Google Security Advisories · August 2021 — Google Security Advisories
676 advisories 436 CVEs 16 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2021-08. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 16 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2021-30860

Project ZeroExploitedCISA KEV listed2021-08-24

An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

CVEs:CVE-2021-30860

Upstream advisory

CVE-2021-30860

GoogleExploitedCISA KEV listedCRITICAL2021-08-24

An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code exe...

CVEs:CVE-2021-30860

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
mac_os_x affected apple
poppler affected freedesktop
watchos affected apple
xpdf affected xpdfreader
Upstream advisory

CVE-2021-36948

GoogleExploitedCISA KEV listedCRITICAL2021-08-11

Windows Update Medic Service Elevation of Privilege Vulnerability

CVEs:CVE-2021-36948

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1809 affected microsoft
windows_10_1909 affected microsoft
windows_10_2004 affected microsoft
windows_10_20h2 affected microsoft
windows_10_21h1 affected microsoft
windows_server_2004 affected microsoft
windows_server_2019 affected microsoft
windows_server_20h2 affected microsoft
Upstream advisory

CVE-2021-30883

GoogleExploitedCISA KEV listedCRITICAL2021-08-24

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 15.0.2 and iPadOS 15.0.2, macOS Monterey 12.0.1, iOS 14.8.1 and iPadOS 14.8.1, tvOS 15.1, watchOS 8.1, macOS Big Sur 11.6.1. An application may be able to...

CVEs:CVE-2021-30883

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2021-30883

Project ZeroExploitedCISA KEV listed2021-08-24

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 15.0.2 and iPadOS 15.0.2, macOS Monterey 12.0.1, iOS 14.8.1 and iPadOS 14.8.1, tvOS 15.1, watchOS 8.1, macOS Big Sur 11.6.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..

CVEs:CVE-2021-30883

Upstream advisory

CVE-2021-30858

GoogleExploitedCISA KEV listedCRITICAL2021-08-24

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that ...

CVEs:CVE-2021-30858

Affected products

ProductStatusVendorPackageEcosystem
debian_linux affected debian
fedora affected fedoraproject
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2021-30858

Project ZeroExploitedCISA KEV listed2021-08-24

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

CVEs:CVE-2021-30858

Upstream advisory

DEBIAN-CVE-2021-30563

Open SourceExploitedCISA KEV listedHIGH2021-08-03

DEBIAN-CVE-2021-30563

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-30869

GoogleExploitedCISA KEV listedCRITICAL2021-08-24

A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 12.5.5, iOS 14.4 and iPadOS 14.4, macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, Security Update 2021-006 Catalina. A...

CVEs:CVE-2021-30869

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
mac_os_x affected apple
Upstream advisory

CVE-2021-30869

Project ZeroExploitedCISA KEV listed2021-08-24

A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 12.5.5, iOS 14.4 and iPadOS 14.4, macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, Security Update 2021-006 Catalina. A malicious application may be able to execute arbitrary code with kernel privileges. Apple is aware of reports that an exploit for this issue exists in the wild.

CVEs:CVE-2021-30869

Upstream advisory

CVE-2021-31010

GoogleExploitedCISA KEV listedHIGH2021-08-24

A deserialization issue was addressed through improved validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 12.5.5, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. A sandboxed process may be able to circumvent sandbox ...

CVEs:CVE-2021-31010

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
mac_os_x affected apple
watchos affected apple
Upstream advisory

CVE-2021-31010

Project ZeroExploitedCISA KEV listed2021-08-24

A deserialization issue was addressed through improved validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 12.5.5, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. A sandboxed process may be able to circumvent sandbox restrictions. Apple was aware of a report that this issue may have been actively exploited at the time of release..

CVEs:CVE-2021-31010

Upstream advisory

CVE-2021-30983

GoogleExploitedCISA KEV listedCRITICAL2021-08-24

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 15.2 and iPadOS 15.2. An application may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2021-30983

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2021-30983

Project ZeroExploitedCISA KEV listed2021-08-24

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 15.2 and iPadOS 15.2. An application may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2021-30983

Upstream advisory

openSUSE-SU-2021:1162-1

Open SourceWeaponized exploitCRITICAL2021-08-17

Security update for SUSE Manager Client Tools

Affected products

ProductStatusVendorPackageEcosystem
ansible affected openSUSE:Leap 15.2 ansible
dracut-saltboot affected openSUSE:Leap 15.2 dracut-saltboot
golang-github-prometheus-prometheus affected openSUSE:Leap 15.2 golang-github-prometheus-prometheus
Upstream advisory

SUSE-SU-2021:2675-1

Open SourceWeaponized exploitCRITICAL2021-08-12

Security update for SUSE Manager Client Tools

Affected products

ProductStatusVendorPackageEcosystem
ansible affected SUSE:Manager Client Tools 15 ansible
dracut-saltboot affected SUSE:Manager Client Tools 15 dracut-saltboot
golang-github-prometheus-prometheus affected SUSE:Manager Client Tools 15 golang-github-prometheus-prometheus
mgr-cfg affected SUSE:Manager Client Tools 15 mgr-cfg
mgr-custom-info affected SUSE:Manager Client Tools 15 mgr-custom-info
mgr-osad affected SUSE:Manager Client Tools 15 mgr-osad
mgr-push affected SUSE:Manager Client Tools 15 mgr-push
mgr-virtualization affected SUSE:Manager Client Tools 15 mgr-virtualization
rhnlib affected SUSE:Manager Client Tools 15 rhnlib
spacecmd affected SUSE:Manager Client Tools 15 spacecmd
spacewalk-client-tools affected SUSE:Manager Client Tools 15 spacewalk-client-tools
spacewalk-koan affected SUSE:Manager Client Tools 15 spacewalk-koan
spacewalk-oscap affected SUSE:Manager Client Tools 15 spacewalk-oscap
suseRegisterInfo affected SUSE:Manager Client Tools 15 suseRegisterInfo
uyuni-common-libs affected SUSE:Manager Client Tools 15 uyuni-common-libs
Upstream advisory

SUSE-SU-2021:2673-1

Open SourceWeaponized exploitHIGH2021-08-12

Security update for SUSE Manager Client Tools

Affected products

ProductStatusVendorPackageEcosystem
golang-github-prometheus-prometheus affected SUSE:Manager Client Tools 12 golang-github-prometheus-prometheus
grafana affected SUSE:Manager Client Tools 12 grafana
mgr-cfg affected SUSE:Manager Client Tools 12 mgr-cfg
mgr-custom-info affected SUSE:Manager Client Tools 12 mgr-custom-info
mgr-osad affected SUSE:Manager Client Tools 12 mgr-osad
mgr-push affected SUSE:Manager Client Tools 12 mgr-push
mgr-virtualization affected SUSE:Manager Client Tools 12 mgr-virtualization
rhnlib affected SUSE:Manager Client Tools 12 rhnlib
spacecmd affected SUSE:Manager Client Tools 12 spacecmd
spacewalk-client-tools affected SUSE:Manager Client Tools 12 spacewalk-client-tools
spacewalk-koan affected SUSE:Manager Client Tools 12 spacewalk-koan
spacewalk-oscap affected SUSE:Manager Client Tools 12 spacewalk-oscap
suseRegisterInfo affected SUSE:Manager Client Tools 12 suseRegisterInfo
uyuni-common-libs affected SUSE:Manager Client Tools 12 uyuni-common-libs
Upstream advisory

openSUSE-SU-2021:2664-1

Open SourceWeaponized exploitCRITICAL2021-08-12

Security update for golang-github-prometheus-prometheus

Affected products

ProductStatusVendorPackageEcosystem
golang-github-prometheus-prometheus affected openSUSE:Leap 15.3 golang-github-prometheus-prometheus
Upstream advisory

SUSE-SU-2021:2664-1

Open SourceWeaponized exploitCRITICAL2021-08-12

Security update for golang-github-prometheus-prometheus

Affected products

ProductStatusVendorPackageEcosystem
golang-github-prometheus-prometheus affected SUSE:Enterprise Storage 6 golang-github-prometheus-prometheus
Upstream advisory

GHSA-7774-7vr3-cc8j

Open SourceActive exploitation (sightings)CRITICAL2021-08-30

Authorization Policy Bypass Due to Case Insensitive Host Comparison

Affected products

ProductStatusVendorPackageEcosystem
cert-manager-istio-csr affected wolfi cert-manager-istio-csr
cert-manager-istio-csr affected chainguard cert-manager-istio-csr
cert-manager-istio-csr-fips affected chainguard cert-manager-istio-csr-fips
istio affected istio.io istio.io/istio
istio-cni-1.21 affected wolfi istio-cni-1.21
istio-cni-1.21 affected chainguard istio-cni-1.21
istio-cni-1.22 affected chainguard istio-cni-1.22
istio-cni-1.22 affected wolfi istio-cni-1.22
istio-fips-1.21 affected chainguard istio-fips-1.21
istio-operator-1.20 affected chainguard istio-operator-1.20
istio-operator-1.20 affected wolfi istio-operator-1.20
istio-operator-1.21 affected chainguard istio-operator-1.21
istio-operator-1.21 affected wolfi istio-operator-1.21
istio-operator-1.22 affected wolfi istio-operator-1.22
istio-operator-1.22 affected chainguard istio-operator-1.22
istio-pilot-agent-1.21 affected wolfi istio-pilot-agent-1.21
istio-pilot-agent-1.21 affected chainguard istio-pilot-agent-1.21
istio-pilot-agent-1.22 affected wolfi istio-pilot-agent-1.22
istio-pilot-agent-1.22 affected chainguard istio-pilot-agent-1.22
istio-pilot-discovery-1.21 affected wolfi istio-pilot-discovery-1.21
istio-pilot-discovery-1.21 affected chainguard istio-pilot-discovery-1.21
istio-pilot-discovery-1.22 affected chainguard istio-pilot-discovery-1.22
istio-pilot-discovery-1.22 affected wolfi istio-pilot-discovery-1.22
kgateway-2.3 affected chainguard kgateway-2.3
kgateway-2.4 affected chainguard kgateway-2.4
kgateway-fips-2.3 affected chainguard kgateway-fips-2.3
kgateway-fips-2.4 affected chainguard kgateway-fips-2.4
Upstream advisory

GHSA-7774-7vr3-cc8j

Open SourceActive exploitation (sightings)CRITICAL2021-08-30

Authorization Policy Bypass Due to Case Insensitive Host Comparison

Affected products

ProductStatusVendorPackageEcosystem
istio affected istio.io istio.io/istio
Upstream advisory

CVE-2021-39155

Open SourceActive exploitation (sightings)CRITICAL2021-08-24

Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies and aggregate telemetry data. According to [RFC 4343](https://datatracker.ietf.org/doc/html/rfc4343), Is...

