | — | — |
| sm4125_firmware | affected | qualcomm | — | — |
| sm6250_firmware | affected | qualcomm | — | — |
| sm6250p_firmware | affected | qualcomm | — | — |
| sm7250p_firmware | affected | qualcomm | — | — |
| smb1350_firmware | affected | qualcomm | — | — |
| smb1351_firmware | affected | qualcomm | — | — |
| smb1354_firmware | affected | qualcomm | — | — |
| smb1355_firmware | affected | qualcomm | — | — |
| smb1357_firmware | affected | qualcomm | — | — |
| smb1358_firmware | affected | qualcomm | — | — |
| smb1360_firmware | affected | qualcomm | — | — |
| smb1380_firmware | affected | qualcomm | — | — |
| smb1381_firmware | affected | qualcomm | — | — |
| smb1390_firmware | affected | qualcomm | — | — |
| smb1395_firmware | affected | qualcomm | — | — |
| smb1396_firmware | affected | qualcomm | — | — |
| smb1398_firmware | affected | qualcomm | — | — |
| smb231_firmware | affected | qualcomm | — | — |
| smb2351_firmware | affected | qualcomm | — | — |
| smb358s_firmware | affected | qualcomm | — | — |
| smr525_firmware | affected | qualcomm | — | — |
| smr526_firmware | affected | qualcomm | — | — |
| smr545_firmware | affected | qualcomm | — | — |
| smr546_firmware | affected | qualcomm | — | — |
| wcd9326_firmware | affected | qualcomm | — | — |
| wcd9330_firmware | affected | qualcomm | — | — |
| wcd9335_firmware | affected | qualcomm | — | — |
| wcd9340_firmware | affected | qualcomm | — | — |
| wcd9341_firmware | affected | qualcomm | — | — |
| wcd9360_firmware | affected | qualcomm | — | — |
| wcd9370_firmware | affected | qualcomm | — | — |
| wcd9371_firmware | affected | qualcomm | — | — |
| wcd9375_firmware | affected | qualcomm | — | — |
| wcd9380_firmware | affected | qualcomm | — | — |
| wcd9385_firmware | affected | qualcomm | — | — |
| wcn3610_firmware | affected | qualcomm | — | — |
| wcn3615_firmware | affected | qualcomm | — | — |
| wcn3620_firmware | affected | qualcomm | — | — |
| wcn3660b_firmware | affected | qualcomm | — | — |
| wcn3660_firmware | affected | qualcomm | — | — |
| wcn3680b_firmware | affected | qualcomm | — | — |
| wcn3680_firmware | affected | qualcomm | — | — |
| wcn3910_firmware | affected | qualcomm | — | — |
| wcn3950_firmware | affected | qualcomm | — | — |
| wcn3980_firmware | affected | qualcomm | — | — |
| wcn3988_firmware | affected | qualcomm | — | — |
| wcn3990_firmware | affected | qualcomm | — | — |
| wcn3991_firmware | affected | qualcomm | — | — |
| wcn3998_firmware | affected | qualcomm | — | — |
| wcn3999_firmware | affected | qualcomm | — | — |
| wcn6850_firmware | affected | qualcomm | — | — |
| wcn6851_firmware | affected | qualcomm | — | — |
| wcn6855_firmware | affected | qualcomm | — | — |
| wcn6856_firmware | affected | qualcomm | — | — |
| wgr7640_firmware | affected | qualcomm | — | — |
| wsa8810_firmware | affected | qualcomm | — | — |
| wsa8815_firmware | affected | qualcomm | — | — |
| wsa8830_firmware | affected | qualcomm | — | — |
| wsa8835_firmware | affected | qualcomm | — | — |
| wtr2955_firmware | affected | qualcomm | — | — |
| wtr2965_firmware | affected | qualcomm | — | — |
| wtr3925_firmware | affected | qualcomm | — | — |
| wtr4905_firmware | affected | qualcomm | — | — |
| wtr5975_firmware | affected | qualcomm | — | — |
| wtr6955_firmware | affected | qualcomm | — | — |
CVEs:CVE-2021-1905
ASB-A-178809945
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
CVEs:CVE-2021-1906
Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Vo...
CVEs:CVE-2021-1906
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| apq8009_firmware | affected | qualcomm | — | — |
| apq8009w_firmware | affected | qualcomm | — | — |
| apq8017_firmware | affected | qualcomm | — | — |
| apq8053_firmware | affected | qualcomm | — | — |
| apq8064au_firmware | affected | qualcomm | — | — |
| apq8096au_firmware | affected | qualcomm | — | — |
| aqt1000_firmware | affected | qualcomm | — | — |
| ar8031_firmware | affected | qualcomm | — | — |
| ar8035_firmware | affected | qualcomm | — | — |
| ar8151_firmware | affected | qualcomm | — | — |
| csra6620_firmware | affected | qualcomm | — | — |
| csra6640_firmware | affected | qualcomm | — | — |
| csrb31024_firmware | affected | qualcomm | — | — |
| fsm10055_firmware | affected | qualcomm | — | — |
| fsm10056_firmware | affected | qualcomm | — | — |
| mdm9150_firmware | affected | qualcomm | — | — |
| mdm9206_firmware | affected | qualcomm | — | — |
| mdm9250_firmware | affected | qualcomm | — | — |
| mdm9607_firmware | affected | qualcomm | — | — |
| mdm9626_firmware | affected | qualcomm | — | — |
| mdm9628_firmware | affected | qualcomm | — | — |
| mdm9650_firmware | affected | qualcomm | — | — |
| msm8909w_firmware | affected | qualcomm | — | — |
| msm8917_firmware | affected | qualcomm | — | — |
| msm8953_firmware | affected | qualcomm | — | — |
| msm8996au_firmware | affected | qualcomm | — | — |
| pm215_firmware | affected | qualcomm | — | — |
| pm3003a_firmware | affected | qualcomm | — | — |
| pm4125_firmware | affected | qualcomm | — | — |
| pm4250_firmware | affected | qualcomm | — | — |
| pm439_firmware | affected | qualcomm | — | — |
| pm456_firmware | affected | qualcomm | — | — |
| pm6125_firmware | affected | qualcomm | — | — |
| pm6150a_firmware | affected | qualcomm | — | — |
| pm6150_firmware | affected | qualcomm | — | — |
| pm6150l_firmware | affected | qualcomm | — | — |
| pm6250_firmware | affected | qualcomm | — | — |
| pm6350_firmware | affected | qualcomm | — | — |
| pm640a_firmware | affected | qualcomm | — | — |
| pm640l_firmware | affected | qualcomm | — | — |
| pm640p_firmware | affected | qualcomm | — | — |
| pm660a_firmware | affected | qualcomm | — | — |
| pm660_firmware | affected | qualcomm | — | — |
| pm660l_firmware | affected | qualcomm | — | — |
| pm670a_firmware | affected | qualcomm | — | — |
| pm670_firmware | affected | qualcomm | — | — |
| pm670l_firmware | affected | qualcomm | — | — |
| pm7150a_firmware | affected | qualcomm | — | — |
| pm7150l_firmware | affected | qualcomm | — | — |
| pm7250b_firmware | affected | qualcomm | — | — |
| pm7250_firmware | affected | qualcomm | — | — |
| pm7350c_firmware | affected | qualcomm | — | — |
| pm8004_firmware | affected | qualcomm | — | — |
| pm8005_firmware | affected | qualcomm | — | — |
| pm8008_firmware | affected | qualcomm | — | — |
| pm8009_firmware | affected | qualcomm | — | — |
| pm8150a_firmware | affected | qualcomm | — | — |
| pm8150b_firmware | affected | qualcomm | — | — |
| pm8150c_firmware | affected | qualcomm | — | — |
| pm8150_firmware | affected | qualcomm | — | — |
| pm8150l_firmware | affected | qualcomm | — | — |
| pm8250_firmware | affected | qualcomm | — | — |
| pm8350b_firmware | affected | qualcomm | — | — |
| pm8350bh_firmware | affected | qualcomm | — | — |
| pm8350bhs_firmware | affected | qualcomm | — | — |
| pm8350c_firmware | affected | qualcomm | — | — |
| pm8350_firmware | affected | qualcomm | — | — |
| pm855a_firmware | affected | qualcomm | — | — |
| pm855b_firmware | affected | qualcomm | — | — |
| pm855_firmware | affected | qualcomm | — | — |
| pm855l_firmware | affected | qualcomm | — | — |
| pm855p_firmware | affected | qualcomm | — | — |
| pm8909_firmware | affected | qualcomm | — | — |
| pm8916_firmware | affected | qualcomm | — | — |
| pm8937_firmware | affected | qualcomm | — | — |
| pm8953_firmware | affected | qualcomm | — | — |
| pm8998_firmware | affected | qualcomm | — | — |
| pmc1000h_firmware | affected | qualcomm | — | — |
| pmd9607_firmware | affected | qualcomm | — | — |
| pmd9655au_firmware | affected | qualcomm | — | — |
| pmd9655_firmware | affected | qualcomm | — | — |
| pme605_firmware | affected | qualcomm | — | — |
| pmi632_firmware | affected | qualcomm | — | — |
| pmi8937_firmware | affected | qualcomm | — | — |
| pmi8952_firmware | affected | qualcomm | — | — |
| pmi8998_firmware | affected | qualcomm | — | — |
| pmk7350_firmware | affected | qualcomm | — | — |
| pmk8002_firmware | affected | qualcomm | — | — |
| pmk8003_firmware | affected | qualcomm | — | — |
| pmk8350_firmware | affected | qualcomm | — | — |
| pmm6155au_firmware | affected | qualcomm | — | — |
| pmm8155au_firmware | affected | qualcomm | — | — |
| pmm8195au_firmware | affected | qualcomm | — | — |
| pmm855au_firmware | affected | qualcomm | — | — |
| pmm8996au_firmware | affected | qualcomm | — | — |
| pmr525_firmware | affected | qualcomm | — | — |
| pmr735a_firmware | affected | qualcomm | — | — |
| pmr735b_firmware | affected | qualcomm | — | — |
| pmx20_firmware | affected | qualcomm | — | — |
| pmx24_firmware | affected | qualcomm | — | — |
| pmx50_firmware | affected | qualcomm | — | — |
| pmx55_firmware | affected | qualcomm | — | — |
| qat3514_firmware | affected | qualcomm | — | — |
| qat3516_firmware | affected | qualcomm | — | — |
| qat3518_firmware | affected | qualcomm | — | — |
| qat3519_firmware | affected | qualcomm | — | — |
| qat3522_firmware | affected | qualcomm | — | — |
| qat3550_firmware | affected | qualcomm | — | — |
| qat3555_firmware | affected | qualcomm | — | — |
| qat5515_firmware | affected | qualcomm | — | — |
| qat5516_firmware | affected | qualcomm | — | — |
| qat5522_firmware | affected | qualcomm | — | — |
| qat5533_firmware | affected | qualcomm | — | — |
| qat5568_firmware | affected | qualcomm | — | — |
| qbt1000_firmware | affected | qualcomm | — | — |
| qbt1500_firmware | affected | qualcomm | — | — |
| qbt2000_firmware | affected | qualcomm | — | — |
| qca6174a_firmware | affected | qualcomm | — | — |
| qca6310_firmware | affected | qualcomm | — | — |
| qca6320_firmware | affected | qualcomm | — | — |
| qca6335_firmware | affected | qualcomm | — | — |
| qca6390_firmware | affected | qualcomm | — | — |
| qca6391_firmware | affected | qualcomm | — | — |
| qca6420_firmware | affected | qualcomm | — | — |
| qca6426_firmware | affected | qualcomm | — | — |
| qca6430_firmware | affected | qualcomm | — | — |
| qca6436_firmware | affected | qualcomm | — | — |
| qca6564a_firmware | affected | qualcomm | — | — |
| qca6564au_firmware | affected | qualcomm | — | — |
| qca6564_firmware | affected | qualcomm | — | — |
| qca6574a_firmware | affected | qualcomm | — | — |
| qca6574au_firmware | affected | qualcomm | — | — |
| qca6574_firmware | affected | qualcomm | — | — |
| qca6584au_firmware | affected | qualcomm | — | — |
| qca6595au_firmware | affected | qualcomm | — | — |
| qca6696_firmware | affected | qualcomm | — | — |
| qca8337_firmware | affected | qualcomm | — | — |
| qca9367_firmware | affected | qualcomm | — | — |
| qca9377_firmware | affected | qualcomm | — | — |
| qcm2290_firmware | affected | qualcomm | — | — |
| qcm4290_firmware | affected | qualcomm | — | — |
| qcm6125_firmware | affected | qualcomm | — | — |
| qcs2290_firmware | affected | qualcomm | — | — |
| qcs405_firmware | affected | qualcomm | — | — |
| qcs410_firmware | affected | qualcomm | — | — |
| qcs4290_firmware | affected | qualcomm | — | — |
| qcs603_firmware | affected | qualcomm | — | — |
| qcs605_firmware | affected | qualcomm | — | — |
| qcs610_firmware | affected | qualcomm | — | — |
| qcs6125_firmware | affected | qualcomm | — | — |
| qdm2301_firmware | affected | qualcomm | — | — |
| qdm2302_firmware | affected | qualcomm | — | — |
| qdm2305_firmware | affected | qualcomm | — | — |
| qdm2307_firmware | affected | qualcomm | — | — |
| qdm2308_firmware | affected | qualcomm | — | — |
| qdm2310_firmware | affected | qualcomm | — | — |
| qdm3301_firmware | affected | qualcomm | — | — |
| qdm3302_firmware | affected | qualcomm | — | — |
| qdm4643_firmware | affected | qualcomm | — | — |
| qdm4650_firmware | affected | qualcomm | — | — |
| qdm5579_firmware | affected | qualcomm | — | — |
| qdm5620_firmware | affected | qualcomm | — | — |
| qdm5621_firmware | affected | qualcomm | — | — |
| qdm5650_firmware | affected | qualcomm | — | — |
| qdm5652_firmware | affected | qualcomm | — | — |