CVEs:CVE-2021-39155

Affected products

ProductStatusVendorPackageEcosystem
istio affected istio
Upstream advisory

CVE-2021-39155

Open SourceActive exploitation (sightings)HIGH2021-08-24

Authorization Policy Bypass Due to Case Insensitive Host Comparison

CVEs:CVE-2021-39155

Affected products

ProductStatusVendorPackageEcosystem
istio affected istio.io istio.io/istio
Upstream advisory

GHSA-hqxw-mm44-gc4r

Open SourceActive exploitation (sightings)HIGH2021-08-30

Istio Fragments in Path May Lead to Authorization Policy Bypass

Affected products

ProductStatusVendorPackageEcosystem
istio affected istio.io istio.io/istio
Upstream advisory

GHSA-hqxw-mm44-gc4r

Open SourceActive exploitation (sightings)HIGH2021-08-30

Istio Fragments in Path May Lead to Authorization Policy Bypass

Affected products

ProductStatusVendorPackageEcosystem
cert-manager-istio-csr affected chainguard cert-manager-istio-csr
cert-manager-istio-csr affected wolfi cert-manager-istio-csr
cert-manager-istio-csr-fips affected chainguard cert-manager-istio-csr-fips
istio affected istio.io istio.io/istio
istio-cni-1.21 affected wolfi istio-cni-1.21
istio-cni-1.21 affected chainguard istio-cni-1.21
istio-cni-1.22 affected chainguard istio-cni-1.22
istio-cni-1.22 affected wolfi istio-cni-1.22
istio-fips-1.21 affected chainguard istio-fips-1.21
istio-operator-1.20 affected wolfi istio-operator-1.20
istio-operator-1.20 affected chainguard istio-operator-1.20
istio-operator-1.21 affected wolfi istio-operator-1.21
istio-operator-1.21 affected chainguard istio-operator-1.21
istio-operator-1.22 affected chainguard istio-operator-1.22
istio-operator-1.22 affected wolfi istio-operator-1.22
istio-pilot-agent-1.21 affected wolfi istio-pilot-agent-1.21
istio-pilot-agent-1.21 affected chainguard istio-pilot-agent-1.21
istio-pilot-agent-1.22 affected wolfi istio-pilot-agent-1.22
istio-pilot-agent-1.22 affected chainguard istio-pilot-agent-1.22
istio-pilot-discovery-1.21 affected chainguard istio-pilot-discovery-1.21
istio-pilot-discovery-1.21 affected wolfi istio-pilot-discovery-1.21
istio-pilot-discovery-1.22 affected wolfi istio-pilot-discovery-1.22
istio-pilot-discovery-1.22 affected chainguard istio-pilot-discovery-1.22
kgateway-2.3 affected chainguard kgateway-2.3
kgateway-2.4 affected chainguard kgateway-2.4
kgateway-fips-2.3 affected chainguard kgateway-fips-2.3
kgateway-fips-2.4 affected chainguard kgateway-fips-2.4
Upstream advisory

CVE-2021-39156

Open SourceActive exploitation (sightings)HIGH2021-08-24

Istio Fragments in Path May Lead to Authorization Policy Bypass

CVEs:CVE-2021-39156

Affected products

ProductStatusVendorPackageEcosystem
istio affected istio.io istio.io/istio
Upstream advisory

CVE-2021-39156

Open SourceActive exploitation (sightings)CRITICAL2021-08-24

Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies and aggregate telemetry data. Istio 1.11.0, 1.10.3 and below, and 1.9.7 and below contain a remotely exp...

CVEs:CVE-2021-39156

Affected products

ProductStatusVendorPackageEcosystem
istio affected istio
Upstream advisory

ASB-A-175037520

GoogleActive exploitation (sightings)2021-08-01

ASB-A-175037520

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

DEBIAN-CVE-2021-30560

Open SourcePoC exploitCRITICAL2021-08-03

DEBIAN-CVE-2021-30560

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
libxslt affected Debian:11 libxslt
libxslt affected Debian:12 libxslt
libxslt affected Debian:13 libxslt
libxslt affected Debian:14 libxslt
Upstream advisory

RLSA-2021:3076

Open SourcePoC exploitHIGH2021-08-10

Moderate: go-toolset:rhel8 security, bug fix, and enhancement update

Affected products

ProductStatusVendorPackageEcosystem
delve affected Rocky Linux:8 delve
golang affected Rocky Linux:8 golang
go-toolset affected Rocky Linux:8 go-toolset
Upstream advisory

openSUSE-SU-2021:1144-1

Open SourcePoC exploitCRITICAL2021-08-10

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP3 chromium
chromium affected openSUSE:Leap 15.3 chromium
Upstream advisory

openSUSE-SU-2021:1131-1

Open SourcePoC exploitCRITICAL2021-08-10

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.2 chromium
Upstream advisory

DEBIAN-CVE-2021-30573

Open SourcePoC exploitCRITICAL2021-08-03

DEBIAN-CVE-2021-30573

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

AZL-79056

Open SourcePoC exploitHIGH2021-08-07

CVE-2021-29923 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

CVE-2021-29923

GooglePoC exploitHIGH2021-08-07

Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation...

CVEs:CVE-2021-29923

Affected products

ProductStatusVendorPackageEcosystem
fedora affected fedoraproject
go affected golang
timesten_in-memory_database affected oracle
Upstream advisory

DEBIAN-CVE-2021-29923

Open SourcePoC exploitHIGH2021-08-07

DEBIAN-CVE-2021-29923

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
Upstream advisory

AZL-79084

Open SourcePoC exploitHIGH2021-08-02

CVE-2021-33196 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2021-33196

Open SourcePoC exploitHIGH2021-08-02

DEBIAN-CVE-2021-33196

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
Upstream advisory

AZL-78998

Open SourcePoC exploitCRITICAL2021-08-02

CVE-2021-33195 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2021-33195

Open SourcePoC exploitCRITICAL2021-08-02

DEBIAN-CVE-2021-33195

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
Upstream advisory

CVE-2021-36221

GooglePoC exploitMEDIUM2021-08-08

Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic upon an ErrAbortHandler abort.

CVEs:CVE-2021-36221

Affected products

ProductStatusVendorPackageEcosystem
debian_linux affected debian
fedora affected fedoraproject
go affected golang
scalance_lpe9403_firmware affected siemens
timesten_in-memory_database affected oracle
Upstream advisory

DEBIAN-CVE-2021-36221

Open SourcePoC exploitMEDIUM2021-08-08

DEBIAN-CVE-2021-36221

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
Upstream advisory

AZL-79094

Open SourcePoC exploitMEDIUM2021-08-02

CVE-2021-33197 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2021-33197

Open SourcePoC exploitMEDIUM2021-08-02

DEBIAN-CVE-2021-33197

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
Upstream advisory

ASB-A-171705902

GooglePoC exploitHIGH2021-08-01

ASB-A-171705902

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

ASB-A-175193031

GooglePoC exploitHIGH2021-08-01

ASB-A-175193031

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

GHSA-r6jx-9g48-2r5r

Open SourcePoC exploitCRITICAL2021-08-25

Arbitrary code execution due to YAML deserialization

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-r6jx-9g48-2r5r

Open SourcePoC exploitCRITICAL2021-08-25

Arbitrary code execution due to YAML deserialization

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-300

Open SourcePoC exploitHIGH2021-08-12

PYSEC-2021-300

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-591

Open SourcePoC exploitHIGH2021-08-12

PYSEC-2021-591

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-789

Open SourcePoC exploitHIGH2021-08-12

PYSEC-2021-789

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37678

Open SourcePoC exploitCRITICAL2021-08-12

Arbitrary code execution due to YAML deserialization

CVEs:CVE-2021-37678

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37678

Open SourcePoC exploitCRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions TensorFlow and Keras can be tricked to perform arbitrary code execution when deserializing a Keras model from YAML format. The [implementation](https://github.c...

CVEs:CVE-2021-37678

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37678

Open SourcePoC exploitCRITICAL2021-08-12

PYSEC-2021-789

CVEs:CVE-2021-37678

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

ASB-A-183188047

GooglePoC exploitNONE2021-08-01

ASB-A-183188047

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2021-0519

Open SourcePoC exploitHIGH2021-08-03

In BITSTREAM_FLUSH of ih264e_bitstream.h, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2021-0519

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0640

Open SourcePoC exploitHIGH2021-08-03

In noteAtomLogged of StatsdStats.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2021-0640

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0646

Open SourcePoC exploitHIGH2021-08-03

In sqlite3_str_vappendf of sqlite3.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege if the user can also inject a printf into a privileged process's SQL with no additional exe...