| qdm5670_firmware | affected | qualcomm | — | — |
| qdm5671_firmware | affected | qualcomm | — | — |
| qdm5677_firmware | affected | qualcomm | — | — |
| qdm5679_firmware | affected | qualcomm | — | — |
| qet4100_firmware | affected | qualcomm | — | — |
| qet4101_firmware | affected | qualcomm | — | — |
| qet5100_firmware | affected | qualcomm | — | — |
| qet5100m_firmware | affected | qualcomm | — | — |
| qet6100_firmware | affected | qualcomm | — | — |
| qet6105_firmware | affected | qualcomm | — | — |
| qet6110_firmware | affected | qualcomm | — | — |
| qfe2101_firmware | affected | qualcomm | — | — |
| qfe2520_firmware | affected | qualcomm | — | — |
| qfe2550_firmware | affected | qualcomm | — | — |
| qfe3340_firmware | affected | qualcomm | — | — |
| qfe4301_firmware | affected | qualcomm | — | — |
| qfe4302_firmware | affected | qualcomm | — | — |
| qfe4303_firmware | affected | qualcomm | — | — |
| qfe4305_firmware | affected | qualcomm | — | — |
| qfe4308_firmware | affected | qualcomm | — | — |
| qfe4309_firmware | affected | qualcomm | — | — |
| qfe4320_firmware | affected | qualcomm | — | — |
| qfe4373fc_firmware | affected | qualcomm | — | — |
| qfs2530_firmware | affected | qualcomm | — | — |
| qfs2580_firmware | affected | qualcomm | — | — |
| qfs2608_firmware | affected | qualcomm | — | — |
| qfs2630_firmware | affected | qualcomm | — | — |
| qln1020_firmware | affected | qualcomm | — | — |
| qln1021aq_firmware | affected | qualcomm | — | — |
| qln1030_firmware | affected | qualcomm | — | — |
| qln1031_firmware | affected | qualcomm | — | — |
| qln1036aq_firmware | affected | qualcomm | — | — |
| qln4640_firmware | affected | qualcomm | — | — |
| qln4642_firmware | affected | qualcomm | — | — |
| qln4650_firmware | affected | qualcomm | — | — |
| qln5020_firmware | affected | qualcomm | — | — |
| qln5030_firmware | affected | qualcomm | — | — |
| qln5040_firmware | affected | qualcomm | — | — |
| qpa2625_firmware | affected | qualcomm | — | — |
| qpa4340_firmware | affected | qualcomm | — | — |
| qpa4360_firmware | affected | qualcomm | — | — |
| qpa4361_firmware | affected | qualcomm | — | — |
| qpa5373_firmware | affected | qualcomm | — | — |
| qpa5460_firmware | affected | qualcomm | — | — |
| qpa5461_firmware | affected | qualcomm | — | — |
| qpa5580_firmware | affected | qualcomm | — | — |
| qpa5581_firmware | affected | qualcomm | — | — |
| qpa6560_firmware | affected | qualcomm | — | — |
| qpa8673_firmware | affected | qualcomm | — | — |
| qpa8675_firmware | affected | qualcomm | — | — |
| qpa8686_firmware | affected | qualcomm | — | — |
| qpa8801_firmware | affected | qualcomm | — | — |
| qpa8802_firmware | affected | qualcomm | — | — |
| qpa8803_firmware | affected | qualcomm | — | — |
| qpa8821_firmware | affected | qualcomm | — | — |
| qpa8842_firmware | affected | qualcomm | — | — |
| qpm2630_firmware | affected | qualcomm | — | — |
| qpm4621_firmware | affected | qualcomm | — | — |
| qpm4630_firmware | affected | qualcomm | — | — |
| qpm4640_firmware | affected | qualcomm | — | — |
| qpm4641_firmware | affected | qualcomm | — | — |
| qpm4650_firmware | affected | qualcomm | — | — |
| qpm5541_firmware | affected | qualcomm | — | — |
| qpm5577_firmware | affected | qualcomm | — | — |
| qpm5579_firmware | affected | qualcomm | — | — |
| qpm5620_firmware | affected | qualcomm | — | — |
| qpm5621_firmware | affected | qualcomm | — | — |
| qpm5641_firmware | affected | qualcomm | — | — |
| qpm5657_firmware | affected | qualcomm | — | — |
| qpm5658_firmware | affected | qualcomm | — | — |
| qpm5670_firmware | affected | qualcomm | — | — |
| qpm5677_firmware | affected | qualcomm | — | — |
| qpm5679_firmware | affected | qualcomm | — | — |
| qpm5870_firmware | affected | qualcomm | — | — |
| qpm5875_firmware | affected | qualcomm | — | — |
| qpm6325_firmware | affected | qualcomm | — | — |
| qpm6375_firmware | affected | qualcomm | — | — |
| qpm6582_firmware | affected | qualcomm | — | — |
| qpm6585_firmware | affected | qualcomm | — | — |
| qpm6621_firmware | affected | qualcomm | — | — |
| qpm6670_firmware | affected | qualcomm | — | — |
| qpm8820_firmware | affected | qualcomm | — | — |
| qpm8830_firmware | affected | qualcomm | — | — |
| qpm8870_firmware | affected | qualcomm | — | — |
| qpm8895_firmware | affected | qualcomm | — | — |
| qsm7250_firmware | affected | qualcomm | — | — |
| qsw6310_firmware | affected | qualcomm | — | — |
| qsw8573_firmware | affected | qualcomm | — | — |
| qsw8574_firmware | affected | qualcomm | — | — |
| qtc410s_firmware | affected | qualcomm | — | — |
| qtc800h_firmware | affected | qualcomm | — | — |
| qtc800s_firmware | affected | qualcomm | — | — |
| qtc800t_firmware | affected | qualcomm | — | — |
| qtc801s_firmware | affected | qualcomm | — | — |
| qtm525_firmware | affected | qualcomm | — | — |
| qtm527_firmware | affected | qualcomm | — | — |
| qualcomm215_firmware | affected | qualcomm | — | — |
| rgr7640au_firmware | affected | qualcomm | — | — |
| rsw8577_firmware | affected | qualcomm | — | — |
| sa2150p_firmware | affected | qualcomm | — | — |
| sa415m_firmware | affected | qualcomm | — | — |
| sa515m_firmware | affected | qualcomm | — | — |
| sa6145p_firmware | affected | qualcomm | — | — |
| sa6150p_firmware | affected | qualcomm | — | — |
| sa6155_firmware | affected | qualcomm | — | — |
| sa6155p_firmware | affected | qualcomm | — | — |
| sa8150p_firmware | affected | qualcomm | — | — |
| sa8155_firmware | affected | qualcomm | — | — |
| sa8155p_firmware | affected | qualcomm | — | — |
| sa8195p_firmware | affected | qualcomm | — | — |
| sd205_firmware | affected | qualcomm | — | — |
| sd210_firmware | affected | qualcomm | — | — |
| sd429_firmware | affected | qualcomm | — | — |
| sd439_firmware | affected | qualcomm | — | — |
| sd450_firmware | affected | qualcomm | — | — |
| sd455_firmware | affected | qualcomm | — | — |
| sd460_firmware | affected | qualcomm | — | — |
| sd480_firmware | affected | qualcomm | — | — |
| sd632_firmware | affected | qualcomm | — | — |
| sd636_firmware | affected | qualcomm | — | — |
| sd660_firmware | affected | qualcomm | — | — |
| sd662_firmware | affected | qualcomm | — | — |
| sd665_firmware | affected | qualcomm | — | — |
| sd670_firmware | affected | qualcomm | — | — |
| sd675_firmware | affected | qualcomm | — | — |
| sd678_firmware | affected | qualcomm | — | — |
| sd6905g_firmware | affected | qualcomm | — | — |
| sd710_firmware | affected | qualcomm | — | — |
| sd720g_firmware | affected | qualcomm | — | — |
| sd730_firmware | affected | qualcomm | — | — |
| sd750g_firmware | affected | qualcomm | — | — |
| sd765_firmware | affected | qualcomm | — | — |
| sd765g_firmware | affected | qualcomm | — | — |
| sd768g_firmware | affected | qualcomm | — | — |
| sd835_firmware | affected | qualcomm | — | — |
| sd845_firmware | affected | qualcomm | — | — |
| sd855_firmware | affected | qualcomm | — | — |
| sd8655g_firmware | affected | qualcomm | — | — |
| sd870_firmware | affected | qualcomm | — | — |
| sd8885g_firmware | affected | qualcomm | — | — |
| sd888_firmware | affected | qualcomm | — | — |
| sd8c_firmware | affected | qualcomm | — | — |
| sd8cx_firmware | affected | qualcomm | — | — |
| sda429w_firmware | affected | qualcomm | — | — |
| sdm429w_firmware | affected | qualcomm | — | — |
| sdm630_firmware | affected | qualcomm | — | — |
| sdm830_firmware | affected | qualcomm | — | — |
| sdr051_firmware | affected | qualcomm | — | — |
| sdr052_firmware | affected | qualcomm | — | — |
| sdr425_firmware | affected | qualcomm | — | — |
| sdr660_firmware | affected | qualcomm | — | — |
| sdr660g_firmware | affected | qualcomm | — | — |
| sdr675_firmware | affected | qualcomm | — | — |
| sdr735_firmware | affected | qualcomm | — | — |
| sdr735g_firmware | affected | qualcomm | — | — |
| sdr8150_firmware | affected | qualcomm | — | — |
| sdr8250_firmware | affected | qualcomm | — | — |
| sdr865_firmware | affected | qualcomm | — | — |
| sdw3100_firmware | affected | qualcomm | — | — |
| sdx20_firmware | affected | qualcomm | — | — |
| sdx20m_firmware | affected | qualcomm | — | — |
| sdx24_firmware | affected | qualcomm | — | — |
| sdx50m_firmware | affected | qualcomm | — | — |
| sdx55_firmware | affected | qualcomm | — | — |
| sdx55m_firmware | affected | qualcomm | — | — |
| sdxr1_firmware | affected | qualcomm | — | — |
| sdxr25g_firmware | affected | qualcomm | — | — |
| sm4125_firmware | affected | qualcomm | — | — |
| sm6250_firmware | affected | qualcomm | — | — |
| sm6250p_firmware | affected | qualcomm | — | — |
| sm7250p_firmware | affected | qualcomm | — | — |
| sm7350_firmware | affected | qualcomm | — | — |
| smb1350_firmware | affected | qualcomm | — | — |
| smb1351_firmware | affected | qualcomm | — | — |
| smb1354_firmware | affected | qualcomm | — | — |
| smb1355_firmware | affected | qualcomm | — | — |
| smb1357_firmware | affected | qualcomm | — | — |
| smb1358_firmware | affected | qualcomm | — | — |
| smb1360_firmware | affected | qualcomm | — | — |
| smb1380_firmware | affected | qualcomm | — | — |
| smb1381_firmware | affected | qualcomm | — | — |
| smb1390_firmware | affected | qualcomm | — | — |
| smb1394_firmware | affected | qualcomm | — | — |
| smb1395_firmware | affected | qualcomm | — | — |
| smb1396_firmware | affected | qualcomm | — | — |
| smb1398_firmware | affected | qualcomm | — | — |
| smb231_firmware | affected | qualcomm | — | — |
| smb2351_firmware | affected | qualcomm | — | — |
| smb358s_firmware | affected | qualcomm | — | — |
| smr525_firmware | affected | qualcomm | — | — |
| smr526_firmware | affected | qualcomm | — | — |
| smr545_firmware | affected | qualcomm | — | — |
| smr546_firmware | affected | qualcomm | — | — |
| wcd9326_firmware | affected | qualcomm | — | — |
| wcd9330_firmware | affected | qualcomm | — | — |
| wcd9335_firmware | affected | qualcomm | — | — |
| wcd9340_firmware | affected | qualcomm | — | — |
| wcd9341_firmware | affected | qualcomm | — | — |
| wcd9360_firmware | affected | qualcomm | — | — |
| wcd9370_firmware | affected | qualcomm | — | — |
| wcd9371_firmware | affected | qualcomm | — | — |
| wcd9375_firmware | affected | qualcomm | — | — |
| wcd9380_firmware | affected | qualcomm | — | — |
| wcd9385_firmware | affected | qualcomm | — | — |
| wcn3610_firmware | affected | qualcomm | — | — |
| wcn3615_firmware | affected | qualcomm | — | — |
| wcn3620_firmware | affected | qualcomm | — | — |
| wcn3660b_firmware | affected | qualcomm | — | — |
| wcn3660_firmware | affected | qualcomm | — | — |
| wcn3680b_firmware | affected | qualcomm | — | — |
| wcn3680_firmware | affected | qualcomm | — | — |
| wcn3910_firmware | affected | qualcomm | — | — |
| wcn3950_firmware | affected | qualcomm | — | — |
| wcn3980_firmware | affected | qualcomm | — | — |
| wcn3988_firmware | affected | qualcomm | — | — |
| wcn3990_firmware | affected | qualcomm | — | — |
| wcn3991_firmware | affected | qualcomm | — | — |
| wcn3998_firmware | affected | qualcomm | — | — |
| wcn3999_firmware | affected | qualcomm | — | — |
| wcn6740_firmware | affected | qualcomm | — | — |
| wcn6850_firmware | affected | qualcomm | — | — |
| wcn6851_firmware | affected | qualcomm | — | — |
| wcn6855_firmware | affected | qualcomm | — | — |
| wcn6856_firmware | affected | qualcomm | — | — |
| wgr7640_firmware | affected | qualcomm | — | — |
| wsa8810_firmware | affected | qualcomm | — | — |
| wsa8815_firmware | affected | qualcomm | — | — |
| wsa8830_firmware | affected | qualcomm | — | — |
| wsa8835_firmware | affected | qualcomm | — | — |
| wtr2955_firmware | affected | qualcomm | — | — |
| wtr2965_firmware | affected | qualcomm | — | — |
| wtr3925_firmware | affected | qualcomm | — | — |
| wtr4905_firmware | affected | qualcomm | — | — |
| wtr5975_firmware | affected | qualcomm | — | — |
| wtr6955_firmware | affected | qualcomm | — | — |
CVEs:CVE-2021-1906
ASB-A-178810049
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page.
CVEs:CVE-2021-30538
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30538
XML Entity Expansion and Improper Input Validation in Kubernetes API server
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubeflow-pipelines | affected | wolfi | kubeflow-pipelines | — |
| kubeflow-pipelines | affected | chainguard | kubeflow-pipelines | — |
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
| kubernetes-dns-node-cache-1.17 | affected | chainguard | kubernetes-dns-node-cache-1.17 | — |
XML Entity Expansion and Improper Input Validation in Kubernetes API server
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
Improper Verification of Cryptographic Signature in golang.org/x/crypto
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| x/crypto | affected | golang.org | golang.org/x/crypto | — |
Improper Verification of Cryptographic Signature in golang.org/x/crypto
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| dex-k8s-authenticator | affected | chainguard | dex-k8s-authenticator | — |
| k3d | affected | chainguard | k3d | — |
| k3d | affected | wolfi | k3d | — |
| x/crypto | affected | golang.org | golang.org/x/crypto | — |
ASB-A-175451802
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.3.7 security update on RHEL 8
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| eap7-artemis-wildfly-integration | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-artemis-wildfly-integration | — |
| eap7-bouncycastle | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-bouncycastle | — |
| eap7-bouncycastle-mail | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-bouncycastle-mail | — |
| eap7-bouncycastle-pkix | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-bouncycastle-pkix | — |
| eap7-bouncycastle-prov | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-bouncycastle-prov | — |
| eap7-hal-console | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-hal-console | — |
| eap7-infinispan | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-infinispan | — |
| eap7-infinispan-cachestore-jdbc | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-infinispan-cachestore-jdbc | — |
| eap7-infinispan-cachestore-remote | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-infinispan-cachestore-remote | — |
| eap7-infinispan-client-hotrod | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-infinispan-client-hotrod | — |
| eap7-infinispan-commons | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-infinispan-commons | — |
| eap7-infinispan-core | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-infinispan-core | — |
| eap7-infinispan-hibernate-cache-commons | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-infinispan-hibernate-cache-commons | — |
| eap7-infinispan-hibernate-cache-spi | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-infinispan-hibernate-cache-spi | — |
| eap7-infinispan-hibernate-cache-v53 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-infinispan-hibernate-cache-v53 | — |
| eap7-ironjacamar | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-ironjacamar | — |
| eap7-ironjacamar-common-api | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-ironjacamar-common-api | — |
| eap7-ironjacamar-common-impl | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-ironjacamar-common-impl | — |
| eap7-ironjacamar-common-spi | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-ironjacamar-common-spi | — |
| eap7-ironjacamar-core-api | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-ironjacamar-core-api | — |
| eap7-ironjacamar-core-impl | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-ironjacamar-core-impl | — |
| eap7-ironjacamar-deployers-common | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-ironjacamar-deployers-common | — |
| eap7-ironjacamar-jdbc | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-ironjacamar-jdbc | — |
| eap7-ironjacamar-validator | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-ironjacamar-validator | — |
| eap7-jboss-genericjms | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-jboss-genericjms | — |
| eap7-jboss-marshalling | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-jboss-marshalling | — |
| eap7-jboss-marshalling-river | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-jboss-marshalling-river | — |
| eap7-jboss-server-migration | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-jboss-server-migration | — |
| eap7-jboss-server-migration-cli | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-jboss-server-migration-cli | — |
| eap7-jboss-server-migration-core | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-jboss-server-migration-core | — |
| eap7-jboss-server-migration-eap6.4 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-jboss-server-migration-eap6.4 | — |
| eap7-jboss-server-migration-eap6.4-to-eap7.3 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-jboss-server-migration-eap6.4-to-eap7.3 | — |
| eap7-jboss-server-migration-eap7.0 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-jboss-server-migration-eap7.0 | — |
| eap7-jboss-server-migration-eap7.1 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-jboss-server-migration-eap7.1 | — |
| eap7-jboss-server-migration-eap7.2 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-jboss-server-migration-eap7.2 | — |
| eap7-jboss-server-migration-eap7.2-to-eap7.3 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-jboss-server-migration-eap7.2-to-eap7.3 | — |
| eap7-jboss-server-migration-eap7.3-server | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-jboss-server-migration-eap7.3-server | — |
| eap7-jboss-server-migration-wildfly10.0 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-jboss-server-migration-wildfly10.0 | — |
| eap7-jboss-server-migration-wildfly10.1 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-jboss-server-migration-wildfly10.1 | — |
| eap7-jboss-server-migration-wildfly11.0 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-jboss-server-migration-wildfly11.0 | — |
| eap7-jboss-server-migration-wildfly12.0 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-jboss-server-migration-wildfly12.0 | — |
| eap7-jboss-server-migration-wildfly13.0-server | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-jboss-server-migration-wildfly13.0-server | — |
| eap7-jboss-server-migration-wildfly14.0-server | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-jboss-server-migration-wildfly14.0-server | — |
| eap7-jboss-server-migration-wildfly15.0-server | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-jboss-server-migration-wildfly15.0-server | — |
| eap7-jboss-server-migration-wildfly16.0-server | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-jboss-server-migration-wildfly16.0-server | — |
| eap7-jboss-server-migration-wildfly17.0-server | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-jboss-server-migration-wildfly17.0-server | — |
| eap7-jboss-server-migration-wildfly18.0-server | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-jboss-server-migration-wildfly18.0-server | — |
| eap7-jboss-server-migration-wildfly8.2 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-jboss-server-migration-wildfly8.2 | — |
| eap7-jboss-server-migration-wildfly9.0 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-jboss-server-migration-wildfly9.0 | — |
| eap7-jboss-weld-3.1-api | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-jboss-weld-3.1-api | — |
| eap7-jboss-weld-3.1-api-weld-api | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-jboss-weld-3.1-api-weld-api | — |
| eap7-jboss-weld-3.1-api-weld-spi | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-jboss-weld-3.1-api-weld-spi | — |
| eap7-jgroups-kubernetes | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-jgroups-kubernetes | — |
| eap7-mod_cluster | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-mod_cluster | — |
| eap7-netty | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-netty | — |
| eap7-netty-all | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-netty-all | — |
| eap7-resteasy | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-resteasy | — |
| eap7-resteasy-atom-provider | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-resteasy-atom-provider | — |
| eap7-resteasy-cdi | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-resteasy-cdi | — |
| eap7-resteasy-client | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-resteasy-client | — |
| eap7-resteasy-client-microprofile | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-resteasy-client-microprofile | — |
| eap7-resteasy-crypto | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-resteasy-crypto | — |
| eap7-resteasy-jackson2-provider | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-resteasy-jackson2-provider | — |
| eap7-resteasy-jackson-provider | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-resteasy-jackson-provider | — |
| eap7-resteasy-jaxb-provider | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-resteasy-jaxb-provider | — |
| eap7-resteasy-jaxrs | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-resteasy-jaxrs | — |
| eap7-resteasy-jettison-provider | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-resteasy-jettison-provider | — |
| eap7-resteasy-jose-jwt | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-resteasy-jose-jwt | — |
| eap7-resteasy-jsapi | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-resteasy-jsapi | — |
| eap7-resteasy-json-binding-provider | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-resteasy-json-binding-provider | — |
| eap7-resteasy-json-p-provider | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-resteasy-json-p-provider | — |
| eap7-resteasy-multipart-provider | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-resteasy-multipart-provider | — |
| eap7-resteasy-rxjava2 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-resteasy-rxjava2 | — |
| eap7-resteasy-spring | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-resteasy-spring | — |
| eap7-resteasy-validator-provider-11 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-resteasy-validator-provider-11 | — |
| eap7-resteasy-yaml-provider | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-resteasy-yaml-provider | — |
| eap7-undertow | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-undertow | — |
| eap7-velocity | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-velocity | — |
| eap7-velocity-engine-core | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-velocity-engine-core | — |
| eap7-weld-core | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-weld-core | — |
| eap7-weld-core-impl | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-weld-core-impl | — |
| eap7-weld-core-jsf | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-weld-core-jsf | — |
| eap7-weld-ejb | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-weld-ejb | — |
| eap7-weld-jta | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-weld-jta | — |
| eap7-weld-probe-core | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-weld-probe-core | — |
| eap7-weld-web | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-weld-web | — |
| eap7-wildfly | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-wildfly | — |
| eap7-wildfly-elytron | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-wildfly-elytron | — |
| eap7-wildfly-elytron-tool | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-wildfly-elytron-tool | — |
| eap7-wildfly-http-client | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-wildfly-http-client | — |
| eap7-wildfly-http-client-common | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-wildfly-http-client-common | — |
| eap7-wildfly-http-ejb-client | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-wildfly-http-ejb-client | — |
| eap7-wildfly-http-naming-client | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-wildfly-http-naming-client | — |
| eap7-wildfly-http-transaction-client | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-wildfly-http-transaction-client | — |
| eap7-wildfly-javadocs | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-wildfly-javadocs | — |
| eap7-wildfly-modules | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-wildfly-modules | — |
| eap7-xalan-j2 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-xalan-j2 | — |
| eap7-yasson | affected | Red Hat:jboss_enterprise_application_platform:7.3::el8 | eap7-yasson | — |
Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.3.7 security update on RHEL 6
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| eap7-artemis-wildfly-integration | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-artemis-wildfly-integration | — |
| eap7-bouncycastle | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-bouncycastle | — |
| eap7-bouncycastle-mail | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-bouncycastle-mail | — |
| eap7-bouncycastle-pkix | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-bouncycastle-pkix | — |
| eap7-bouncycastle-prov | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-bouncycastle-prov | — |
| eap7-hal-console | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-hal-console | — |
| eap7-infinispan | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-infinispan | — |
| eap7-infinispan-cachestore-jdbc | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-infinispan-cachestore-jdbc | — |
| eap7-infinispan-cachestore-remote | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-infinispan-cachestore-remote | — |
| eap7-infinispan-client-hotrod | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-infinispan-client-hotrod | — |
| eap7-infinispan-commons | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-infinispan-commons | — |
| eap7-infinispan-core | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-infinispan-core | — |
| eap7-infinispan-hibernate-cache-commons | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-infinispan-hibernate-cache-commons | — |
| eap7-infinispan-hibernate-cache-spi | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-infinispan-hibernate-cache-spi | — |
| eap7-infinispan-hibernate-cache-v53 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-infinispan-hibernate-cache-v53 | — |
| eap7-ironjacamar | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-ironjacamar | — |
| eap7-ironjacamar-common-api | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-ironjacamar-common-api | — |
| eap7-ironjacamar-common-impl | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-ironjacamar-common-impl | — |
| eap7-ironjacamar-common-spi | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-ironjacamar-common-spi | — |
| eap7-ironjacamar-core-api | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-ironjacamar-core-api | — |
| eap7-ironjacamar-core-impl | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-ironjacamar-core-impl | — |
| eap7-ironjacamar-deployers-common | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-ironjacamar-deployers-common | — |
| eap7-ironjacamar-jdbc | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-ironjacamar-jdbc | — |
| eap7-ironjacamar-validator | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-ironjacamar-validator | — |
| eap7-jboss-genericjms | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-jboss-genericjms | — |
| eap7-jboss-marshalling | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-jboss-marshalling | — |
| eap7-jboss-marshalling-river | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-jboss-marshalling-river | — |
| eap7-jboss-server-migration | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-jboss-server-migration | — |
| eap7-jboss-server-migration-cli | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-jboss-server-migration-cli | — |
| eap7-jboss-server-migration-core | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-jboss-server-migration-core | — |
| eap7-jboss-server-migration-eap6.4 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-jboss-server-migration-eap6.4 | — |
| eap7-jboss-server-migration-eap6.4-to-eap7.3 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-jboss-server-migration-eap6.4-to-eap7.3 | — |
| eap7-jboss-server-migration-eap7.0 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-jboss-server-migration-eap7.0 | — |
| eap7-jboss-server-migration-eap7.1 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-jboss-server-migration-eap7.1 | — |
| eap7-jboss-server-migration-eap7.2 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-jboss-server-migration-eap7.2 | — |
| eap7-jboss-server-migration-eap7.2-to-eap7.3 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-jboss-server-migration-eap7.2-to-eap7.3 | — |
| eap7-jboss-server-migration-eap7.3-server | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-jboss-server-migration-eap7.3-server | — |
| eap7-jboss-server-migration-wildfly10.0 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-jboss-server-migration-wildfly10.0 | — |
| eap7-jboss-server-migration-wildfly10.1 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-jboss-server-migration-wildfly10.1 | — |
| eap7-jboss-server-migration-wildfly11.0 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-jboss-server-migration-wildfly11.0 | — |
| eap7-jboss-server-migration-wildfly12.0 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-jboss-server-migration-wildfly12.0 | — |
| eap7-jboss-server-migration-wildfly13.0-server | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-jboss-server-migration-wildfly13.0-server | — |
| eap7-jboss-server-migration-wildfly14.0-server | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-jboss-server-migration-wildfly14.0-server | — |
| eap7-jboss-server-migration-wildfly15.0-server | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-jboss-server-migration-wildfly15.0-server | — |
| eap7-jboss-server-migration-wildfly16.0-server | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-jboss-server-migration-wildfly16.0-server | — |
| eap7-jboss-server-migration-wildfly17.0-server | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-jboss-server-migration-wildfly17.0-server | — |
| eap7-jboss-server-migration-wildfly18.0-server | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-jboss-server-migration-wildfly18.0-server | — |
| eap7-jboss-server-migration-wildfly8.2 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-jboss-server-migration-wildfly8.2 | — |
| eap7-jboss-server-migration-wildfly9.0 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-jboss-server-migration-wildfly9.0 | — |
| eap7-jboss-weld-3.1-api | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-jboss-weld-3.1-api | — |
| eap7-jboss-weld-3.1-api-weld-api | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-jboss-weld-3.1-api-weld-api | — |
| eap7-jboss-weld-3.1-api-weld-spi | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-jboss-weld-3.1-api-weld-spi | — |
| eap7-jgroups-kubernetes | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-jgroups-kubernetes | — |
| eap7-mod_cluster | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-mod_cluster | — |
| eap7-netty | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-netty | — |
| eap7-netty-all | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-netty-all | — |
| eap7-resteasy | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-resteasy | — |
| eap7-resteasy-atom-provider | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-resteasy-atom-provider | — |
| eap7-resteasy-cdi | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-resteasy-cdi | — |
| eap7-resteasy-client | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-resteasy-client | — |
| eap7-resteasy-client-microprofile | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-resteasy-client-microprofile | — |
| eap7-resteasy-crypto | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-resteasy-crypto | — |
| eap7-resteasy-jackson2-provider | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-resteasy-jackson2-provider | — |
| eap7-resteasy-jackson-provider | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-resteasy-jackson-provider | — |
| eap7-resteasy-jaxb-provider | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-resteasy-jaxb-provider | — |
| eap7-resteasy-jaxrs | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-resteasy-jaxrs | — |
| eap7-resteasy-jettison-provider | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-resteasy-jettison-provider | — |
| eap7-resteasy-jose-jwt | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-resteasy-jose-jwt | — |
| eap7-resteasy-jsapi | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-resteasy-jsapi | — |
| eap7-resteasy-json-binding-provider | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-resteasy-json-binding-provider | — |
| eap7-resteasy-json-p-provider | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-resteasy-json-p-provider | — |
| eap7-resteasy-multipart-provider | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-resteasy-multipart-provider | — |
| eap7-resteasy-rxjava2 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-resteasy-rxjava2 | — |
| eap7-resteasy-spring | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-resteasy-spring | — |
| eap7-resteasy-validator-provider-11 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-resteasy-validator-provider-11 | — |
| eap7-resteasy-yaml-provider | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-resteasy-yaml-provider | — |
| eap7-undertow | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-undertow | — |
| eap7-velocity | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-velocity | — |
| eap7-velocity-engine-core | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-velocity-engine-core | — |
| eap7-weld-core | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-weld-core | — |