CVEs:CVE-2021-0646

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2021-30598

Open SourceCoalition ESS < 30%CRITICAL2021-08-26

DEBIAN-CVE-2021-30598

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

openSUSE-SU-2021:1180-1

Open SourceCoalition ESS < 30%CRITICAL2021-08-23

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP3 chromium
chromium affected openSUSE:Leap 15.3 chromium
Upstream advisory

openSUSE-SU-2021:1172-1

Open SourceCoalition ESS < 30%CRITICAL2021-08-20

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.2 chromium
Upstream advisory

CVE-2021-30598

GoogleCoalition ESS < 30%CRITICAL2021-08-17

Type confusion in V8 in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

CVEs:CVE-2021-30598

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-30582

Open SourceCoalition ESS < 30%MEDIUM2021-08-03

DEBIAN-CVE-2021-30582

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30599

Open SourceCoalition ESS < 30%CRITICAL2021-08-26

DEBIAN-CVE-2021-30599

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-30599

GoogleCoalition ESS < 30%CRITICAL2021-08-17

Type confusion in V8 in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

CVEs:CVE-2021-30599

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-30561

Open SourceCoalition ESS < 30%HIGH2021-08-03

DEBIAN-CVE-2021-30561

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30603

Open SourceCoalition ESS < 30%HIGH2021-08-26

DEBIAN-CVE-2021-30603

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:11 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-30603

GoogleCoalition ESS < 30%HIGH2021-08-17

Data race in WebAudio in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30603

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

GHSA-mh6h-f25p-98f8

Open SourceCoalition ESS < 30%HIGH2021-08-25

Uncontrolled memory consumption in protobuf

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected crates.io protobuf
Upstream advisory

GHSA-mh6h-f25p-98f8

Open SourceCoalition ESS < 30%HIGH2021-08-25

Uncontrolled memory consumption in protobuf

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected crates.io protobuf
Upstream advisory

DEBIAN-CVE-2021-33198

Open SourceCoalition ESS < 30%HIGH2021-08-02

DEBIAN-CVE-2021-33198

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
Upstream advisory

DEBIAN-CVE-2021-30590

Open SourceCoalition ESS < 30%CRITICAL2021-08-26

DEBIAN-CVE-2021-30590

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-30590

GoogleCoalition ESS < 30%CRITICAL2021-08-04

Heap buffer overflow in Bookmarks in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30590

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-30600

Open SourceCoalition ESS < 30%CRITICAL2021-08-26

DEBIAN-CVE-2021-30600

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-30600

GoogleCoalition ESS < 30%CRITICAL2021-08-17

Use after free in Printing in Google Chrome prior to 92.0.4515.159 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30600

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-30591

Open SourceCoalition ESS < 30%CRITICAL2021-08-26

DEBIAN-CVE-2021-30591

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30604

Open SourceCoalition ESS < 30%CRITICAL2021-08-26

DEBIAN-CVE-2021-30604

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-30604

GoogleCoalition ESS < 30%CRITICAL2021-08-17

Use after free in ANGLE in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30604

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30591

GoogleCoalition ESS < 30%CRITICAL2021-08-04

Use after free in File System API in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30591

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-30602

Open SourceCoalition ESS < 30%HIGH2021-08-26

DEBIAN-CVE-2021-30602

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-30602

GoogleCoalition ESS < 30%HIGH2021-08-17

Use after free in WebRTC in Google Chrome prior to 92.0.4515.159 allowed an attacker who convinced a user to visit a malicious website to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30602

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-30592

Open SourceCoalition ESS < 30%CRITICAL2021-08-26

DEBIAN-CVE-2021-30592

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-30592

GoogleCoalition ESS < 30%CRITICAL2021-08-04

Out of bounds write in Tab Groups in Google Chrome prior to 92.0.4515.131 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page.

CVEs:CVE-2021-30592

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-30588

Open SourceCoalition ESS < 30%HIGH2021-08-03

DEBIAN-CVE-2021-30588

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30593

Open SourceCoalition ESS < 30%HIGH2021-08-26

DEBIAN-CVE-2021-30593

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-30593

GoogleCoalition ESS < 30%HIGH2021-08-04

Out of bounds read in Tab Strip in Google Chrome prior to 92.0.4515.131 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted HTML page.

CVEs:CVE-2021-30593

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-30601

Open SourceCoalition ESS < 30%CRITICAL2021-08-26

DEBIAN-CVE-2021-30601

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-30601

GoogleCoalition ESS < 30%CRITICAL2021-08-17

Use after free in Extensions API in Google Chrome prior to 92.0.4515.159 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30601

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-30584

Open SourceCoalition ESS < 30%MEDIUM2021-08-03

DEBIAN-CVE-2021-30584

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30565

Open SourceCoalition ESS < 30%CRITICAL2021-08-03

DEBIAN-CVE-2021-30565

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-38783

Open SourceCoalition ESS < 30%HIGH2021-08-09

There is a Out-of-Bound Write in the Allwinner R818 SoC Android Q SDK V1.0 camera driver "/dev/cedar_dev" through iotcl cmd IOCTL_SET_PROC_INFO and IOCTL_COPY_PROC_INFO, which could cause a system crash or EoP.

CVEs:CVE-2021-38783

Affected products

ProductStatusVendorPackageEcosystem
android_q_sdk affected allwinnertech
Upstream advisory

DEBIAN-CVE-2021-30583

Open SourceCoalition ESS < 30%CRITICAL2021-08-03

DEBIAN-CVE-2021-30583

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-38784

Open SourceCoalition ESS < 30%HIGH2021-08-09

There is a NULL pointer dereference in the syscall open_exec function of Allwinner R818 SoC Android Q SDK V1.0 that could executable a malicious file to cause a system crash.

CVEs:CVE-2021-38784

Affected products

ProductStatusVendorPackageEcosystem
android_q_sdk affected allwinnertech
Upstream advisory

CVE-2021-38786

Open SourceCoalition ESS < 30%HIGH2021-08-09

There is a NULL pointer dereference in media/libcedarc/vdecoder of Allwinner R818 SoC Android Q SDK V1.0, which could cause a media crash (denial of service).

CVEs:CVE-2021-38786

Affected products

ProductStatusVendorPackageEcosystem
android_q_sdk affected allwinnertech
Upstream advisory

DEBIAN-CVE-2021-30578

Open SourceCoalition ESS < 30%HIGH2021-08-03

DEBIAN-CVE-2021-30578

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30566

Open SourceCoalition ESS < 30%CRITICAL2021-08-03

DEBIAN-CVE-2021-30566

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30541

Open SourceCoalition ESS < 30%CRITICAL2021-08-03

DEBIAN-CVE-2021-30541

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30596

Open SourceCoalition ESS < 30%MEDIUM2021-08-26

DEBIAN-CVE-2021-30596

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-30596

GoogleCoalition ESS < 30%MEDIUM2021-08-04

Incorrect security UI in Navigation in Google Chrome on Android prior to 92.0.4515.131 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2021-30596

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-30587

Open SourceCoalition ESS < 30%MEDIUM2021-08-03

DEBIAN-CVE-2021-30587

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30574

Open SourceCoalition ESS < 30%CRITICAL2021-08-03

DEBIAN-CVE-2021-30574

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30575

Open SourceCoalition ESS < 30%CRITICAL2021-08-03

DEBIAN-CVE-2021-30575

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30579

Open SourceCoalition ESS < 30%CRITICAL2021-08-03

DEBIAN-CVE-2021-30579

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30572

Open SourceCoalition ESS < 30%CRITICAL2021-08-03

DEBIAN-CVE-2021-30572

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30589

Open SourceCoalition ESS < 30%MEDIUM2021-08-03

DEBIAN-CVE-2021-30589

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30568

Open SourceCoalition ESS < 30%CRITICAL2021-08-03

DEBIAN-CVE-2021-30568

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30564

Open SourceCoalition ESS < 30%CRITICAL2021-08-03

DEBIAN-CVE-2021-30564

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30585

Open SourceCoalition ESS < 30%CRITICAL2021-08-03

DEBIAN-CVE-2021-30585

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30569

Open SourceCoalition ESS < 30%CRITICAL2021-08-03

DEBIAN-CVE-2021-30569

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30580

Open SourceCoalition ESS < 30%CRITICAL2021-08-03

DEBIAN-CVE-2021-30580

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30559

Open SourceCoalition ESS < 30%CRITICAL2021-08-03

DEBIAN-CVE-2021-30559

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30562

Open SourceCoalition ESS < 30%CRITICAL2021-08-03

DEBIAN-CVE-2021-30562

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30594

Open SourceCoalition ESS < 30%HIGH2021-08-26

DEBIAN-CVE-2021-30594

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30597

Open SourceCoalition ESS < 30%HIGH2021-08-26

DEBIAN-CVE-2021-30597

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-30594

GoogleCoalition ESS < 30%HIGH2021-08-04

Use after free in Page Info UI in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via physical access to the device.

CVEs:CVE-2021-30594

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30597

GoogleCoalition ESS < 30%HIGH2021-08-04

Use after free in Browser UI in Google Chrome on Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via physical access to the device.

CVEs:CVE-2021-30597

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-30581

Open SourceCoalition ESS < 30%CRITICAL2021-08-03

DEBIAN-CVE-2021-30581

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30576

Open SourceCoalition ESS < 30%CRITICAL2021-08-03

DEBIAN-CVE-2021-30576

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30571

Open SourceCoalition ESS < 30%CRITICAL2021-08-03

DEBIAN-CVE-2021-30571

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30567

Open SourceCoalition ESS < 30%CRITICAL2021-08-03

DEBIAN-CVE-2021-30567

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30586

Open SourceCoalition ESS < 30%CRITICAL2021-08-03

DEBIAN-CVE-2021-30586

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30577

Open SourceCoalition ESS < 30%HIGH2021-08-03

DEBIAN-CVE-2021-30577

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-24438

GoogleCoalition ESS < 30%HIGH2021-08-30

The ShareThis Dashboard for Google Analytics WordPress plugin before 2.5.2 does not sanitise or escape the 'ga_action' parameter in the stats view before outputting it back in an attribute when the plugin is connected to a Google Analytics account, lea...

CVEs:CVE-2021-24438

Affected products

ProductStatusVendorPackageEcosystem
dashboard_for_google_analytics affected sharethis
Upstream advisory

CVE-2021-25444

Open SourceCoalition ESS < 30%MEDIUM2021-08-05

An IV reuse vulnerability in keymaster prior to SMR AUG-2021 Release 1 allows decryption of custom keyblob with privileged process.

CVEs:CVE-2021-25444

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0591

Open SourceCoalition ESS < 30%HIGH2021-08-03

In sendReplyIntentToReceiver of BluetoothPermissionActivity.java, there is a possible way to invoke privileged broadcast receivers due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User in...

CVEs:CVE-2021-0591

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0645

Open SourceCoalition ESS < 30%HIGH2021-08-03

In shouldBlockFromTree of ExternalStorageProvider.java, there is a possible permissions bypass. This could lead to local escalation of privilege, allowing an app to read private app directories in external storage, which should be restricted in Android...

CVEs:CVE-2021-0645

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0642

Open SourceCoalition ESS < 30%MEDIUM2021-08-03

In onResume of VoicemailSettingsFragment.java, there is a possible way to retrieve a trackable identifier without permissions due to a missing permission check. This could lead to local information disclosure with no additional execution privileges nee...

CVEs:CVE-2021-0642

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0578

Open SourceCoalition ESS < 30%MEDIUM2021-08-03

In wifi driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure to a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2021-0578

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0579

Open SourceCoalition ESS < 30%MEDIUM2021-08-03

In wifi driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure to a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2021-0579

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0580

Open SourceCoalition ESS < 30%MEDIUM2021-08-03

In wifi driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure to a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2021-0580

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0581

Open SourceCoalition ESS < 30%MEDIUM2021-08-03

In wifi driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure to a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2021-0581

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0582

Open SourceCoalition ESS < 30%MEDIUM2021-08-03

In wifi driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure to a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2021-0582

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-187149601

GoogleCoalition ESS < 30%MEDIUM2021-08-01

ASB-A-187149601

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-187161772

GoogleCoalition ESS < 30%MEDIUM2021-08-01

ASB-A-187161772

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-187231636

GoogleCoalition ESS < 30%MEDIUM2021-08-01

ASB-A-187231636

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-187231637

GoogleCoalition ESS < 30%MEDIUM2021-08-01

ASB-A-187231637

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-187231638

GoogleCoalition ESS < 30%MEDIUM2021-08-01

ASB-A-187231638

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

GHSA-jwf9-w5xm-f437

Open SourceCoalition ESS < 30%HIGH2021-08-25

Heap OOB in TFLite's `Gather*` implementations

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-jwf9-w5xm-f437

Open SourceCoalition ESS < 30%HIGH2021-08-25

Heap OOB in TFLite's `Gather*` implementations

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-309

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-309

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-600

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-600

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-798

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-798

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37687

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions TFLite's [`GatherNd` implementation](https://github.com/tensorflow/tensorflow/blob/149562d49faa709ea80df1d99fc41d005b81082a/tensorflow/lite/kernels/gather_nd.cc...

CVEs:CVE-2021-37687

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37687

Open SourceCoalition ESS < 30%HIGH2021-08-12

Heap OOB in TFLite's `Gather*` implementations

CVEs:CVE-2021-37687

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37687

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

PYSEC-2021-798

CVEs:CVE-2021-37687

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-f5cx-5wr3-5qrc

Open SourceCoalition ESS < 30%HIGH2021-08-25

Reference binding to nullptr in boosted trees

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-f5cx-5wr3-5qrc

Open SourceCoalition ESS < 30%HIGH2021-08-25

Reference binding to nullptr in boosted trees

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-284

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-284

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-575

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-575

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-773

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-773

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37662

Open SourceCoalition ESS < 30%HIGH2021-08-12

Reference binding to nullptr in boosted trees

CVEs:CVE-2021-37662

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37662

Open SourceCoalition ESS < 30%HIGH2021-08-12

PYSEC-2021-773

CVEs:CVE-2021-37662

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37662

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can generate undefined behavior via a reference binding to nullptr in `BoostedTreesCalculateBestGainsPerFeature` and similar attack can occur in `Bo...

CVEs:CVE-2021-37662

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

GHSA-wp77-4gmm-7cq8

Open SourceCoalition ESS < 30%HIGH2021-08-25

Incorrect validation of `SaveV2` inputs

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-wp77-4gmm-7cq8

Open SourceCoalition ESS < 30%HIGH2021-08-25

Incorrect validation of `SaveV2` inputs

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-270

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-270

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-561

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-561

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-759

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-759

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37648

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions the code for `tf.raw_ops.SaveV2` does not properly validate the inputs and an attacker can trigger a null pointer dereference. The [implementation](https://gith...

CVEs:CVE-2021-37648

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37648

Open SourceCoalition ESS < 30%HIGH2021-08-12

PYSEC-2021-759

CVEs:CVE-2021-37648

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37648

Open SourceCoalition ESS < 30%HIGH2021-08-12

Incorrect validation of `SaveV2` inputs

CVEs:CVE-2021-37648

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-v82p-hv3v-p6qp

Open SourceCoalition ESS < 30%HIGH2021-08-25

Incomplete validation in MKL requantization

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-v82p-hv3v-p6qp

Open SourceCoalition ESS < 30%HIGH2021-08-25

Incomplete validation in MKL requantization

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-287

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-287

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-578

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-578

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-776

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-776

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37665

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions due to incomplete validation in MKL implementation of requantization, an attacker can trigger undefined behavior via binding a reference to a null pointer or ca...

CVEs:CVE-2021-37665

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37665

Open SourceCoalition ESS < 30%HIGH2021-08-12

Incomplete validation in MKL requantization

CVEs:CVE-2021-37665

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37665

Open SourceCoalition ESS < 30%HIGH2021-08-12

PYSEC-2021-776

CVEs:CVE-2021-37665

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-f8h4-7rgh-q2gm

Open SourceCoalition ESS < 30%CRITICAL2021-08-25

Segfault and heap buffer overflow in `{Experimental,}DatasetToTFRecord`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-f8h4-7rgh-q2gm

Open SourceCoalition ESS < 30%CRITICAL2021-08-25

Segfault and heap buffer overflow in `{Experimental,}DatasetToTFRecord`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-272

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-272

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-563

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-563

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-761

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-761

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37650

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

Segfault and heap buffer overflow in `{Experimental,}DatasetToTFRecord`

CVEs:CVE-2021-37650

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37650

Open SourceCoalition ESS < 30%HIGH2021-08-12

PYSEC-2021-761

CVEs:CVE-2021-37650

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37650

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation for `tf.raw_ops.ExperimentalDatasetToTFRecord` and `tf.raw_ops.DatasetToTFRecord` can trigger heap buffer overflow and segmentation fault. Th...

CVEs:CVE-2021-37650

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

GHSA-g8wg-cjwc-xhhp

Open SourceCoalition ESS < 30%HIGH2021-08-25

Heap OOB in nested `tf.map_fn` with `RaggedTensor`s

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-g8wg-cjwc-xhhp

Open SourceCoalition ESS < 30%HIGH2021-08-25

Heap OOB in nested `tf.map_fn` with `RaggedTensor`s

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-301

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-301

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-592

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-592

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-790

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-790

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37679

Open SourceCoalition ESS < 30%HIGH2021-08-12

PYSEC-2021-790

CVEs:CVE-2021-37679

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37679

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions it is possible to nest a `tf.map_fn` within another `tf.map_fn` call. However, if the input tensor is a `RaggedTensor` and there is no function signature provid...

CVEs:CVE-2021-37679

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37679

Open SourceCoalition ESS < 30%HIGH2021-08-12

Heap OOB in nested `tf.map_fn` with `RaggedTensor`s

CVEs:CVE-2021-37679

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-4c4g-crqm-xrxw

Open SourceCoalition ESS < 30%MEDIUM2021-08-25

Use of unitialized value in TFLite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-4c4g-crqm-xrxw

Open SourceCoalition ESS < 30%MEDIUM2021-08-25

Use of unitialized value in TFLite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-304

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-304

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-595

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-595

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-793

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-793

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37682

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

PYSEC-2021-793

CVEs:CVE-2021-37682

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37682

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions all TFLite operations that use quantization can be made to use unitialized values. [For example](https://github.com/tensorflow/tensorflow/blob/460e000de3a83278f...

CVEs:CVE-2021-37682

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37682

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

Use of unitialized value in TFLite

CVEs:CVE-2021-37682

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-7ghq-fvr3-pj2x

Open SourceCoalition ESS < 30%HIGH2021-08-25

Incomplete validation in `MaxPoolGrad`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-7ghq-fvr3-pj2x

Open SourceCoalition ESS < 30%HIGH2021-08-25

Incomplete validation in `MaxPoolGrad`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-296

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-296

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-587

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-587

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-785

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-785

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37674

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can trigger a denial of service via a segmentation fault in `tf.raw_ops.MaxPoolGrad` caused by missing validation. The [implementation](https://gith...

CVEs:CVE-2021-37674

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37674

Open SourceCoalition ESS < 30%HIGH2021-08-12

Incomplete validation in `MaxPoolGrad`

CVEs:CVE-2021-37674

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37674

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

PYSEC-2021-785

CVEs:CVE-2021-37674

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-q3g3-h9r4-prrc

Open SourceCoalition ESS < 30%HIGH2021-08-25

Reference binding to nullptr and heap OOB in binary cwise ops

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-q3g3-h9r4-prrc

Open SourceCoalition ESS < 30%HIGH2021-08-25

Reference binding to nullptr and heap OOB in binary cwise ops

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-281

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-281

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-572

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-572

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-770

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-770

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37659

Open SourceCoalition ESS < 30%HIGH2021-08-12

PYSEC-2021-770

CVEs:CVE-2021-37659

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37659

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause undefined behavior via binding a reference to null pointer in all binary cwise operations that don't require broadcasting (e.g., gradients...