| eap7-weld-core-impl | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-weld-core-impl | — |
| eap7-weld-core-jsf | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-weld-core-jsf | — |
| eap7-weld-ejb | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-weld-ejb | — |
| eap7-weld-jta | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-weld-jta | — |
| eap7-weld-probe-core | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-weld-probe-core | — |
| eap7-weld-web | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-weld-web | — |
| eap7-wildfly | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-wildfly | — |
| eap7-wildfly-elytron | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-wildfly-elytron | — |
| eap7-wildfly-elytron-tool | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-wildfly-elytron-tool | — |
| eap7-wildfly-http-client | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-wildfly-http-client | — |
| eap7-wildfly-http-client-common | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-wildfly-http-client-common | — |
| eap7-wildfly-http-ejb-client | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-wildfly-http-ejb-client | — |
| eap7-wildfly-http-naming-client | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-wildfly-http-naming-client | — |
| eap7-wildfly-http-transaction-client | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-wildfly-http-transaction-client | — |
| eap7-wildfly-javadocs | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-wildfly-javadocs | — |
| eap7-wildfly-modules | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-wildfly-modules | — |
| eap7-xalan-j2 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-xalan-j2 | — |
| eap7-yasson | affected | Red Hat:jboss_enterprise_application_platform:7.3::el6 | eap7-yasson | — |
Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.3.7 security update on RHEL 7
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| eap7-artemis-wildfly-integration | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-artemis-wildfly-integration | — |
| eap7-bouncycastle | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-bouncycastle | — |
| eap7-bouncycastle-mail | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-bouncycastle-mail | — |
| eap7-bouncycastle-pkix | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-bouncycastle-pkix | — |
| eap7-bouncycastle-prov | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-bouncycastle-prov | — |
| eap7-hal-console | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-hal-console | — |
| eap7-infinispan | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-infinispan | — |
| eap7-infinispan-cachestore-jdbc | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-infinispan-cachestore-jdbc | — |
| eap7-infinispan-cachestore-remote | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-infinispan-cachestore-remote | — |
| eap7-infinispan-client-hotrod | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-infinispan-client-hotrod | — |
| eap7-infinispan-commons | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-infinispan-commons | — |
| eap7-infinispan-core | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-infinispan-core | — |
| eap7-infinispan-hibernate-cache-commons | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-infinispan-hibernate-cache-commons | — |
| eap7-infinispan-hibernate-cache-spi | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-infinispan-hibernate-cache-spi | — |
| eap7-infinispan-hibernate-cache-v53 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-infinispan-hibernate-cache-v53 | — |
| eap7-ironjacamar | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-ironjacamar | — |
| eap7-ironjacamar-common-api | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-ironjacamar-common-api | — |
| eap7-ironjacamar-common-impl | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-ironjacamar-common-impl | — |
| eap7-ironjacamar-common-spi | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-ironjacamar-common-spi | — |
| eap7-ironjacamar-core-api | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-ironjacamar-core-api | — |
| eap7-ironjacamar-core-impl | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-ironjacamar-core-impl | — |
| eap7-ironjacamar-deployers-common | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-ironjacamar-deployers-common | — |
| eap7-ironjacamar-jdbc | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-ironjacamar-jdbc | — |
| eap7-ironjacamar-validator | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-ironjacamar-validator | — |
| eap7-jboss-genericjms | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-jboss-genericjms | — |
| eap7-jboss-marshalling | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-jboss-marshalling | — |
| eap7-jboss-marshalling-river | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-jboss-marshalling-river | — |
| eap7-jboss-server-migration | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-jboss-server-migration | — |
| eap7-jboss-server-migration-cli | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-jboss-server-migration-cli | — |
| eap7-jboss-server-migration-core | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-jboss-server-migration-core | — |
| eap7-jboss-server-migration-eap6.4 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-jboss-server-migration-eap6.4 | — |
| eap7-jboss-server-migration-eap6.4-to-eap7.3 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-jboss-server-migration-eap6.4-to-eap7.3 | — |
| eap7-jboss-server-migration-eap7.0 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-jboss-server-migration-eap7.0 | — |
| eap7-jboss-server-migration-eap7.1 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-jboss-server-migration-eap7.1 | — |
| eap7-jboss-server-migration-eap7.2 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-jboss-server-migration-eap7.2 | — |
| eap7-jboss-server-migration-eap7.2-to-eap7.3 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-jboss-server-migration-eap7.2-to-eap7.3 | — |
| eap7-jboss-server-migration-eap7.3-server | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-jboss-server-migration-eap7.3-server | — |
| eap7-jboss-server-migration-wildfly10.0 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-jboss-server-migration-wildfly10.0 | — |
| eap7-jboss-server-migration-wildfly10.1 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-jboss-server-migration-wildfly10.1 | — |
| eap7-jboss-server-migration-wildfly11.0 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-jboss-server-migration-wildfly11.0 | — |
| eap7-jboss-server-migration-wildfly12.0 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-jboss-server-migration-wildfly12.0 | — |
| eap7-jboss-server-migration-wildfly13.0-server | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-jboss-server-migration-wildfly13.0-server | — |
| eap7-jboss-server-migration-wildfly14.0-server | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-jboss-server-migration-wildfly14.0-server | — |
| eap7-jboss-server-migration-wildfly15.0-server | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-jboss-server-migration-wildfly15.0-server | — |
| eap7-jboss-server-migration-wildfly16.0-server | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-jboss-server-migration-wildfly16.0-server | — |
| eap7-jboss-server-migration-wildfly17.0-server | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-jboss-server-migration-wildfly17.0-server | — |
| eap7-jboss-server-migration-wildfly18.0-server | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-jboss-server-migration-wildfly18.0-server | — |
| eap7-jboss-server-migration-wildfly8.2 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-jboss-server-migration-wildfly8.2 | — |
| eap7-jboss-server-migration-wildfly9.0 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-jboss-server-migration-wildfly9.0 | — |
| eap7-jboss-weld-3.1-api | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-jboss-weld-3.1-api | — |
| eap7-jboss-weld-3.1-api-weld-api | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-jboss-weld-3.1-api-weld-api | — |
| eap7-jboss-weld-3.1-api-weld-spi | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-jboss-weld-3.1-api-weld-spi | — |
| eap7-jgroups-kubernetes | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-jgroups-kubernetes | — |
| eap7-mod_cluster | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-mod_cluster | — |
| eap7-netty | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-netty | — |
| eap7-netty-all | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-netty-all | — |
| eap7-resteasy | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-resteasy | — |
| eap7-resteasy-atom-provider | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-resteasy-atom-provider | — |
| eap7-resteasy-cdi | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-resteasy-cdi | — |
| eap7-resteasy-client | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-resteasy-client | — |
| eap7-resteasy-client-microprofile | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-resteasy-client-microprofile | — |
| eap7-resteasy-crypto | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-resteasy-crypto | — |
| eap7-resteasy-jackson2-provider | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-resteasy-jackson2-provider | — |
| eap7-resteasy-jackson-provider | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-resteasy-jackson-provider | — |
| eap7-resteasy-jaxb-provider | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-resteasy-jaxb-provider | — |
| eap7-resteasy-jaxrs | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-resteasy-jaxrs | — |
| eap7-resteasy-jettison-provider | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-resteasy-jettison-provider | — |
| eap7-resteasy-jose-jwt | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-resteasy-jose-jwt | — |
| eap7-resteasy-jsapi | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-resteasy-jsapi | — |
| eap7-resteasy-json-binding-provider | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-resteasy-json-binding-provider | — |
| eap7-resteasy-json-p-provider | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-resteasy-json-p-provider | — |
| eap7-resteasy-multipart-provider | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-resteasy-multipart-provider | — |
| eap7-resteasy-rxjava2 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-resteasy-rxjava2 | — |
| eap7-resteasy-spring | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-resteasy-spring | — |
| eap7-resteasy-validator-provider-11 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-resteasy-validator-provider-11 | — |
| eap7-resteasy-yaml-provider | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-resteasy-yaml-provider | — |
| eap7-undertow | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-undertow | — |
| eap7-velocity | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-velocity | — |
| eap7-velocity-engine-core | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-velocity-engine-core | — |
| eap7-weld-core | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-weld-core | — |
| eap7-weld-core-impl | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-weld-core-impl | — |
| eap7-weld-core-jsf | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-weld-core-jsf | — |
| eap7-weld-ejb | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-weld-ejb | — |
| eap7-weld-jta | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-weld-jta | — |
| eap7-weld-probe-core | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-weld-probe-core | — |
| eap7-weld-web | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-weld-web | — |
| eap7-wildfly | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-wildfly | — |
| eap7-wildfly-elytron | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-wildfly-elytron | — |
| eap7-wildfly-elytron-tool | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-wildfly-elytron-tool | — |
| eap7-wildfly-http-client | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-wildfly-http-client | — |
| eap7-wildfly-http-client-common | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-wildfly-http-client-common | — |
| eap7-wildfly-http-ejb-client | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-wildfly-http-ejb-client | — |
| eap7-wildfly-http-naming-client | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-wildfly-http-naming-client | — |
| eap7-wildfly-http-transaction-client | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-wildfly-http-transaction-client | — |
| eap7-wildfly-javadocs | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-wildfly-javadocs | — |
| eap7-wildfly-java-jdk11 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-wildfly-java-jdk11 | — |
| eap7-wildfly-java-jdk8 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-wildfly-java-jdk8 | — |
| eap7-wildfly-modules | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-wildfly-modules | — |
| eap7-xalan-j2 | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-xalan-j2 | — |
| eap7-yasson | affected | Red Hat:jboss_enterprise_application_platform:7.3::el7 | eap7-yasson | — |
DEBIAN-CVE-2021-33194
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-golang-x-net | affected | Debian:14 | golang-golang-x-net | — |
| golang-golang-x-net | affected | Debian:11 | golang-golang-x-net | — |
| golang-golang-x-net | affected | Debian:12 | golang-golang-x-net | — |
| golang-golang-x-net | affected | Debian:13 | golang-golang-x-net | — |
golang.org/x/net before v0.0.0-20210520170846-37e1c6afe023 allows attackers to cause a denial of service (infinite loop) via crafted ParseFragment input.
CVEs:CVE-2021-33194
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| fedora | affected | fedoraproject | — | — |
| go | affected | golang | — | — |
golang.org/x/net/html Infinite Loop vulnerability
CVEs:CVE-2021-33194
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| x/net | affected | golang.org | golang.org/x/net | — |
Moderate: go-toolset:rhel8 security, bug fix, and enhancement update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | Rocky Linux:8 | delve | — |
| golang | affected | Rocky Linux:8 | golang | — |
| go-toolset | affected | Rocky Linux:8 | go-toolset | — |
A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission based ...
CVEs:CVE-2021-25735
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | kubernetes | — | — |
Access Restriction Bypass in kube-apiserver
CVEs:CVE-2021-25735
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
Access Restriction Bypass in kube-apiserver
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubeflow-pipelines | affected | wolfi | kubeflow-pipelines | — |
| kubeflow-pipelines | affected | chainguard | kubeflow-pipelines | — |
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
| kubernetes-dns-node-cache-1.17 | affected | chainguard | kubernetes-dns-node-cache-1.17 | — |
Access Restriction Bypass in kube-apiserver
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
In avrc_msg_cback of avrc_api.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: A...
CVEs:CVE-2021-0474
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0474
Kubernetes kubectl cp Vulnerable to Symlink Attack
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
Kubernetes kubectl cp Vulnerable to Symlink Attack
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | openSUSE:Leap 15.2 | chromium | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:10 | chromium | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | openSUSE:Leap 15.2 | chromium | — |
Type confusion in V8 in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30517
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30517
Type confusion in V8 in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30513
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30513
golang.org/x/text Infinite loop
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| x/text | affected | golang.org | golang.org/x/text | — |
golang.org/x/text Infinite loop
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| dex-k8s-authenticator | affected | chainguard | dex-k8s-authenticator | — |
| k3d | affected | chainguard | k3d | — |
| k3d | affected | wolfi | k3d | — |
| vt-cli | affected | wolfi | vt-cli | — |
| vt-cli | affected | chainguard | vt-cli | — |
| x/text | affected | golang.org | golang.org/x/text | — |
| x/text | affected | golang.org | — | — |
PUB-A-175769013
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:10 | chromium | — |
CVEs:CVE-2021-0466
In startIpClient of ClientModeImpl.java, there is a possible identifier which could be used to track a device. This could lead to remote information disclosure to a proximal attacker, with no additional execution privileges needed. User interaction is ...
CVEs:CVE-2021-0466
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Heap buffer overflow in History in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30516
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30516
CVEs:CVE-2021-30518
Heap buffer overflow in Reader Mode in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30518
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30512
Use after free in Notifications in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30512
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30510
Use after free in Aura in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30510
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30515
Use after free in File API in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30515
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30507
Inappropriate implementation in Offline in Google Chrome on Android prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
CVEs:CVE-2021-30507
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30514
Use after free in Autofill in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30514
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-0475
In on_l2cap_data_ind of btif_sock_l2cap.cc, there is possible memory corruption due to a use after free. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploita...
CVEs:CVE-2021-0475
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-30508
Heap buffer overflow in Media Feeds in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to enable certain features in Chrome to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30508
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30519
Use after free in Payments in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious payments app to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30519
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30511
Out of bounds read in Tab Groups in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted HTML page.
CVEs:CVE-2021-30511
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
Use after free in Tab Strip in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30520
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30520
CVEs:CVE-2021-30509
Out of bounds write in Tab Strip in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page and a crafted Chrome extension.
CVEs:CVE-2021-30509
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30506
Incorrect security UI in Web App Installs in Google Chrome on Android prior to 90.0.4430.212 allowed an attacker who convinced a user to install a web application to inject scripts or HTML into a privileged page via a crafted HTML page.
CVEs:CVE-2021-30506
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-0481
In onActivityResult of EditUserPhotoController.java, there is a possible access of unauthorized files due to an unexpected URI handler. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is...
CVEs:CVE-2021-0481
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-175769054
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
CVEs:CVE-2021-0472
In shouldLockKeyguard of LockTaskController.java, there is a possible way to exit App Pinning without a PIN due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction i...
CVEs:CVE-2021-0472
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In FindOrCreatePeer of btif_av.cc, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: And...
CVEs:CVE-2021-0476
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0476
Use after free in WebAudio in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30522
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30522
Prototype pollution in grpc and @grpc/grpc-js
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| grpc | affected | npm | grpc | — |
| grpc-js | affected | grpc | @grpc/grpc-js | — |
Prototype pollution in grpc and @grpc/grpc-js
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| grpc | affected | npm | grpc | — |
| grpc-js | affected | grpc | @grpc/grpc-js | — |
DEBIAN-CVE-2021-31525
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-1.15 | affected | Debian:11 | golang-1.15 | — |
| golang-golang-x-net | affected | Debian:11 | golang-golang-x-net | — |
| golang-golang-x-net | affected | Debian:12 | golang-golang-x-net | — |
| golang-golang-x-net | affected | Debian:13 | golang-golang-x-net | — |
| golang-golang-x-net | affected | Debian:14 | golang-golang-x-net | — |
golang.org/x/net/http/httpguts vulnerable to Uncontrolled Recursion
CVEs:CVE-2021-31525
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| x/net | affected | golang.org | golang.org/x/net | — |
net/http in Go before 1.15.12 and 1.16.x before 1.16.4 allows remote attackers to cause a denial of service (panic) via a large header to ReadRequest or ReadResponse. Server, Transport, and Client can each be affected in some configurations.