CVEs:CVE-2021-37659

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37659

Open SourceCoalition ESS < 30%HIGH2021-08-12

Reference binding to nullptr and heap OOB in binary cwise ops

CVEs:CVE-2021-37659

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-vmjw-c2vp-p33c

Open SourceCoalition ESS < 30%HIGH2021-08-25

Crash in NMS ops caused by integer conversion to unsigned

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-vmjw-c2vp-p33c

Open SourceCoalition ESS < 30%HIGH2021-08-25

Crash in NMS ops caused by integer conversion to unsigned

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-291

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-291

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-582

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-582

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-780

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-780

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37669

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

PYSEC-2021-780

CVEs:CVE-2021-37669

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37669

Open SourceCoalition ESS < 30%HIGH2021-08-12

Crash in NMS ops caused by integer conversion to unsigned

CVEs:CVE-2021-37669

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37669

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause denial of service in applications serving models using `tf.raw_ops.NonMaxSuppressionV5` by triggering a division by 0. The [implementation...

CVEs:CVE-2021-37669

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

GHSA-hpv4-7p9c-mvfr

Open SourceCoalition ESS < 30%HIGH2021-08-25

Heap buffer overflow in `FractionalAvgPoolGrad`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-hpv4-7p9c-mvfr

Open SourceCoalition ESS < 30%HIGH2021-08-25

Heap buffer overflow in `FractionalAvgPoolGrad`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-273

Open SourceCoalition ESS < 30%HIGH2021-08-12

PYSEC-2021-273

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-564

Open SourceCoalition ESS < 30%HIGH2021-08-12

PYSEC-2021-564

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-762

Open SourceCoalition ESS < 30%HIGH2021-08-12

PYSEC-2021-762

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37651

Open SourceCoalition ESS < 30%HIGH2021-08-12

PYSEC-2021-762

CVEs:CVE-2021-37651

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37651

Open SourceCoalition ESS < 30%HIGH2021-08-12

Heap buffer overflow in `FractionalAvgPoolGrad`

CVEs:CVE-2021-37651

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37651

Open SourceCoalition ESS < 30%HIGH2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation for `tf.raw_ops.FractionalAvgPoolGrad` can be tricked into accessing data outside of bounds of heap allocated buffers. The [implementation](h...

CVEs:CVE-2021-37651

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

GHSA-gh6x-4whr-2qv4

Open SourceCoalition ESS < 30%HIGH2021-08-25

Null pointer dereference and heap OOB read in operations restoring tensors

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-gh6x-4whr-2qv4

Open SourceCoalition ESS < 30%HIGH2021-08-25

Null pointer dereference and heap OOB read in operations restoring tensors

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-m7fm-4jfh-jrg6

Open SourceCoalition ESS < 30%CRITICAL2021-08-25

Use after free in boosted trees creation

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-m7fm-4jfh-jrg6

Open SourceCoalition ESS < 30%CRITICAL2021-08-25

Use after free in boosted trees creation

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-g25h-jr74-qp5j

Open SourceCoalition ESS < 30%HIGH2021-08-25

Incomplete validation in `QuantizeV2`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-g25h-jr74-qp5j

Open SourceCoalition ESS < 30%HIGH2021-08-25

Incomplete validation in `QuantizeV2`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-w4xf-2pqw-5mq7

Open SourceCoalition ESS < 30%HIGH2021-08-25

Reference binding to nullptr in `RaggedTensorToVariant`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-w4xf-2pqw-5mq7

Open SourceCoalition ESS < 30%HIGH2021-08-25

Reference binding to nullptr in `RaggedTensorToVariant`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-w74j-v8xh-3w5h

Open SourceCoalition ESS < 30%HIGH2021-08-25

Reference binding to nullptr in unicode encoding

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-w74j-v8xh-3w5h

Open SourceCoalition ESS < 30%HIGH2021-08-25

Reference binding to nullptr in unicode encoding

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-qr82-2c78-4m8h

Open SourceCoalition ESS < 30%HIGH2021-08-25

Reference binding to nullptr in map operations

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-qr82-2c78-4m8h

Open SourceCoalition ESS < 30%HIGH2021-08-25

Reference binding to nullptr in map operations

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-v768-w7m9-2vmm

Open SourceCoalition ESS < 30%HIGH2021-08-25

Reference binding to nullptr in shape inference

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-v768-w7m9-2vmm

Open SourceCoalition ESS < 30%HIGH2021-08-25

Reference binding to nullptr in shape inference

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-7xwj-5r4v-429p

Open SourceCoalition ESS < 30%HIGH2021-08-25

NPE in TFLite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-7xwj-5r4v-429p

Open SourceCoalition ESS < 30%HIGH2021-08-25

NPE in TFLite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-mhhc-q96p-mfm9

Open SourceCoalition ESS < 30%HIGH2021-08-25

Infinite loop in TFLite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-mhhc-q96p-mfm9

Open SourceCoalition ESS < 30%HIGH2021-08-25

Infinite loop in TFLite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-285

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-285

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-576

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-576

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-774

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-774

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37663

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions due to incomplete validation in `tf.raw_ops.QuantizeV2`, an attacker can trigger undefined behavior via binding a reference to a null pointer or can access data...

CVEs:CVE-2021-37663

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37663

Open SourceCoalition ESS < 30%HIGH2021-08-12

Incomplete validation in `QuantizeV2`

CVEs:CVE-2021-37663

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37663

Open SourceCoalition ESS < 30%HIGH2021-08-12

PYSEC-2021-774

CVEs:CVE-2021-37663

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-274

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-274

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-288

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-288

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-289

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-289

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-293

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-293

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-298

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-298

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-303

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-303

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-308

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-308

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-565

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-565

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-579

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-579

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-580

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-580

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-584

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-584

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-589

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-589

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-594

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-594

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-599

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-599

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-763

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-763

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-777

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-777

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-778

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-778

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-782

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-782

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-787

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-787

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-792

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-792

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-797

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-797

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37681

Open SourceCoalition ESS < 30%HIGH2021-08-12

PYSEC-2021-792

CVEs:CVE-2021-37681

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37681

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of SVDF in TFLite is [vulnerable to a null pointer error](https://github.com/tensorflow/tensorflow/blob/460e000de3a83278fb00b61a16d161b1964f1...

CVEs:CVE-2021-37681

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37681

Open SourceCoalition ESS < 30%HIGH2021-08-12

NPE in TFLite

CVEs:CVE-2021-37681

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37686

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions the strided slice implementation in TFLite has a logic bug which can allow an attacker to trigger an infinite loop. This arises from newly introduced support fo...

CVEs:CVE-2021-37686

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37686

Open SourceCoalition ESS < 30%HIGH2021-08-12

Infinite loop in TFLite

CVEs:CVE-2021-37686

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37686

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

PYSEC-2021-797

CVEs:CVE-2021-37686

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37676

Open SourceCoalition ESS < 30%HIGH2021-08-12

PYSEC-2021-787

CVEs:CVE-2021-37676

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37676

Open SourceCoalition ESS < 30%HIGH2021-08-12

Reference binding to nullptr in shape inference

CVEs:CVE-2021-37676

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37676

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause undefined behavior via binding a reference to null pointer in `tf.raw_ops.SparseFillEmptyRows`. The shape inference [implementation](https...

CVEs:CVE-2021-37676

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37671

Open SourceCoalition ESS < 30%HIGH2021-08-12

PYSEC-2021-782

CVEs:CVE-2021-37671

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37671

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause undefined behavior via binding a reference to null pointer in `tf.raw_ops.Map*` and `tf.raw_ops.OrderedMap*` operations. The [implementati...

CVEs:CVE-2021-37671

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37671

Open SourceCoalition ESS < 30%HIGH2021-08-12

Reference binding to nullptr in map operations

CVEs:CVE-2021-37671

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37666

Open SourceCoalition ESS < 30%HIGH2021-08-12

PYSEC-2021-777

CVEs:CVE-2021-37666

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37666

Open SourceCoalition ESS < 30%HIGH2021-08-12

Reference binding to nullptr in `RaggedTensorToVariant`

CVEs:CVE-2021-37666

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37666

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause undefined behavior via binding a reference to null pointer in `tf.raw_ops.RaggedTensorToVariant`. The [implementation](https://github.com/...

CVEs:CVE-2021-37666

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37667

Open SourceCoalition ESS < 30%HIGH2021-08-12

Reference binding to nullptr in unicode encoding

CVEs:CVE-2021-37667

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37667

Open SourceCoalition ESS < 30%HIGH2021-08-12

PYSEC-2021-778

CVEs:CVE-2021-37667

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37667

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause undefined behavior via binding a reference to null pointer in `tf.raw_ops.UnicodeEncode`. The [implementation](https://github.com/tensorfl...

CVEs:CVE-2021-37667

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37652

Open SourceCoalition ESS < 30%HIGH2021-08-12

PYSEC-2021-763

CVEs:CVE-2021-37652

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37652

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation for `tf.raw_ops.BoostedTreesCreateEnsemble` can result in a use after free error if an attacker supplies specially crafted arguments. The [im...

CVEs:CVE-2021-37652

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37652

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

Use after free in boosted trees creation

CVEs:CVE-2021-37652

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-261

Open SourceCoalition ESS < 30%HIGH2021-08-12

PYSEC-2021-261

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-552

Open SourceCoalition ESS < 30%HIGH2021-08-12

PYSEC-2021-552

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-750

Open SourceCoalition ESS < 30%HIGH2021-08-12

PYSEC-2021-750

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37639

Open SourceCoalition ESS < 30%HIGH2021-08-12

PYSEC-2021-750

CVEs:CVE-2021-37639

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37639

Open SourceCoalition ESS < 30%HIGH2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. When restoring tensors via raw APIs, if the tensor name is not provided, TensorFlow can be tricked into dereferencing a null pointer. Alternatively, attackers can read memory outsid...