CVEs:CVE-2021-31525
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| fedora | affected | fedoraproject | — | — |
| go | affected | golang | — | — |
golang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | openEuler:20.03-LTS-SP1 | golang | — |
Exposure of sensitive information in k8s.io/kube-state-metrics
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kube-state-metrics | affected | k8s.io | k8s.io/kube-state-metrics | — |
CVEs:CVE-2021-30531
Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page.
CVEs:CVE-2021-30531
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
Incorrect security UI in payments in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
CVEs:CVE-2021-30540
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30540
Use after free in WebAuthentication in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker who had compromised the renderer process of a user who had saved a credit card in their Google account to potentially exploit heap corruptio...
CVEs:CVE-2021-30528
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30528
CVEs:CVE-2021-30521
Heap buffer overflow in Autofill in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.
CVEs:CVE-2021-30521
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVEs:CVE-2021-31982
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
CVEs:CVE-2021-31982
CVEs:CVE-2021-30539
Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page.
CVEs:CVE-2021-30539
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
Insufficient policy enforcement in iFrameSandbox in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
CVEs:CVE-2021-30534
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30534
CVEs:CVE-2021-30536
Out of bounds read in V8 in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page.
CVEs:CVE-2021-30536
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30530
Out of bounds memory access in WebAudio in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.
CVEs:CVE-2021-30530
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
Istio Authorization Bypass Vulnerability
CVEs:CVE-2021-31920
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| istio | affected | istio.io | istio.io/istio | — |
Istio before 1.8.6 and 1.9.x before 1.9.5 has a remotely exploitable vulnerability where an HTTP request path with multiple slashes or escaped slash characters (%2F or %5C) could potentially bypass an Istio authorization policy when path based authoriz...
CVEs:CVE-2021-31920
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| istio | affected | istio | — | — |
Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page.
CVEs:CVE-2021-30532
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30532
Insufficient policy enforcement in cookies in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass cookie policy via a crafted HTML page.
CVEs:CVE-2021-30537
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30537
CVEs:CVE-2021-30535
Double free in ICU in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30535
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
Use after free in WebRTC in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption via a crafted SCTP packet.
CVEs:CVE-2021-30523
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30523
Use after free in Bookmarks in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30529
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30529
CVEs:CVE-2021-30526
Out of bounds write in TabStrip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page.
CVEs:CVE-2021-30526
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30524
Use after free in TabStrip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30524
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
Use after free in WebUI in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30527
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30527
DEBIAN-CVE-2021-29499
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-sylabs-sif | affected | Debian:11 | golang-github-sylabs-sif | — |
| golang-github-sylabs-sif | affected | Debian:12 | golang-github-sylabs-sif | — |
| golang-github-sylabs-sif | affected | Debian:13 | golang-github-sylabs-sif | — |
| golang-github-sylabs-sif | affected | Debian:14 | golang-github-sylabs-sif | — |
Use after free in TabGroups in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30525
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30525
CVEs:CVE-2021-31937
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVEs:CVE-2021-31937
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
Privilege escalation in rbac
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google/exposure-notifications-verification-server | affected | github.com | github.com/google/exposure-notifications-verification-server | — |
Privilege escalation in rbac
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google/exposure-notifications-verification-server | affected | github.com | github.com/google/exposure-notifications-verification-server | — |
Uncontrolled Resource Consumption in firebase
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| util | affected | firebase | @firebase/util | — |
Uncontrolled Resource Consumption in firebase
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| util | affected | firebase | @firebase/util | — |
Improper Input Validation in Google Closure Library
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google-closure-library | affected | npm | google-closure-library | — |
Improper Input Validation in Google Closure Library
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google-closure-library | affected | npm | google-closure-library | — |
CVEs:CVE-2021-0324
Product: AndroidVersions: Android SoCAndroid ID: A-175402462
CVEs:CVE-2021-0324
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-175402462
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In rw_t3t_process_error of rw_t3t.cc, there is a possible double free due to uninitialized data. This could lead to remote code execution over NFC with no additional execution privileges needed. User interaction is not needed for exploitation.Product: ...
CVEs:CVE-2021-0473
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0473
PUB-A-174904705
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
CVEs:CVE-2021-0480
In createPendingIntent of SnoozeHelper.java, there is a possible broadcast intent containing a sensitive identifier. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploita...
CVEs:CVE-2021-0480
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CHECK-fail in `QuantizeAndDequantizeV4Grad`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CHECK-fail in `QuantizeAndDequantizeV4Grad`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-181
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-472
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-670
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CHECK-fail in `QuantizeAndDequantizeV4Grad`
CVEs:CVE-2021-29544
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-670
CVEs:CVE-2021-29544
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a denial of service via a `CHECK`-fail in `tf.raw_ops.QuantizeAndDequantizeV4Grad`. This is because the implementation does not validate the rank of the `inp...
CVEs:CVE-2021-29544
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Heap buffer overflow in `BandedTriangularSolve`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `BandedTriangularSolve`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-249
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-540
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-738
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a heap buffer overflow in Eigen implementation of `tf.raw_ops.BandedTriangularSolve`. The implementation(https://github.com/tensorflow/tensorflow/blob/eccb7e...
CVEs:CVE-2021-29612
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Heap buffer overflow in `BandedTriangularSolve`
CVEs:CVE-2021-29612
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-738
CVEs:CVE-2021-29612
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Stack overflow due to looping TFLite subgraph
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Stack overflow due to looping TFLite subgraph
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-228
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-519
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | — | — |
PYSEC-2021-717
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. TFlite graphs must not have loops between nodes. However, this condition was not checked and an attacker could craft models that would result in infinite loop during evaluation. In ...
CVEs:CVE-2021-29591
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-717
CVEs:CVE-2021-29591
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Stack overflow due to looping TFLite subgraph
CVEs:CVE-2021-29591
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow caused by rounding
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow caused by rounding
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-166
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-457
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-655
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-655
CVEs:CVE-2021-29529
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a heap buffer overflow in `tf.raw_ops.QuantizedResizeBilinear` by manipulating input values so that float rounding results in off-by-one error in accessing i...
CVEs:CVE-2021-29529
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Heap buffer overflow caused by rounding
CVEs:CVE-2021-29529
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Incomplete validation in `tf.raw_ops.CTCLoss`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Incomplete validation in `tf.raw_ops.CTCLoss`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Memory corruption in `DrawBoundingBoxesV2`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Memory corruption in `DrawBoundingBoxesV2`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-208
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-250
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-499
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-541
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-697
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-739
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. Incomplete validation in `tf.raw_ops.CTCLoss` allows an attacker to trigger an OOB read from heap. The fix will be included in TensorFlow 2.5.0. We will also cherrypick these commit...
CVEs:CVE-2021-29613
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Incomplete validation in `tf.raw_ops.CTCLoss`
CVEs:CVE-2021-29613
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-739
CVEs:CVE-2021-29613
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-697
CVEs:CVE-2021-29571
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Memory corruption in `DrawBoundingBoxesV2`
CVEs:CVE-2021-29571
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.MaxPoolGradWithArgmax` can cause reads outside of bounds of heap allocated data if attacker supplies specially crafted inputs. The implementation(h...
CVEs:CVE-2021-29571
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Incomplete validation in `SparseAdd`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Incomplete validation in `SparseAdd`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap OOB and null pointer dereference in `RaggedTensorToTensor`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap OOB and null pointer dereference in `RaggedTensorToTensor`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-244
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-245
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-246
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-535
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-536
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-537
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-733
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-734
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-735
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. Incomplete validation in `SparseAdd` results in allowing attackers to exploit undefined behavior (dereferencing null pointers) as well as write outside of bounds of heap allocated d...
CVEs:CVE-2021-29607
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Incomplete validation in `SparseSparseMinimum`
CVEs:CVE-2021-29607
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-733
CVEs:CVE-2021-29607
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap OOB and null pointer dereference in `RaggedTensorToTensor`
CVEs:CVE-2021-29608
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. Due to lack of validation in `tf.raw_ops.RaggedTensorToTensor`, an attacker can exploit an undefined behavior if input arguments are empty. The implementation(https://github.com/ten...
CVEs:CVE-2021-29608
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-734
CVEs:CVE-2021-29608
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-735
CVEs:CVE-2021-29609
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Incomplete validation in `SparseAdd`
CVEs:CVE-2021-29609
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. Incomplete validation in `SparseAdd` results in allowing attackers to exploit undefined behavior (dereferencing null pointers) as well as write outside of bounds of heap allocated d...
CVEs:CVE-2021-29609
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Invalid validation in `SparseMatrixSparseCholesky`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Invalid validation in `SparseMatrixSparseCholesky`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-167
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-458
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-656
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a null pointer dereference by providing an invalid `permutation` to `tf.raw_ops.SparseMatrixSparseCholesky`. This is because the implementation(https://githu...
CVEs:CVE-2021-29530
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Invalid validation in `SparseMatrixSparseCholesky`
CVEs:CVE-2021-29530
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-656
CVEs:CVE-2021-29530
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Crash in `tf.transpose` with complex inputs
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Crash in `tf.transpose` with complex inputs
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Crash in `tf.strings.substr` due to `CHECK`-fail
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Crash in `tf.strings.substr` due to `CHECK`-fail
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-254
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-255
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-545
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-546
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-743
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-744
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-743
CVEs:CVE-2021-29617
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Crash in `tf.strings.substr` due to `CHECK`-fail
CVEs:CVE-2021-29617
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service via `CHECK`-fail in `tf.strings.substr` with invalid arguments. The fix will be included in TensorFlow 2.5.0. We will also cherrypick this ...
CVEs:CVE-2021-29617
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-744
CVEs:CVE-2021-29618
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. Passing a complex argument to `tf.transpose` at the same time as passing `conjugate=True` argument results in a crash. The fix will be included in TensorFlow 2.5.0. We will also che...
CVEs:CVE-2021-29618
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Crash in `tf.transpose` with complex inputs
CVEs:CVE-2021-29618
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `Conv3DBackprop*`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `Conv3DBackprop*`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-157
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-448
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-646
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `Conv3DBackprop*`
CVEs:CVE-2021-29520
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. Missing validation between arguments to `tf.raw_ops.Conv3DBackprop*` operations can result in heap buffer overflows. This is because the implementation(https://github.com/tensorflow...
CVEs:CVE-2021-29520
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-646
CVEs:CVE-2021-29520
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Interpreter crash from `tf.io.decode_raw`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Interpreter crash from `tf.io.decode_raw`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-251
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-542
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-740
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Interpreter crash from `tf.io.decode_raw`
CVEs:CVE-2021-29614
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-740
CVEs:CVE-2021-29614
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.io.decode_raw` produces incorrect results and crashes the Python interpreter when combining `fixed_length` and wider datatypes. The implementation of the p...
CVEs:CVE-2021-29614
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Integer overflow in TFLite memory allocation
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Integer overflow in TFLite memory allocation
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-242
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-533
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-731
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-731
CVEs:CVE-2021-29605
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Integer overflow in TFLite memory allocation
CVEs:CVE-2021-29605
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. The TFLite code for allocating `TFLiteIntArray`s is vulnerable to an integer overflow issue(https://github.com/tensorflow/tensorflow/blob/4ceffae632721e52bf3501b736e4fe9d1221cdfa/te...
CVEs:CVE-2021-29605
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
OOB read in `MatrixTriangularSolve`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
OOB read in `MatrixTriangularSolve`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CHECK-fail in DrawBoundingBoxes
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CHECK-fail in DrawBoundingBoxes
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-170
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-188
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-461
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-479
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-659
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-677
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a denial of service via a `CHECK` failure by passing an empty image to `tf.raw_ops.DrawBoundingBoxes`. This is because the implementation(https://github.com/...
CVEs:CVE-2021-29533
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
CHECK-fail in DrawBoundingBoxes
CVEs:CVE-2021-29533
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-659
CVEs:CVE-2021-29533
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-677
CVEs:CVE-2021-29551
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
OOB read in `MatrixTriangularSolve`
CVEs:CVE-2021-29551
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. The implementation of `MatrixTriangularSolve`(https://github.com/tensorflow/tensorflow/blob/8cae746d8449c7dda5298327353d68613f16e798/tensorflow/core/kernels/linalg/matrix_triangular...
CVEs:CVE-2021-29551
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
CVEs:CVE-2021-22547
In IoT Devices SDK, there is an implementation of calloc() that doesn't have a length check. An attacker could pass in memory objects larger than the buffer and wrap around to have a smaller buffer than required, allowing the attacker access to the oth...
CVEs:CVE-2021-22547
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| cloud_iot_device_sdk_for_embedded_c | affected | — | — |
Heap OOB read in TFLite
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap OOB read in TFLite
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Null pointer dereference in TFLite's `Reshape` operator
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Null pointer dereference in TFLite's `Reshape` operator
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `Conv2DBackpropFilter`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `Conv2DBackpropFilter`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-177
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-229
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-243
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-468
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-520
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | — | — |
PYSEC-2021-534
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-666
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-718
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-732
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Null pointer dereference in TFLite's `Reshape` operator
CVEs:CVE-2021-29592
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-718
CVEs:CVE-2021-29592
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. The fix for CVE-2020-15209(https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15209) missed the case when the target shape of `Reshape` operator is given by the elements of a 1...
CVEs:CVE-2021-29592
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-732
CVEs:CVE-2021-29606
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap OOB read in TFLite
CVEs:CVE-2021-29606
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. A specially crafted TFLite model could trigger an OOB read on heap in the TFLite implementation of `Split_V`(https://github.com/tensorflow/tensorflow/blob/c59c37e7b2d563967da813fa50...
CVEs:CVE-2021-29606
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow to occur in `Conv2DBackpropFilter`. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/1b0296c3b8dd9bd948f...
CVEs:CVE-2021-29540
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Heap buffer overflow in `Conv2DBackpropFilter`
CVEs:CVE-2021-29540
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-666
CVEs:CVE-2021-29540
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `MaxPoolGrad`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `MaxPoolGrad`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-216
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-507
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-705
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `MaxPoolGrad`
CVEs:CVE-2021-29579
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-705
CVEs:CVE-2021-29579
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.MaxPoolGrad` is vulnerable to a heap buffer overflow. The implementation(https://github.com/tensorflow/tensorflow/blob/ab1e644b48c82cb71493f4362b4d...