CVEs:CVE-2021-37639

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37639

Open SourceCoalition ESS < 30%HIGH2021-08-12

Null pointer dereference and heap OOB read in operations restoring tensors

CVEs:CVE-2021-37639

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-5hj3-vjjf-f5m7

Open SourceCoalition ESS < 30%MEDIUM2021-08-25

Heap OOB in `SdcaOptimizerV2`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-5hj3-vjjf-f5m7

Open SourceCoalition ESS < 30%MEDIUM2021-08-25

Heap OOB in `SdcaOptimizerV2`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-c545-c4f9-rf6v

Open SourceCoalition ESS < 30%HIGH2021-08-25

Heap OOB in TFLite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-c545-c4f9-rf6v

Open SourceCoalition ESS < 30%HIGH2021-08-25

Heap OOB in TFLite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-cmgw-8vpc-rc59

Open SourceCoalition ESS < 30%MEDIUM2021-08-25

Segfault on strings tensors with mistmatched dimensions, due to Go code

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-cmgw-8vpc-rc59

Open SourceCoalition ESS < 30%MEDIUM2021-08-25

Segfault on strings tensors with mistmatched dimensions, due to Go code

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-294

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-294

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-307

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-307

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-314

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-314

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-585

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-585

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-598

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-598

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-605

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-605

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-783

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-783

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-796

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-796

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-803

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-803

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37692

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

PYSEC-2021-803

CVEs:CVE-2021-37692

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37692

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

Segfault on strings tensors with mistmatched dimensions, due to Go code

CVEs:CVE-2021-37692

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37692

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions under certain conditions, Go code can trigger a segfault in string deallocation. For string tensors, `C.TF_TString_Dealloc` is called during garbage collection ...

CVEs:CVE-2021-37692

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37672

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

Heap OOB in `SdcaOptimizerV2`

CVEs:CVE-2021-37672

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37672

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

PYSEC-2021-783

CVEs:CVE-2021-37672

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37672

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can read from outside of bounds of heap allocated data by sending specially crafted illegal arguments to `tf.raw_ops.SdcaOptimizerV2`. The [implemen...

CVEs:CVE-2021-37672

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37685

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions TFLite's [`expand_dims.cc`](https://github.com/tensorflow/tensorflow/blob/149562d49faa709ea80df1d99fc41d005b81082a/tensorflow/lite/kernels/expand_dims.cc#L36-L5...

CVEs:CVE-2021-37685

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37685

Open SourceCoalition ESS < 30%HIGH2021-08-12

Heap OOB in TFLite

CVEs:CVE-2021-37685

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37685

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

PYSEC-2021-796

CVEs:CVE-2021-37685

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-9697-98pf-4rw7

Open SourceCoalition ESS < 30%MEDIUM2021-08-25

Heap OOB in `UpperBound` and `LowerBound`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-9697-98pf-4rw7

Open SourceCoalition ESS < 30%MEDIUM2021-08-25

Heap OOB in `UpperBound` and `LowerBound`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-292

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-292

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-583

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-583

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-781

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-781

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37670

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

Heap OOB in `UpperBound` and `LowerBound`

CVEs:CVE-2021-37670

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37670

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

PYSEC-2021-781

CVEs:CVE-2021-37670

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37670

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can read from outside of bounds of heap allocated data by sending specially crafted illegal arguments to `tf.raw_ops.UpperBound`. The [implementatio...

CVEs:CVE-2021-37670

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

GHSA-cgfm-62j4-v4rf

Open SourceCoalition ESS < 30%HIGH2021-08-25

Heap out of bounds access in sparse reduction operations

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-cgfm-62j4-v4rf

Open SourceCoalition ESS < 30%HIGH2021-08-25

Heap out of bounds access in sparse reduction operations

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-hwr7-8gxx-fj5p

Open SourceCoalition ESS < 30%HIGH2021-08-25

Null pointer dereference in `RaggedTensorToTensor`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-hwr7-8gxx-fj5p

Open SourceCoalition ESS < 30%HIGH2021-08-25

Null pointer dereference in `RaggedTensorToTensor`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-9c8h-vvrj-w2p8

Open SourceCoalition ESS < 30%HIGH2021-08-25

Heap OOB in `RaggedGather`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-9c8h-vvrj-w2p8

Open SourceCoalition ESS < 30%HIGH2021-08-25

Heap OOB in `RaggedGather`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-2r8p-fg3c-wcj4

Open SourceCoalition ESS < 30%CRITICAL2021-08-25

Heap OOB and CHECK fail in `ResourceGather`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-2r8p-fg3c-wcj4

Open SourceCoalition ESS < 30%CRITICAL2021-08-25

Heap OOB and CHECK fail in `ResourceGather`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-7fvx-3jfc-2cpc

Open SourceCoalition ESS < 30%CRITICAL2021-08-25

Heap OOB in `ResourceScatterUpdate`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-7fvx-3jfc-2cpc

Open SourceCoalition ESS < 30%CRITICAL2021-08-25

Heap OOB in `ResourceScatterUpdate`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-4xfp-4pfp-89wg

Open SourceCoalition ESS < 30%HIGH2021-08-25

Reference binding to nullptr in `RaggedTensorToSparse`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-4xfp-4pfp-89wg

Open SourceCoalition ESS < 30%HIGH2021-08-25

Reference binding to nullptr in `RaggedTensorToSparse`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-5xwc-mrhx-5g3m

Open SourceCoalition ESS < 30%HIGH2021-08-25

Reference binding to nullptr in `MatrixDiagV*` ops

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-5xwc-mrhx-5g3m

Open SourceCoalition ESS < 30%HIGH2021-08-25

Reference binding to nullptr in `MatrixDiagV*` ops

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-6p5r-g9mq-ggh2

Open SourceCoalition ESS < 30%HIGH2021-08-25

Reference binding to nullptr in `MatrixSetDiagV*` ops

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-6p5r-g9mq-ggh2

Open SourceCoalition ESS < 30%HIGH2021-08-25

Reference binding to nullptr in `MatrixSetDiagV*` ops

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-r4c4-5fpq-56wg

Open SourceCoalition ESS < 30%HIGH2021-08-25

Heap OOB in boosted trees

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-r4c4-5fpq-56wg

Open SourceCoalition ESS < 30%HIGH2021-08-25

Heap OOB in boosted trees

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-257

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-257

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-263

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-263

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-276

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-276

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-277

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-277

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-278

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-278

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-279

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-279

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-280

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-280

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-286

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-286

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-548

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-548

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-554

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-554

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-567

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-567

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-568

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-568

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-569

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-569

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-570

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-570

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-571

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-571

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-577

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-577

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-746

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-746

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-752

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-752

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-765

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-765

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-766

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-766

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-767

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-767

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-768

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-768

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-769

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-769

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-775

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-775

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37656

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause undefined behavior via binding a reference to null pointer in `tf.raw_ops.RaggedTensorToSparse`. The [implementation](https://github.com/t...

CVEs:CVE-2021-37656

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37656

Open SourceCoalition ESS < 30%HIGH2021-08-12

PYSEC-2021-767

CVEs:CVE-2021-37656

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37656

Open SourceCoalition ESS < 30%HIGH2021-08-12

Reference binding to nullptr in `RaggedTensorToSparse`

CVEs:CVE-2021-37656

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37657

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause undefined behavior via binding a reference to null pointer in all operations of type `tf.raw_ops.MatrixDiagV*`. The [implementation](https...

CVEs:CVE-2021-37657

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37657

Open SourceCoalition ESS < 30%HIGH2021-08-12

Reference binding to nullptr in `MatrixDiagV*` ops

CVEs:CVE-2021-37657

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37657

Open SourceCoalition ESS < 30%HIGH2021-08-12

PYSEC-2021-768

CVEs:CVE-2021-37657

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37658

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause undefined behavior via binding a reference to null pointer in all operations of type `tf.raw_ops.MatrixSetDiagV*`. The [implementation](ht...

CVEs:CVE-2021-37658

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37658

Open SourceCoalition ESS < 30%HIGH2021-08-12

Reference binding to nullptr in `MatrixSetDiagV*` ops

CVEs:CVE-2021-37658

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37658

Open SourceCoalition ESS < 30%HIGH2021-08-12

PYSEC-2021-769

CVEs:CVE-2021-37658

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37654

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can trigger a crash via a `CHECK`-fail in debug builds of TensorFlow using `tf.raw_ops.ResourceGather` or a read from outside the bounds of heap all...

CVEs:CVE-2021-37654

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37654

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

Heap OOB and CHECK fail in `ResourceGather`

CVEs:CVE-2021-37654

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37654

Open SourceCoalition ESS < 30%HIGH2021-08-12

PYSEC-2021-765

CVEs:CVE-2021-37654

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37641

Open SourceCoalition ESS < 30%HIGH2021-08-12

Heap OOB in `RaggedGather`

CVEs:CVE-2021-37641

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37641

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions if the arguments to `tf.raw_ops.RaggedGather` don't determine a valid ragged tensor code can trigger a read from outside of bounds of heap allocated buffers. Th...

CVEs:CVE-2021-37641

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37641

Open SourceCoalition ESS < 30%HIGH2021-08-12

PYSEC-2021-752

CVEs:CVE-2021-37641

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37635

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of sparse reduction operations in TensorFlow can trigger accesses outside of bounds of heap allocated data. The [implementation](https://gith...

CVEs:CVE-2021-37635

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37635

Open SourceCoalition ESS < 30%HIGH2021-08-12

PYSEC-2021-746

CVEs:CVE-2021-37635

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37635

Open SourceCoalition ESS < 30%HIGH2021-08-12

Heap out of bounds access in sparse reduction operations

CVEs:CVE-2021-37635

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37664

Open SourceCoalition ESS < 30%HIGH2021-08-12

PYSEC-2021-775

CVEs:CVE-2021-37664

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37664

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can read from outside of bounds of heap allocated data by sending specially crafted illegal arguments to `BoostedTreesSparseCalculateBestFeatureSpli...

CVEs:CVE-2021-37664

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37664

Open SourceCoalition ESS < 30%HIGH2021-08-12

Heap OOB in boosted trees

CVEs:CVE-2021-37664

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37655

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

Heap OOB in `ResourceScatterUpdate`

CVEs:CVE-2021-37655

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37655

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can trigger a read from outside of bounds of heap allocated data by sending invalid arguments to `tf.raw_ops.ResourceScatterUpdate`. The [implementa...