CVEs:CVE-2021-29579
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Heap buffer overflow and undefined behavior in `FusedBatchNorm`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow and undefined behavior in `FusedBatchNorm`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `FractionalAvgPoolGrad`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `FractionalAvgPoolGrad`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `AvgPool3DGrad`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `AvgPool3DGrad`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `MaxPool3DGradGrad`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `MaxPool3DGradGrad`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `SparseSplit`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `SparseSplit`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `QuantizedResizeBilinear`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `QuantizedResizeBilinear`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `QuantizedReshape`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `QuantizedReshape`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `QuantizedMul`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `QuantizedMul`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap out of bounds write in `RaggedBinCount`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap out of bounds write in `RaggedBinCount`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `RaggedBinCount`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `RaggedBinCount`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-151
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-172
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-173
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-174
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-195
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-213
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-214
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-215
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-220
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-442
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-463
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | — | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-464
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | — | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-465
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-486
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-504
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-505
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-506
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-511
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-640
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-661
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-662
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-663
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-684
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-702
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-703
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-704
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-709
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap out of bounds write in `RaggedBinCount`
CVEs:CVE-2021-29514
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-640
CVEs:CVE-2021-29514
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. If the `splits` argument of `RaggedBincount` does not specify a valid `SparseTensor`(https://www.tensorflow.org/api_docs/python/tf/sparse/SparseTensor), then an attacker can trigger...
CVEs:CVE-2021-29514
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow in `tf.raw_ops.SparseSplit`. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/699bff5d961f0abfde8fa3f876...
CVEs:CVE-2021-29558
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Heap buffer overflow in `SparseSplit`
CVEs:CVE-2021-29558
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-684
CVEs:CVE-2021-29558
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `MaxPool3DGradGrad`
CVEs:CVE-2021-29576
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-702
CVEs:CVE-2021-29576
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.MaxPool3DGradGrad` is vulnerable to a heap buffer overflow. The implementation(https://github.com/tensorflow/tensorflow/blob/596c05a159b6fbb9e39ca1...
CVEs:CVE-2021-29576
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.AvgPool3DGrad` is vulnerable to a heap buffer overflow. The implementation(https://github.com/tensorflow/tensorflow/blob/d80ffba9702dc19d1fac74fc4b...
CVEs:CVE-2021-29577
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Heap buffer overflow in `AvgPool3DGrad`
CVEs:CVE-2021-29577
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-703
CVEs:CVE-2021-29577
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.FractionalAvgPoolGrad` is vulnerable to a heap buffer overflow. The implementation(https://github.com/tensorflow/tensorflow/blob/dcba796a28364d6d7f...
CVEs:CVE-2021-29578
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-704
CVEs:CVE-2021-29578
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `FractionalAvgPoolGrad`
CVEs:CVE-2021-29578
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-709
CVEs:CVE-2021-29583
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow and undefined behavior in `FusedBatchNorm`
CVEs:CVE-2021-29583
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.FusedBatchNorm` is vulnerable to a heap buffer overflow. If the tensors are empty, the same implementation can trigger undefined behavior by derefe...
CVEs:CVE-2021-29583
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-149
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-440
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-638
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow in `QuantizedMul` by passing in invalid thresholds for the quantization. This is because the implementation(https://github.com/tensorflo...
CVEs:CVE-2021-29535
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-661
CVEs:CVE-2021-29535
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `QuantizedMul`
CVEs:CVE-2021-29535
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `QuantizedReshape`
CVEs:CVE-2021-29536
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow in `QuantizedReshape` by passing in invalid thresholds for the quantization. This is because the implementation(https://github.com/tenso...
CVEs:CVE-2021-29536
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-662
CVEs:CVE-2021-29536
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-663
CVEs:CVE-2021-29537
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow in `QuantizedResizeBilinear` by passing in invalid thresholds for the quantization. This is because the implementation(https://github.co...
CVEs:CVE-2021-29537
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Heap buffer overflow in `QuantizedResizeBilinear`
CVEs:CVE-2021-29537
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. If the `splits` argument of `RaggedBincount` does not specify a valid `SparseTensor`(https://www.tensorflow.org/api_docs/python/tf/sparse/SparseTensor), then an attacker can trigger...
CVEs:CVE-2021-29512
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-638
CVEs:CVE-2021-29512
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `RaggedBinCount`
CVEs:CVE-2021-29512
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in TFLite's implementation of Split
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in TFLite's implementation of Split
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-236
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-527
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-725
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. The implementation of the `Split` TFLite operator is vulnerable to a division by zero error(https://github.com/tensorflow/tensorflow/blob/e2752089ef7ce9bcf3db0ec618ebd23ea119d0c7/te...
CVEs:CVE-2021-29599
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-725
CVEs:CVE-2021-29599
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in TFLite's implementation of Split
CVEs:CVE-2021-29599
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `RaggedTensorToTensor`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `RaggedTensorToTensor`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-197
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-488
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-686
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow in `tf.raw_ops.RaggedTensorToTensor`. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/d94227d43aa125ad8...
CVEs:CVE-2021-29560
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-686
CVEs:CVE-2021-29560
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `RaggedTensorToTensor`
CVEs:CVE-2021-29560
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Null dereference in Grappler's `TrySimplify`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Null dereference in Grappler's `TrySimplify`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-253
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-544
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-742
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Null dereference in Grappler's `TrySimplify`
CVEs:CVE-2021-29616
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. The implementation of TrySimplify(https://github.com/tensorflow/tensorflow/blob/c22d88d6ff33031aa113e48aa3fc9aa74ed79595/tensorflow/core/grappler/optimizers/arithmetic_optimizer.cc#...
CVEs:CVE-2021-29616
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-742
CVEs:CVE-2021-29616
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Stack overflow in `ParseAttrValue` with nested tensors
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Stack overflow in `ParseAttrValue` with nested tensors
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-252
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-543
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-741
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-741
CVEs:CVE-2021-29615
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Stack overflow in `ParseAttrValue` with nested tensors
CVEs:CVE-2021-29615
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. The implementation of `ParseAttrValue`(https://github.com/tensorflow/tensorflow/blob/c22d88d6ff33031aa113e48aa3fc9aa74ed79595/tensorflow/core/framework/attr_value_util.cc#L397-L453)...
CVEs:CVE-2021-29615
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Type confusion during tensor casts lead to dereferencing null pointers
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Type confusion during tensor casts lead to dereferencing null pointers
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-150
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-441
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-639
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Type confusion during tensor casts lead to dereferencing null pointers
CVEs:CVE-2021-29513
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-639
CVEs:CVE-2021-29513
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. Calling TF operations with tensors of non-numeric types when the operations expect numeric tensors result in null pointer dereferences. The conversion from Python array to C++ array...
CVEs:CVE-2021-29513
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Incomplete validation in `SparseReshape`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Incomplete validation in `SparseReshape`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-248
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-539
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-737
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-737
CVEs:CVE-2021-29611
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Incomplete validation in `SparseReshape`
CVEs:CVE-2021-29611
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. Incomplete validation in `SparseReshape` results in a denial of service based on a `CHECK`-failure. The implementation(https://github.com/tensorflow/tensorflow/blob/e87b51ce05c3eb17...
CVEs:CVE-2021-29611
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Invalid validation in `QuantizeAndDequantizeV2`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Invalid validation in `QuantizeAndDequantizeV2`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap OOB write in TFLite
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap OOB write in TFLite
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in TFLite's implementation of `OneHot`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in TFLite's implementation of `OneHot`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in TFLite's implementation of `SVDF`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in TFLite's implementation of `SVDF`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in TFLite's implementation of `SpaceToBatchNd`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in TFLite's implementation of `SpaceToBatchNd`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in TFLite's implementation of `EmbeddingLookup`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in TFLite's implementation of `EmbeddingLookup`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in TFLite's implementation of `DepthToSpace`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in TFLite's implementation of `DepthToSpace`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in TFLite's convolution code
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in TFLite's convolution code
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in TFLite's implementation of `BatchToSpaceNd`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in TFLite's implementation of `BatchToSpaceNd`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in TFLite's implementation of `GatherNd`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in TFLite's implementation of `GatherNd`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in TFLite's implementation of `TransposeConv`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in TFLite's implementation of `TransposeConv`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in TFLite's implementation of `SpaceToDepth`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in TFLite's implementation of `SpaceToDepth`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in optimized pooling implementations in TFLite
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in optimized pooling implementations in TFLite
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in padding computation in TFLite
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in padding computation in TFLite
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Undefined behavior in `MaxPool3DGradGrad`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Undefined behavior in `MaxPool3DGradGrad`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap OOB access in `Dilation2DBackpropInput`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap OOB access in `Dilation2DBackpropInput`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `QuantizedBiasAdd`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `QuantizedBiasAdd`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `Conv2DBackpropInput`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `Conv2DBackpropInput`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Session operations in eager mode lead to null pointer dereferences
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Session operations in eager mode lead to null pointer dereferences
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Reference binding to null pointer in `MatrixDiag*` ops
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Reference binding to null pointer in `MatrixDiag*` ops
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-152
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-155
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-162
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-183
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-203
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-211
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-222
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-223
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-224
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-225
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-226
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-230
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-231
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-232
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-233
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-234
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-235
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-237
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-240
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-247
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-443
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-446
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-453
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-474
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-494
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-502
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-513
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-514
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-515
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-516
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-517
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-521
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-522
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-523
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-524
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-525
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-526
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-528
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-531
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-538
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-641
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-644
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-651
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-672
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-692
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-700
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-711
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-712
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-713
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-714
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-715
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-719
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-720
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-721
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-722
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-723
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-724
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-726
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-729
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-736
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. The implementation of `MatrixDiag*` operations(https://github.com/tensorflow/tensorflow/blob/4c4f420e68f1cfaf8f4b6e8e3eb857e9e4c3ff33/tensorflow/core/kernels/linalg/matrix_diag_op.c...
CVEs:CVE-2021-29515
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Reference binding to null pointer in `MatrixDiag*` ops
CVEs:CVE-2021-29515
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-641
CVEs:CVE-2021-29515
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-644
CVEs:CVE-2021-29518
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. In eager mode (default in TF 2.0 and later), session operations are invalid. However, users could still call the raw ops associated with them and trigger a null pointer dereference....
CVEs:CVE-2021-29518
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Session operations in eager mode lead to null pointer dereferences
CVEs:CVE-2021-29518
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in padding computation in TFLite
CVEs:CVE-2021-29585
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. The TFLite computation for size of output after padding, `ComputeOutSize`(https://github.com/tensorflow/tensorflow/blob/0c9692ae7b1671c983569e5d3de5565843d500cf/tensorflow/lite/kern...
CVEs:CVE-2021-29585
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-711
CVEs:CVE-2021-29585
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-712
CVEs:CVE-2021-29586
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in optimized pooling implementations in TFLite
CVEs:CVE-2021-29586
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. Optimized pooling implementations in TFLite fail to check that the stride arguments are not 0 before calling `ComputePaddingHeightWidth`(https://github.com/tensorflow/tensorflow/blo...
CVEs:CVE-2021-29586
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-713
CVEs:CVE-2021-29587
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in TFLite's implementation of `SpaceToDepth`
CVEs:CVE-2021-29587
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. The `Prepare` step of the `SpaceToDepth` TFLite operator does not check for 0 before division(https://github.com/tensorflow/tensorflow/blob/5f7975d09eac0f10ed8a17dbb6f5964977725adc/...
CVEs:CVE-2021-29587
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-714
CVEs:CVE-2021-29588
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. The optimized implementation of the `TransposeConv` TFLite operator is [vulnerable to a division by zero error](https://github.com/tensorflow/tensorflow/blob/0d45ea1ca641b21b73bcf9c...
CVEs:CVE-2021-29588
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Division by zero in TFLite's implementation of `TransposeConv`
CVEs:CVE-2021-29588
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in TFLite's implementation of `GatherNd`
CVEs:CVE-2021-29589
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. The reference implementation of the `GatherNd` TFLite operator is vulnerable to a division by zero error(https://github.com/tensorflow/tensorflow/blob/0d45ea1ca641b21b73bcf9c00e0179...
CVEs:CVE-2021-29589
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-715
CVEs:CVE-2021-29589
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in TFLite's implementation of `BatchToSpaceNd`
CVEs:CVE-2021-29593
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. The implementation of the `BatchToSpaceNd` TFLite operator is vulnerable to a division by zero error(https://github.com/tensorflow/tensorflow/blob/b5ed552fe55895aee8bd8b191f744a0699...
CVEs:CVE-2021-29593
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-719
CVEs:CVE-2021-29593
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. TFLite's convolution code(https://github.com/tensorflow/tensorflow/blob/09c73bca7d648e961dd05898292d91a8322a9d45/tensorflow/lite/kernels/conv.cc) has multiple division where the div...
CVEs:CVE-2021-29594
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Division by zero in TFLite's convolution code
CVEs:CVE-2021-29594
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-720
CVEs:CVE-2021-29594
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-721
CVEs:CVE-2021-29595
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in TFLite's implementation of `DepthToSpace`
CVEs:CVE-2021-29595
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. The implementation of the `DepthToSpace` TFLite operator is vulnerable to a division by zero error(https://github.com/tensorflow/tensorflow/blob/0d45ea1ca641b21b73bcf9c00e0179cda284...
CVEs:CVE-2021-29595
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow is an end-to-end open source platform for machine learning. The implementation of the `EmbeddingLookup` TFLite operator is vulnerable to a division by zero error(https://github.com/tensorflow/tensorflow/blob/e4b29809543b250bc9b19678ec4776299...
CVEs:CVE-2021-29596
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-722
CVEs:CVE-2021-29596
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in TFLite's implementation of `EmbeddingLookup`
CVEs:CVE-2021-29596
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in TFLite's implementation of `SpaceToBatchNd`
CVEs:CVE-2021-29597
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. The implementation of the `SpaceToBatchNd` TFLite operator is [vulnerable to a division by zero error](https://github.com/tensorflow/tensorflow/blob/412c7d9bb8f8a762c5b266c9e73bfa16...
CVEs:CVE-2021-29597
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-723
CVEs:CVE-2021-29597
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-724
CVEs:CVE-2021-29598
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. The implementation of the `SVDF` TFLite operator is vulnerable to a division by zero error(https://github.com/tensorflow/tensorflow/blob/7f283ff806b2031f407db64c4d3edcda8fb9f9f5/ten...
CVEs:CVE-2021-29598
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Division by zero in TFLite's implementation of `SVDF`
CVEs:CVE-2021-29598
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in TFLite's implementation of `OneHot`
CVEs:CVE-2021-29600
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-726
CVEs:CVE-2021-29600
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. The implementation of the `OneHot` TFLite operator is vulnerable to a division by zero error(https://github.com/tensorflow/tensorflow/blob/f61c57bd425878be108ec787f4d96390579fb83e/t...
CVEs:CVE-2021-29600
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-729
CVEs:CVE-2021-29603
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap OOB write in TFLite
CVEs:CVE-2021-29603
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. A specially crafted TFLite model could trigger an OOB write on heap in the TFLite implementation of `ArgMin`/`ArgMax`(https://github.com/tensorflow/tensorflow/blob/102b211d892f3abc1...
CVEs:CVE-2021-29603
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-736
CVEs:CVE-2021-29610
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. The validation in `tf.raw_ops.QuantizeAndDequantizeV2` allows invalid values for `axis` argument:. The validation(https://github.com/tensorflow/tensorflow/blob/eccb7ec454e6617738554...