CVEs:CVE-2021-37655

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37655

Open SourceCoalition ESS < 30%HIGH2021-08-12

PYSEC-2021-766

CVEs:CVE-2021-37655

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-260

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-260

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-551

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-551

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-749

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-749

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37638

Open SourceCoalition ESS < 30%HIGH2021-08-12

Null pointer dereference in `RaggedTensorToTensor`

CVEs:CVE-2021-37638

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37638

Open SourceCoalition ESS < 30%HIGH2021-08-12

PYSEC-2021-749

CVEs:CVE-2021-37638

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37638

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. Sending invalid argument for `row_partition_types` of `tf.raw_ops.RaggedTensorToTensor` API results in a null pointer dereference and undefined behavior. The [implementation](https:...

CVEs:CVE-2021-37638

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

GHSA-vcjj-9vg7-vf68

Open SourceCoalition ESS < 30%HIGH2021-08-25

Null pointer dereference in TFLite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-vcjj-9vg7-vf68

Open SourceCoalition ESS < 30%HIGH2021-08-25

Null pointer dereference in TFLite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-wf5p-c75w-w3wh

Open SourceCoalition ESS < 30%HIGH2021-08-25

Null pointer dereference in TFLite MLIR optimizations

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-wf5p-c75w-w3wh

Open SourceCoalition ESS < 30%HIGH2021-08-25

Null pointer dereference in TFLite MLIR optimizations

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-310

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-310

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-311

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-311

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-601

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-601

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-602

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-602

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-799

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-799

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-800

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-800

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37689

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can craft a TFLite model that would trigger a null pointer dereference, which would result in a crash and denial of service. This is caused by the M...

CVEs:CVE-2021-37689

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37689

Open SourceCoalition ESS < 30%HIGH2021-08-12

Null pointer dereference in TFLite MLIR optimizations

CVEs:CVE-2021-37689

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37689

Open SourceCoalition ESS < 30%HIGH2021-08-12

PYSEC-2021-800

CVEs:CVE-2021-37689

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37688

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can craft a TFLite model that would trigger a null pointer dereference, which would result in a crash and denial of service. The [implementation](ht...

CVEs:CVE-2021-37688

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37688

Open SourceCoalition ESS < 30%HIGH2021-08-12

PYSEC-2021-799

CVEs:CVE-2021-37688

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37688

Open SourceCoalition ESS < 30%HIGH2021-08-12

Null pointer dereference in TFLite

CVEs:CVE-2021-37688

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-3hxh-8cp2-g4hg

Open SourceCoalition ESS < 30%CRITICAL2021-08-25

Use after free and segfault in shape inference functions

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-3hxh-8cp2-g4hg

Open SourceCoalition ESS < 30%CRITICAL2021-08-25

Use after free and segfault in shape inference functions

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-312

Open SourceCoalition ESS < 30%CRITICAL2021-08-13

PYSEC-2021-312

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-603

Open SourceCoalition ESS < 30%CRITICAL2021-08-13

PYSEC-2021-603

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-801

Open SourceCoalition ESS < 30%CRITICAL2021-08-13

PYSEC-2021-801

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37690

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

Use after free and segfault in shape inference functions

CVEs:CVE-2021-37690

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37690

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions when running shape functions, some functions (such as `MutableHashTableShape`) produce extra output information in the form of a `ShapeAndType` struct. The shap...

CVEs:CVE-2021-37690

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37690

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

PYSEC-2021-801

CVEs:CVE-2021-37690

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-c9qf-r67m-p7cg

Open SourceCoalition ESS < 30%HIGH2021-08-25

Null pointer dereference in `CompressElement`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-c9qf-r67m-p7cg

Open SourceCoalition ESS < 30%HIGH2021-08-25

Null pointer dereference in `CompressElement`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-fcwc-p4fc-c5cc

Open SourceCoalition ESS < 30%HIGH2021-08-25

Null pointer dereference in `MatrixDiagPartOp`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-fcwc-p4fc-c5cc

Open SourceCoalition ESS < 30%HIGH2021-08-25

Null pointer dereference in `MatrixDiagPartOp`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-c5x2-p679-95wc

Open SourceCoalition ESS < 30%HIGH2021-08-25

Null pointer dereference in `SparseTensorSliceDataset`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-c5x2-p679-95wc

Open SourceCoalition ESS < 30%HIGH2021-08-25

Null pointer dereference in `SparseTensorSliceDataset`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-6gv8-p3vj-pxvr

Open SourceCoalition ESS < 30%HIGH2021-08-25

Null pointer dereference in `UncompressElement`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-6gv8-p3vj-pxvr

Open SourceCoalition ESS < 30%HIGH2021-08-25

Null pointer dereference in `UncompressElement`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-9c8h-2mv3-49ww

Open SourceCoalition ESS < 30%HIGH2021-08-25

Division by 0 in most convolution operators

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-9c8h-2mv3-49ww

Open SourceCoalition ESS < 30%HIGH2021-08-25

Division by 0 in most convolution operators

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-297

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-297

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-588

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-588

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-786

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-786

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37675

Open SourceCoalition ESS < 30%HIGH2021-08-12

Division by 0 in most convolution operators

CVEs:CVE-2021-37675

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37675

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

PYSEC-2021-786

CVEs:CVE-2021-37675

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37675

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions most implementations of convolution operators in TensorFlow are affected by a division by 0 vulnerability where an attacker can trigger a denial of service via ...

CVEs:CVE-2021-37675

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

PYSEC-2021-259

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-259

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-265

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-265

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-269

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-269

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-271

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-271

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-550

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-550

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-556

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-556

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-560

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-560

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-562

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-562

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-748

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-748

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-754

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-754

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-758

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-758

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-760

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-760

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37637

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. It is possible to trigger a null pointer dereference in TensorFlow by passing an invalid input to `tf.raw_ops.CompressElement`. The [implementation](https://github.com/tensorflow/te...

CVEs:CVE-2021-37637

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37637

Open SourceCoalition ESS < 30%HIGH2021-08-12

Null pointer dereference in `CompressElement`

CVEs:CVE-2021-37637

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37637

Open SourceCoalition ESS < 30%HIGH2021-08-12

PYSEC-2021-748

CVEs:CVE-2021-37637

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37649

Open SourceCoalition ESS < 30%HIGH2021-08-12

Null pointer dereference in `UncompressElement`

CVEs:CVE-2021-37649

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37649

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. The code for `tf.raw_ops.UncompressElement` can be made to trigger a null pointer dereference. The [implementation](https://github.com/tensorflow/tensorflow/blob/f24faa153ad31a4b515...

CVEs:CVE-2021-37649

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37649

Open SourceCoalition ESS < 30%HIGH2021-08-12

PYSEC-2021-760

CVEs:CVE-2021-37649

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37647

Open SourceCoalition ESS < 30%HIGH2021-08-12

PYSEC-2021-758

CVEs:CVE-2021-37647

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37647

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. When a user does not supply arguments that determine a valid sparse tensor, `tf.raw_ops.SparseTensorSliceDataset` implementation can be made to dereference a null pointer. The [impl...

CVEs:CVE-2021-37647

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37647

Open SourceCoalition ESS < 30%HIGH2021-08-12

Null pointer dereference in `SparseTensorSliceDataset`

CVEs:CVE-2021-37647

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37643

Open SourceCoalition ESS < 30%HIGH2021-08-12

Null pointer dereference in `MatrixDiagPartOp`

CVEs:CVE-2021-37643

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37643

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. If a user does not provide a valid padding value to `tf.raw_ops.MatrixDiagPartOp`, then the code triggers a null pointer dereference (if input is empty) or produces invalid behavior...

CVEs:CVE-2021-37643

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37643

Open SourceCoalition ESS < 30%HIGH2021-08-12

PYSEC-2021-754

CVEs:CVE-2021-37643

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

ASB-A-187074483

GoogleCoalition ESS < 30%2021-08-01

ASB-A-187074483

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

GHSA-ch4f-829c-v5pw

Open SourceCoalition ESS < 30%CRITICAL2021-08-25

Division by 0 in `ResourceScatterDiv`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-ch4f-829c-v5pw

Open SourceCoalition ESS < 30%CRITICAL2021-08-25

Division by 0 in `ResourceScatterDiv`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-h6jh-7gv5-28vg

Open SourceCoalition ESS < 30%CRITICAL2021-08-25

Bad alloc in `StringNGrams` caused by integer conversion

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-h6jh-7gv5-28vg

Open SourceCoalition ESS < 30%CRITICAL2021-08-25

Bad alloc in `StringNGrams` caused by integer conversion

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-cm5x-837x-jf3c

Open SourceCoalition ESS < 30%MEDIUM2021-08-25

Division by 0 in inplace operations

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-cm5x-837x-jf3c

Open SourceCoalition ESS < 30%MEDIUM2021-08-25

Division by 0 in inplace operations

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-gf88-j2mg-cc82

Open SourceCoalition ESS < 30%CRITICAL2021-08-25

Crash caused by integer conversion to unsigned

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-gf88-j2mg-cc82

Open SourceCoalition ESS < 30%CRITICAL2021-08-25

Crash caused by integer conversion to unsigned

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-2wmv-37vq-52g5

Open SourceCoalition ESS < 30%HIGH2021-08-25

FPE in `tf.raw_ops.UnravelIndex`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-2wmv-37vq-52g5

Open SourceCoalition ESS < 30%HIGH2021-08-25

FPE in `tf.raw_ops.UnravelIndex`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-278g-rq84-9hmg

Open SourceCoalition ESS < 30%HIGH2021-08-25

`CHECK`-fail in `MapStage`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-278g-rq84-9hmg

Open SourceCoalition ESS < 30%HIGH2021-08-25

`CHECK`-fail in `MapStage`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-rhrq-64mq-hf9h

Open SourceCoalition ESS < 30%MEDIUM2021-08-25

FPE in TFLite division operations

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-rhrq-64mq-hf9h

Open SourceCoalition ESS < 30%MEDIUM2021-08-25

FPE in TFLite division operations

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-290

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-290

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-295

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-295

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-305

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-305

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-581

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-581

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-586

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-586

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-596

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-596

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-779

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-779

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-784

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-784

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-794

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-794

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37673

Open SourceCoalition ESS < 30%HIGH2021-08-12

`CHECK`-fail in `MapStage`

CVEs:CVE-2021-37673

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37673

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can trigger a denial of service via a `CHECK`-fail in `tf.raw_ops.MapStage`. The [implementation](https://github.com/tensorflow/tensorflow/blob/460e...