CVEs:CVE-2021-29610
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Invalid validation in `QuantizeAndDequantizeV2`
CVEs:CVE-2021-29610
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can write outside the bounds of heap allocated arrays by passing invalid arguments to `tf.raw_ops.Dilation2DBackpropInput`. This is because the implementation(https://gi...
CVEs:CVE-2021-29566
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-692
CVEs:CVE-2021-29566
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap OOB access in `Dilation2DBackpropInput`
CVEs:CVE-2021-29566
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Undefined behavior in `MaxPool3DGradGrad`
CVEs:CVE-2021-29574
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.MaxPool3DGradGrad` exhibits undefined behavior by dereferencing null pointers backing attacker-supplied empty tensors. The implementation(https://g...
CVEs:CVE-2021-29574
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-700
CVEs:CVE-2021-29574
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-651
CVEs:CVE-2021-29525
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a division by 0 in `tf.raw_ops.Conv2DBackpropInput`. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/b40060c9f697b044e310791...
CVEs:CVE-2021-29525
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Division by 0 in `Conv2DBackpropInput`
CVEs:CVE-2021-29525
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-672
CVEs:CVE-2021-29546
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger an integer division by zero undefined behavior in `tf.raw_ops.QuantizedBiasAdd`. This is because the implementation of the Eigen kernel(https://github.com/te...
CVEs:CVE-2021-29546
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Division by 0 in `QuantizedBiasAdd`
CVEs:CVE-2021-29546
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
In pfkey_dump of af_key.c, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure in the kernel with System execution privileges needed. User interaction is not needed for exploitation.Prod...
CVEs:CVE-2021-0605
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0605
Heap OOB read in TFLite's implementation of `Minimum` or `Maximum`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap OOB read in TFLite's implementation of `Minimum` or `Maximum`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap OOB read in `tf.raw_ops.Dequantize`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap OOB read in `tf.raw_ops.Dequantize`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Overflow/denial of service in `tf.raw_ops.ReverseSequence`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Overflow/denial of service in `tf.raw_ops.ReverseSequence`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap out of bounds read in `RequantizationRange`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap out of bounds read in `RequantizationRange`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap OOB access in unicode ops
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap OOB access in unicode ops
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap OOB in `QuantizeAndDequantizeV3`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap OOB in `QuantizeAndDequantizeV3`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `StringNGrams`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `StringNGrams`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap out of bounds read in `RaggedCross`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap out of bounds read in `RaggedCross`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `Conv2D`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `Conv2D`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Null pointer dereference via invalid Ragged Tensors
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Null pointer dereference via invalid Ragged Tensors
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-153
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-163
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-169
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-179
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-190
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-196
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-206
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-212
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-219
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-227
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-444
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-454
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-460
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-470
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-481
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-487
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-497
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-503
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-510
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-518
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-642
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-652
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-658
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-668
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-679
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-685
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-695
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-701
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-708
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-716
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. Calling `tf.raw_ops.RaggedTensorToVariant` with arguments specifying an invalid ragged tensor results in a null pointer dereference. The implementation of `RaggedTensorToVariant` op...
CVEs:CVE-2021-29516
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-642
CVEs:CVE-2021-29516
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Null pointer dereference via invalid Ragged Tensors
CVEs:CVE-2021-29516
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-716
CVEs:CVE-2021-29590
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap OOB read in TFLite's implementation of `Minimum` or `Maximum`
CVEs:CVE-2021-29590
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. The implementations of the `Minimum` and `Maximum` TFLite operators can be used to read data outside of bounds of heap allocated objects, if any of the two input tensor arguments ar...
CVEs:CVE-2021-29590
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-685
CVEs:CVE-2021-29559
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can access data outside of bounds of heap allocated array in `tf.raw_ops.UnicodeEncode`. This is because the implementation(https://github.com/tensorflow/tensorflow/blob...
CVEs:CVE-2021-29559
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Heap OOB access in unicode ops
CVEs:CVE-2021-29559
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.MaxPoolGradWithArgmax` can cause reads outside of bounds of heap allocated data if attacker supplies specially crafted inputs. The implementation(h...
CVEs:CVE-2021-29569
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Heap out of bounds read in `RequantizationRange`
CVEs:CVE-2021-29569
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-695
CVEs:CVE-2021-29569
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-701
CVEs:CVE-2021-29575
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.ReverseSequence` allows for stack overflow and/or `CHECK`-fail based denial of service. The implementation(https://github.com/tensorflow/tensorflow...
CVEs:CVE-2021-29575
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Overflow/denial of service in `tf.raw_ops.ReverseSequence`
CVEs:CVE-2021-29575
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-708
CVEs:CVE-2021-29582
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. Due to lack of validation in `tf.raw_ops.Dequantize`, an attacker can trigger a read from outside of bounds of heap allocated data. The implementation(https://github.com/tensorflow/...
CVEs:CVE-2021-29582
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Heap OOB read in `tf.raw_ops.Dequantize`
CVEs:CVE-2021-29582
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a division by 0 in `tf.raw_ops.Conv2D`. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/988087bd83f144af14087fe4fecee2d250d9...
CVEs:CVE-2021-29526
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-652
CVEs:CVE-2021-29526
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `Conv2D`
CVEs:CVE-2021-29526
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can force accesses outside the bounds of heap allocated arrays by passing in invalid tensor values to `tf.raw_ops.RaggedCross`. This is because the implementation(https:...
CVEs:CVE-2021-29532
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-658
CVEs:CVE-2021-29532
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap out of bounds read in `RaggedCross`
CVEs:CVE-2021-29532
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow by passing crafted inputs to `tf.raw_ops.StringNGrams`. This is because the implementation(https://github.com/tensorflow/tensorflow/blob...
CVEs:CVE-2021-29542
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-668
CVEs:CVE-2021-29542
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `StringNGrams`
CVEs:CVE-2021-29542
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap OOB in `QuantizeAndDequantizeV3`
CVEs:CVE-2021-29553
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can read data outside of bounds of heap allocated buffer in `tf.raw_ops.QuantizeAndDequantizeV3`. This is because the implementation(https://github.com/tensorflow/tensor...
CVEs:CVE-2021-29553
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-679
CVEs:CVE-2021-29553
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Reference binding to null in `ParameterizedTruncatedNormal`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Reference binding to null in `ParameterizedTruncatedNormal`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-205
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-496
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-694
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Reference binding to null in `ParameterizedTruncatedNormal`
CVEs:CVE-2021-29568
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger undefined behavior by binding to null pointer in `tf.raw_ops.ParameterizedTruncatedNormal`. This is because the implementation(https://github.com/tensorflow/...
CVEs:CVE-2021-29568
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-694
CVEs:CVE-2021-29568
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Segfault in `tf.raw_ops.SparseCountSparseOutput`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Segfault in `tf.raw_ops.SparseCountSparseOutput`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-256
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-547
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-745
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-745
CVEs:CVE-2021-29619
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. Passing invalid arguments (e.g., discovered via fuzzing) to `tf.raw_ops.SparseCountSparseOutput` results in segfault. The fix will be included in TensorFlow 2.5.0. We will also cher...
CVEs:CVE-2021-29619
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Segfault in `tf.raw_ops.SparseCountSparseOutput`
CVEs:CVE-2021-29619
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Integer overflow in TFLite concatentation
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Integer overflow in TFLite concatentation
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-238
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-529
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-727
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Integer overflow in TFLite concatentation
CVEs:CVE-2021-29601
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. The TFLite implementation of concatenation is vulnerable to an integer overflow issue(https://github.com/tensorflow/tensorflow/blob/7b7352a724b690b11bfaae2cd54bc3907daf6285/tensorfl...
CVEs:CVE-2021-29601
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-727
CVEs:CVE-2021-29601
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in TFLite's implementation of hashtable lookup
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in TFLite's implementation of hashtable lookup
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in TFLite's implementation of `DepthwiseConv`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in TFLite's implementation of `DepthwiseConv`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CHECK-fail due to integer overflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CHECK-fail due to integer overflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Segfault in `CTCBeamSearchDecoder`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Segfault in `CTCBeamSearchDecoder`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Undefined behavior and `CHECK`-fail in `FractionalMaxPoolGrad`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Undefined behavior and `CHECK`-fail in `FractionalMaxPoolGrad`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `MaxPoolGradWithArgmax`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `MaxPoolGradWithArgmax`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Reference binding to nullptr in `SdcaOptimizer`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Reference binding to nullptr in `SdcaOptimizer`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Lack of validation in `SparseDenseCwiseMul`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Lack of validation in `SparseDenseCwiseMul`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Null pointer dereference in `SparseFillEmptyRows`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Null pointer dereference in `SparseFillEmptyRows`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Null pointer dereference in `EditDistance`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Null pointer dereference in `EditDistance`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CHECK-fail in `tf.raw_ops.RFFT`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CHECK-fail in `tf.raw_ops.RFFT`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CHECK-fail in `tf.raw_ops.IRFFT`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CHECK-fail in `tf.raw_ops.IRFFT`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CHECK-fail in `LoadAndRemapMatrix`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CHECK-fail in `LoadAndRemapMatrix`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `SparseMatMul`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `SparseMatMul`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `Reverse`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `Reverse`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `FusedBatchNorm`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `FusedBatchNorm`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `DenseCountSparseOutput`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `DenseCountSparseOutput`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CHECK-failure in `UnsortedSegmentJoin`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CHECK-failure in `UnsortedSegmentJoin`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `FractionalAvgPool`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `FractionalAvgPool`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `QuantizedAdd`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `QuantizedAdd`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `QuantizedBatchNormWithGlobalNormalization`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `QuantizedBatchNormWithGlobalNormalization`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap out of bounds in `QuantizedBatchNormWithGlobalNormalization`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap out of bounds in `QuantizedBatchNormWithGlobalNormalization`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `SparseTensorToCSRSparseMatrix`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `SparseTensorToCSRSparseMatrix`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CHECK-fail in `CTCGreedyDecoder`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CHECK-fail in `CTCGreedyDecoder`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Null pointer dereference in `StringNGrams`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Null pointer dereference in `StringNGrams`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Segfault in tf.raw_ops.ImmutableConst
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Segfault in tf.raw_ops.ImmutableConst
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in `Conv2DBackpropFilter`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in `Conv2DBackpropFilter`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CHECK-fail in SparseConcat
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CHECK-fail in SparseConcat
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CHECK-fail in tf.raw_ops.EncodePng
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CHECK-fail in tf.raw_ops.EncodePng
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `QuantizedMul`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `QuantizedMul`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `QuantizedConv2D`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `QuantizedConv2D`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `Conv2DBackpropFilter`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `Conv2DBackpropFilter`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CHECK-fail in AddManySparseToTensorsMap
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CHECK-fail in AddManySparseToTensorsMap
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `Conv3DBackprop*`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `Conv3DBackprop*`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Segfault in SparseCountSparseOutput
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Segfault in SparseCountSparseOutput
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CHECK-fail in SparseCross due to type confusion
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CHECK-fail in SparseCross due to type confusion
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in `Conv3D`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in `Conv3D`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-154
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-156
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-158
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-159
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-160
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-161
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-164
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-165
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-168
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-171
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-175
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-176
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-178
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-180
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-182
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-184
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-185
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-186
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-187
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-189
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-192
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-193
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-194
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-198
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-199
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-200
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-201
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-202
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-204
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-209
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-210
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-217
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-218
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-221
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-239
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-241
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-445
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-447
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-449
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-450
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-451
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-452
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-455
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-456
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-459
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-462
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | — | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-466
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-467
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-469
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-471
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-473
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-475
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-476
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-477
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-478
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-480
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-483
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-484
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-485
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-489
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-490
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-491
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-492
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-493
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-495
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-500
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-501
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-508
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-509
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-512
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-530
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-532
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-643
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-645
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-647
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-648
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-649
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-650
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-653
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-654
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-657
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-660
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-664
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-665
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-667
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-669
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-671
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-673
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-674
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-675
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-676
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-678
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-681
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-682
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-683
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-687
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-688
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-689
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-690
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-691
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-693
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-698
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-699
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-706
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-707
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-710
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-728
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-730
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-643
CVEs:CVE-2021-29517
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. A malicious user could trigger a division by 0 in `Conv3D` implementation. The implementation(https://github.com/tensorflow/tensorflow/blob/42033603003965bffac51ae171b51801565e002d/...
CVEs:CVE-2021-29517
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Division by zero in `Conv3D`
CVEs:CVE-2021-29517
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. The API of `tf.raw_ops.SparseCross` allows combinations which would result in a `CHECK`-failure and denial of service. This is because the implementation(https://github.com/tensorfl...
CVEs:CVE-2021-29519
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-645
CVEs:CVE-2021-29519
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CHECK-fail in SparseCross due to type confusion
CVEs:CVE-2021-29519
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-647
CVEs:CVE-2021-29521
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. Specifying a negative dense shape in `tf.raw_ops.SparseCountSparseOutput` results in a segmentation fault being thrown out from the standard library as `std::vector` invariants are ...
CVEs:CVE-2021-29521
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Segfault in SparseCountSparseOutput
CVEs:CVE-2021-29521
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `Conv3DBackprop*`
CVEs:CVE-2021-29522
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. The `tf.raw_ops.Conv3DBackprop*` operations fail to validate that the input tensors are not empty. In turn, this would result in a division by 0. This is because the implementation(...
CVEs:CVE-2021-29522
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-648
CVEs:CVE-2021-29522
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CHECK-fail in AddManySparseToTensorsMap
CVEs:CVE-2021-29523
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-649
CVEs:CVE-2021-29523
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a denial of service via a `CHECK`-fail in `tf.raw_ops.AddManySparseToTensorsMap`. This is because the implementation(https://github.com/tensorflow/tensorflow...
CVEs:CVE-2021-29523
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a division by 0 in `tf.raw_ops.Conv2DBackpropFilter`. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/496c2630e51c1a478f095b...
CVEs:CVE-2021-29524
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Division by 0 in `Conv2DBackpropFilter`
CVEs:CVE-2021-29524
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-650
CVEs:CVE-2021-29524
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-728
CVEs:CVE-2021-29602
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. The implementation of the `DepthwiseConv` TFLite operator is vulnerable to a division by zero error(https://github.com/tensorflow/tensorflow/blob/1a8e885b864c818198a5b2c0cbbeca5a1e8...
CVEs:CVE-2021-29602
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Division by zero in TFLite's implementation of `DepthwiseConv`
CVEs:CVE-2021-29602
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in TFLite's implementation of hashtable lookup
CVEs:CVE-2021-29604
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. The TFLite implementation of hashtable lookup is vulnerable to a division by zero error(https://github.com/tensorflow/tensorflow/blob/1a8e885b864c818198a5b2c0cbbeca5a1e833bc8/tensor...
CVEs:CVE-2021-29604
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-730
CVEs:CVE-2021-29604
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service via a FPE runtime error in `tf.raw_ops.FusedBatchNorm`. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/82...
CVEs:CVE-2021-29555
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Division by 0 in `FusedBatchNorm`
CVEs:CVE-2021-29555
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-681
CVEs:CVE-2021-29555
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-682
CVEs:CVE-2021-29556
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service via a FPE runtime error in `tf.raw_ops.Reverse`. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/36229ea9e...
CVEs:CVE-2021-29556
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Division by 0 in `Reverse`
CVEs:CVE-2021-29556
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `SparseMatMul`
CVEs:CVE-2021-29557
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-683
CVEs:CVE-2021-29557
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service via a FPE runtime error in `tf.raw_ops.SparseMatMul`. The division by 0 occurs deep in Eigen code because the `b` tensor is empty. The fix ...
CVEs:CVE-2021-29557
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-687
CVEs:CVE-2021-29561
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service by exploiting a `CHECK`-failure coming from `tf.raw_ops.LoadAndRemapMatrix`. This is because the implementation(https://github.com/tensorfl...
CVEs:CVE-2021-29561
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
CHECK-fail in `LoadAndRemapMatrix`
CVEs:CVE-2021-29561
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service by exploiting a `CHECK`-failure coming from the implementation of `tf.raw_ops.IRFFT`. The fix will be included in TensorFlow 2.5.0. We will...
CVEs:CVE-2021-29562
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-688
CVEs:CVE-2021-29562
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CHECK-fail in `tf.raw_ops.IRFFT`
CVEs:CVE-2021-29562
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-689
CVEs:CVE-2021-29563
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CHECK-fail in `tf.raw_ops.RFFT`
CVEs:CVE-2021-29563
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service by exploiting a `CHECK`-failure coming from the implementation of `tf.raw_ops.RFFT`. Eigen code operating on an empty matrix can trigger on...
CVEs:CVE-2021-29563
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Null pointer dereference in `EditDistance`
CVEs:CVE-2021-29564
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a null pointer dereference in the implementation of `tf.raw_ops.EditDistance`. This is because the implementation(https://github.com/tensorflow/tensorflow/bl...
CVEs:CVE-2021-29564
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-690
CVEs:CVE-2021-29564
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-691
CVEs:CVE-2021-29565
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a null pointer dereference in the implementation of `tf.raw_ops.SparseFillEmptyRows`. This is because of missing validation(https://github.com/tensorflow/ten...
CVEs:CVE-2021-29565
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Null pointer dereference in `SparseFillEmptyRows`
CVEs:CVE-2021-29565
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Lack of validation in `SparseDenseCwiseMul`
CVEs:CVE-2021-29567
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-693
CVEs:CVE-2021-29567
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. Due to lack of validation in `tf.raw_ops.SparseDenseCwiseMul`, an attacker can trigger denial of service via `CHECK`-fails or accesses to outside the bounds of heap allocated data. ...
CVEs:CVE-2021-29567
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Reference binding to nullptr in `SdcaOptimizer`
CVEs:CVE-2021-29572
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-698
CVEs:CVE-2021-29572
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.SdcaOptimizer` triggers undefined behavior due to dereferencing a null pointer. The implementation(https://github.com/tensorflow/tensorflow/blob/60...
CVEs:CVE-2021-29572
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.MaxPoolGradWithArgmax` is vulnerable to a division by 0. The implementation(https://github.com/tensorflow/tensorflow/blob/279bab6efa22752a2827621b7...
CVEs:CVE-2021-29573
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-699
CVEs:CVE-2021-29573
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `MaxPoolGradWithArgmax`
CVEs:CVE-2021-29573
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Undefined behavior and `CHECK`-fail in `FractionalMaxPoolGrad`
CVEs:CVE-2021-29580
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-706
CVEs:CVE-2021-29580
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.FractionalMaxPoolGrad` triggers an undefined behavior if one of the input tensors is empty. The code is also vulnerable to a denial of service atta...
CVEs:CVE-2021-29580
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Segfault in `CTCBeamSearchDecoder`
CVEs:CVE-2021-29581
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. Due to lack of validation in `tf.raw_ops.CTCBeamSearchDecoder`, an attacker can trigger denial of service via segmentation faults. The implementation(https://github.com/tensorflow/t...
CVEs:CVE-2021-29581
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-707
CVEs:CVE-2021-29581
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a denial of service via a `CHECK`-fail in caused by an integer overflow in constructing a new tensor shape. This is because the implementation(https://github...
CVEs:CVE-2021-29584
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
CHECK-fail due to integer overflow
CVEs:CVE-2021-29584
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-710
CVEs:CVE-2021-29584
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-191
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-482
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-680
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a division by 0 in `tf.raw_ops.QuantizedConv2D`. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/00e9a4d67d76703fa1aee33dac5...
CVEs:CVE-2021-29527
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Division by 0 in `QuantizedConv2D`
CVEs:CVE-2021-29527
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-653
CVEs:CVE-2021-29527
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a division by 0 in `tf.raw_ops.QuantizedMul`. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/55900e961ed4a23b43839202491215...
CVEs:CVE-2021-29528
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-654
CVEs:CVE-2021-29528
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `QuantizedMul`
CVEs:CVE-2021-29528
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-657
CVEs:CVE-2021-29531
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a `CHECK` fail in PNG encoding by providing an empty input tensor as the pixel data. This is because the implementation(https://github.com/tensorflow/tensorf...
CVEs:CVE-2021-29531
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
CHECK-fail in tf.raw_ops.EncodePng
CVEs:CVE-2021-29531
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CHECK-fail in SparseConcat
CVEs:CVE-2021-29534
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a denial of service via a `CHECK`-fail in `tf.raw_ops.SparseConcat`. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/b432a38...
CVEs:CVE-2021-29534
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-660
CVEs:CVE-2021-29534
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by zero in `Conv2DBackpropFilter`
CVEs:CVE-2021-29538
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-664
CVEs:CVE-2021-29538
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a division by zero to occur in `Conv2DBackpropFilter`. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/1b0296c3b8dd9bd948f924a...
CVEs:CVE-2021-29538
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-665
CVEs:CVE-2021-29539
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. Calling `tf.raw_ops.ImmutableConst`(https://www.tensorflow.org/api_docs/python/tf/raw_ops/ImmutableConst) with a `dtype` of `tf.resource` or `tf.variant` results in a segfault in th...
CVEs:CVE-2021-29539
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Segfault in tf.raw_ops.ImmutableConst
CVEs:CVE-2021-29539
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-667
CVEs:CVE-2021-29541
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Null pointer dereference in `StringNGrams`
CVEs:CVE-2021-29541
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a dereference of a null pointer in `tf.raw_ops.StringNGrams`. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/1cdd4da1428221...
CVEs:CVE-2021-29541
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-669
CVEs:CVE-2021-29543
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a denial of service via a `CHECK`-fail in `tf.raw_ops.CTCGreedyDecoder`. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/161...
CVEs:CVE-2021-29543
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
CHECK-fail in `CTCGreedyDecoder`
CVEs:CVE-2021-29543
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-671
CVEs:CVE-2021-29545
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in `SparseTensorToCSRSparseMatrix`
CVEs:CVE-2021-29545
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a denial of service via a `CHECK`-fail in converting sparse tensors to CSR Sparse matrices. This is because the implementation(https://github.com/tensorflow/...
CVEs:CVE-2021-29545
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a segfault and denial of service via accessing data outside of bounds in `tf.raw_ops.QuantizedBatchNormWithGlobalNormalization`. This is because the implementa...
CVEs:CVE-2021-29547
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-673
CVEs:CVE-2021-29547
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap out of bounds in `QuantizedBatchNormWithGlobalNormalization`
CVEs:CVE-2021-29547
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `QuantizedBatchNormWithGlobalNormalization`
CVEs:CVE-2021-29548
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-674
CVEs:CVE-2021-29548
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a runtime division by zero error and denial of service in `tf.raw_ops.QuantizedBatchNormWithGlobalNormalization`. This is because the implementation(https://gi...
CVEs:CVE-2021-29548
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a runtime division by zero error and denial of service in `tf.raw_ops.QuantizedBatchNormWithGlobalNormalization`. This is because the implementation(https://gi...
CVEs:CVE-2021-29549
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Division by 0 in `QuantizedAdd`
CVEs:CVE-2021-29549
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-675
CVEs:CVE-2021-29549
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-676
CVEs:CVE-2021-29550
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `FractionalAvgPool`
CVEs:CVE-2021-29550
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a runtime division by zero error and denial of service in `tf.raw_ops.FractionalAvgPool`. This is because the implementation(https://github.com/tensorflow/tens...
CVEs:CVE-2021-29550
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
CHECK-failure in `UnsortedSegmentJoin`
CVEs:CVE-2021-29552
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service by controlling the values of `num_segments` tensor argument for `UnsortedSegmentJoin`. This is because the implementation(https://github.co...
CVEs:CVE-2021-29552
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-678
CVEs:CVE-2021-29552
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Division by 0 in `DenseCountSparseOutput`
CVEs:CVE-2021-29554
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-680
CVEs:CVE-2021-29554
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service via a FPE runtime error in `tf.raw_ops.DenseCountSparseOutput`. This is because the implementation(https://github.com/tensorflow/tensorflow...
CVEs:CVE-2021-29554
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
In getMinimalSize of PipBoundsAlgorithm.java, there is a possible bypass of restrictions on background processes due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interact...
CVEs:CVE-2021-0485
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0485
ASB-A-179040600
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
Heap out of bounds read in `MaxPoolGradWithArgmax`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap out of bounds read in `MaxPoolGradWithArgmax`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2021-207
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2021-498
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2021-696
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap out of bounds read in `MaxPoolGradWithArgmax`
CVEs:CVE-2021-29570
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.MaxPoolGradWithArgmax` can cause reads outside of bounds of heap allocated data if attacker supplies specially crafted inputs. The implementation(h...
CVEs:CVE-2021-29570
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2021-696
CVEs:CVE-2021-29570
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
ASB-A-179039763
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
CVEs:CVE-2021-0477
In notifyScreenshotError of ScreenshotNotificationsController.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not ne...
CVEs:CVE-2021-0477
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0490
In memory management driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product...
CVEs:CVE-2021-0490
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-183464868
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-172354397
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In BinderDiedCallback of MediaCodec.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Pro...
CVEs:CVE-2021-0482
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0482
In readVector of IMediaPlayer.cpp, there is a possible read of uninitialized heap data due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exp...
CVEs:CVE-2021-0484
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0484
CVEs:CVE-2021-0492
In memory management driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product...
CVEs:CVE-2021-0492
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0493
In memory management driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product...
CVEs:CVE-2021-0493
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0495
In memory management driver, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: An...
CVEs:CVE-2021-0495
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-183459078
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-183459083
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-183461317
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2021-0489
In memory management driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product...
CVEs:CVE-2021-0489
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0494
In memory management driver, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: A...
CVEs:CVE-2021-0494
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-183461318
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-183464866
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In Chromecast bootROM, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege in the bootloader, with physical USB access, with no additional execution privileges needed. User interact...
CVEs:CVE-2021-0467
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0467
ASB-A-174490700
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In memory management driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi...
CVEs:CVE-2021-0496
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0496
In memory management driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi...
CVEs:CVE-2021-0497
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0497
CVEs:CVE-2021-0498
In memory management driver, there is a possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...
CVEs:CVE-2021-0498
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-183461320
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-183461321
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-183467912
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2021-0491
In memory management driver, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation...
CVEs:CVE-2021-0491
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-183461315
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2021-0487
In onCreate of CalendarDebugActivity.java, there is a possible way to export calendar data to the sdcard without user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. Us...
CVEs:CVE-2021-0487
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Kubernetes Privilege Escalation
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
Kubernetes Privilege Escalation
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
Improper Input Validation in libseccomp-golang
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| seccomp/libseccomp-golang | affected | github.com | github.com/seccomp/libseccomp-golang | — |
Improper Input Validation in libseccomp-golang
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| seccomp/libseccomp-golang | affected | github.com | github.com/seccomp/libseccomp-golang | — |
Import of incorrectly embargoed keys could cause early publication
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google/exposure-notifications-server | affected | github.com | github.com/google/exposure-notifications-server | — |
Import of incorrectly embargoed keys could cause early publication
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| github.com/google/exposure-notifications-server | affected | Go | github.com/google/exposure-notifications-server | — |
| google/exposure-notifications-server | affected | github.com | github.com/google/exposure-notifications-server | — |
| google/exposure-notifications-server | affected | github.com | github.com/google/exposure-notifications-server | — |
protobuf-c bug fix and enhancement update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf-c | affected | AlmaLinux:8 | protobuf-c | — |
| protobuf-c-compiler | affected | AlmaLinux:8 | protobuf-c-compiler | — |
| protobuf-c-devel | affected | AlmaLinux:8 | protobuf-c-devel | — |
maven:3.6 bug fix and enhancement update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aopalliance | affected | AlmaLinux:8 | aopalliance | — |
| apache-commons-cli | affected | AlmaLinux:8 | apache-commons-cli | — |
| apache-commons-codec | affected | AlmaLinux:8 | apache-commons-codec | — |
| apache-commons-io | affected | AlmaLinux:8 | apache-commons-io | — |
| apache-commons-lang3 | affected | AlmaLinux:8 | apache-commons-lang3 | — |
| atinject | affected | AlmaLinux:8 | atinject | — |
| cdi-api | affected | AlmaLinux:8 | cdi-api | — |
| geronimo-annotation | affected | AlmaLinux:8 | geronimo-annotation | — |
| google-guice | affected | AlmaLinux:8 | google-guice | — |
| guava | affected | AlmaLinux:8 | guava | — |
| httpcomponents-core | affected | AlmaLinux:8 | httpcomponents-core | — |
| jansi | affected | AlmaLinux:8 | jansi | — |
| jcl-over-slf4j | affected | AlmaLinux:8 | jcl-over-slf4j | — |
| jsoup | affected | AlmaLinux:8 | jsoup | — |
| jsr-305 | affected | AlmaLinux:8 | jsr-305 | — |
| maven-resolver | affected | AlmaLinux:8 | maven-resolver | — |
| maven-shared-utils | affected | AlmaLinux:8 | maven-shared-utils | — |
| maven-wagon | affected | AlmaLinux:8 | maven-wagon | — |
| plexus-cipher | affected | AlmaLinux:8 | plexus-cipher | — |
| plexus-classworlds | affected | AlmaLinux:8 | plexus-classworlds | — |
| plexus-containers-component-annotations | affected | AlmaLinux:8 | plexus-containers-component-annotations | — |
| plexus-interpolation | affected | AlmaLinux:8 | plexus-interpolation | — |
| plexus-sec-dispatcher | affected | AlmaLinux:8 | plexus-sec-dispatcher | — |
| plexus-utils | affected | AlmaLinux:8 | plexus-utils | — |
| sisu | affected | AlmaLinux:8 | sisu | — |
| slf4j | affected | AlmaLinux:8 | slf4j | — |
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.