CVEs:CVE-2021-37673

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37673

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

PYSEC-2021-784

CVEs:CVE-2021-37673

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37683

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of division in TFLite is [vulnerable to a division by 0 error](https://github.com/tensorflow/tensorflow/blob/460e000de3a83278fb00b61a16d161b1...

CVEs:CVE-2021-37683

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37683

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

PYSEC-2021-794

CVEs:CVE-2021-37683

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37683

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

FPE in TFLite division operations

CVEs:CVE-2021-37683

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37668

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

PYSEC-2021-779

CVEs:CVE-2021-37668

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37668

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause denial of service in applications serving models using `tf.raw_ops.UnravelIndex` by triggering a division by 0. The [implementation](https...

CVEs:CVE-2021-37668

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37668

Open SourceCoalition ESS < 30%HIGH2021-08-12

FPE in `tf.raw_ops.UnravelIndex`

CVEs:CVE-2021-37668

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-268

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-268

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-283

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-283

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-559

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-559

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-574

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-574

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-757

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-757

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-772

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-772

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37646

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of `tf.raw_ops.StringNGrams` is vulnerable to an integer overflow issue caused by converting a signed integer value to an unsigned one and th...

CVEs:CVE-2021-37646

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37646

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

Bad alloc in `StringNGrams` caused by integer conversion

CVEs:CVE-2021-37646

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37646

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

PYSEC-2021-757

CVEs:CVE-2021-37646

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37661

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

Crash caused by integer conversion to unsigned

CVEs:CVE-2021-37661

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37661

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause a denial of service in `boosted_trees_create_quantile_stream_resource` by using negative arguments. The [implementation](https://github.co...

CVEs:CVE-2021-37661

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37661

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

PYSEC-2021-772

CVEs:CVE-2021-37661

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-264

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-264

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-282

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-282

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-555

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-555

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-573

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-573

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-753

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-753

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-771

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-771

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37660

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause a floating point exception by calling inplace operations with crafted arguments that would result in a division by 0. The [implementation]...

CVEs:CVE-2021-37660

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37660

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

Division by 0 in inplace operations

CVEs:CVE-2021-37660

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37660

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

PYSEC-2021-771

CVEs:CVE-2021-37660

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37642

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

PYSEC-2021-753

CVEs:CVE-2021-37642

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37642

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

Division by 0 in `ResourceScatterDiv`

CVEs:CVE-2021-37642

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37642

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of `tf.raw_ops.ResourceScatterDiv` is vulnerable to a division by 0 error. The [implementation](https://github.com/tensorflow/tensorflow/blob...

CVEs:CVE-2021-37642

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

GHSA-hp4c-x6r7-6555

Open SourceCoalition ESS < 30%MEDIUM2021-08-25

Floating point exception in `SparseDenseCwiseDiv`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-hp4c-x6r7-6555

Open SourceCoalition ESS < 30%MEDIUM2021-08-25

Floating point exception in `SparseDenseCwiseDiv`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-95xm-g58g-3p88

Open SourceCoalition ESS < 30%MEDIUM2021-08-25

Integer division by 0 in sparse reshaping

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-95xm-g58g-3p88

Open SourceCoalition ESS < 30%MEDIUM2021-08-25

Integer division by 0 in sparse reshaping

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-27j5-4p9v-pp67

Open SourceCoalition ESS < 30%MEDIUM2021-08-25

`std::abort` raised from `TensorListReserve`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-27j5-4p9v-pp67

Open SourceCoalition ESS < 30%MEDIUM2021-08-25

`std::abort` raised from `TensorListReserve`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-9w2p-5mgw-p94c

Open SourceCoalition ESS < 30%CRITICAL2021-08-25

Integer overflow due to conversion to unsigned

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-9w2p-5mgw-p94c

Open SourceCoalition ESS < 30%CRITICAL2021-08-25

Integer overflow due to conversion to unsigned

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-qjj8-32p7-h289

Open SourceCoalition ESS < 30%CRITICAL2021-08-25

Division by 0 in `ResourceGather`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-qjj8-32p7-h289

Open SourceCoalition ESS < 30%CRITICAL2021-08-25

Division by 0 in `ResourceGather`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-cfpj-3q4c-jhvr

Open SourceCoalition ESS < 30%HIGH2021-08-25

Division by zero in TFLite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-cfpj-3q4c-jhvr

Open SourceCoalition ESS < 30%HIGH2021-08-25

Division by zero in TFLite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-27qf-jwm8-g7f3

Open SourceCoalition ESS < 30%HIGH2021-08-25

FPE in LSH in TFLite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-27qf-jwm8-g7f3

Open SourceCoalition ESS < 30%HIGH2021-08-25

FPE in LSH in TFLite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-313

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-313

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-604

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-604

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-802

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-802

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37691

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can craft a TFLite model that would trigger a division by zero error in LSH [implementation](https://github.com/tensorflow/tensorflow/blob/149562d49...

CVEs:CVE-2021-37691

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37691

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

PYSEC-2021-802

CVEs:CVE-2021-37691

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37691

Open SourceCoalition ESS < 30%HIGH2021-08-12

FPE in LSH in TFLite

CVEs:CVE-2021-37691

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-302

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-302

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-593

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-593

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-791

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-791

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37680

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

PYSEC-2021-791

CVEs:CVE-2021-37680

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37680

Open SourceCoalition ESS < 30%HIGH2021-08-12

Division by zero in TFLite

CVEs:CVE-2021-37680

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37680

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of fully connected layers in TFLite is [vulnerable to a division by zero error](https://github.com/tensorflow/tensorflow/blob/460e000de3a8327...

CVEs:CVE-2021-37680

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

PYSEC-2021-266

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-266

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-267

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-267

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-557

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-557

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-558

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-558

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-755

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-755

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-756

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-756

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37645

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of `tf.raw_ops.QuantizeAndDequantizeV4Grad` is vulnerable to an integer overflow issue caused by converting a signed integer value to an unsi...

CVEs:CVE-2021-37645

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37645

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

PYSEC-2021-756

CVEs:CVE-2021-37645

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37645

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

Integer overflow due to conversion to unsigned

CVEs:CVE-2021-37645

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37644

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

`std::abort` raised from `TensorListReserve`

CVEs:CVE-2021-37644

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37644

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

PYSEC-2021-755

CVEs:CVE-2021-37644

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37644

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions providing a negative element to `num_elements` list argument of `tf.raw_ops.TensorListReserve` causes the runtime to abort the process due to reallocating a `st...

CVEs:CVE-2021-37644

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

PYSEC-2021-258

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-258

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-262

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-262

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-275

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-275

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-549

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-549

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-553

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-553

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-566

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-566

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-747

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-747

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-751

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-751

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-764

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-764

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37653

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

PYSEC-2021-764

CVEs:CVE-2021-37653

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37653

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can trigger a crash via a floating point exception in `tf.raw_ops.ResourceGather`. The [implementation](https://github.com/tensorflow/tensorflow/blo...

CVEs:CVE-2021-37653

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37653

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

Division by 0 in `ResourceGather`

CVEs:CVE-2021-37653

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37640

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

Integer division by 0 in sparse reshaping

CVEs:CVE-2021-37640

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37640

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of `tf.raw_ops.SparseReshape` can be made to trigger an integral division by 0 exception. The [implementation](https://github.com/tensorflow/...

CVEs:CVE-2021-37640

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37640

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

PYSEC-2021-751

CVEs:CVE-2021-37640

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37636

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

Floating point exception in `SparseDenseCwiseDiv`

CVEs:CVE-2021-37636

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37636

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of `tf.raw_ops.SparseDenseCwiseDiv` is vulnerable to a division by 0 error. The [implementation](https://github.com/tensorflow/tensorflow/blo...

CVEs:CVE-2021-37636

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37636

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

PYSEC-2021-747

CVEs:CVE-2021-37636

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-22552

GoogleCoalition ESS < 30%MEDIUM2021-08-02

An untrusted memory read vulnerability in Asylo versions up to 0.6.1 allows an untrusted attacker to pass a syscall number in MessageReader that is then used by sysno() and can bypass validation. This can allow the attacker to read memory from within t...

CVEs:CVE-2021-22552

Affected products

ProductStatusVendorPackageEcosystem
asylo affected google
Upstream advisory

GHSA-qfpc-5pjr-mh26

Open SourceCoalition ESS < 30%HIGH2021-08-25

Missing validation in shape inference for `Dequantize`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-qfpc-5pjr-mh26

Open SourceCoalition ESS < 30%HIGH2021-08-25

Missing validation in shape inference for `Dequantize`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-299

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-299

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-590

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-590

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-788

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-788

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37677

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions the shape inference code for `tf.raw_ops.Dequantize` has a vulnerability that could trigger a denial of service via a segfault if an attacker provides invalid a...

CVEs:CVE-2021-37677

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-37677

Open SourceCoalition ESS < 30%HIGH2021-08-12

Missing validation in shape inference for `Dequantize`

CVEs:CVE-2021-37677

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37677

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

PYSEC-2021-788

CVEs:CVE-2021-37677

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

ASB-A-187073199

GoogleCoalition ESS < 30%2021-08-01

ASB-A-187073199

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

PUB-A-168799695

GoogleCoalition ESS < 30%NONE2021-08-01

PUB-A-168799695

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

GHSA-q7f7-544h-67h9

Open SourceCoalition ESS < 30%MEDIUM2021-08-25

FPE in TFLite pooling operations

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-q7f7-544h-67h9

Open SourceCoalition ESS < 30%MEDIUM2021-08-25

FPE in TFLite pooling operations

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-306

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-306

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-597

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-597

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-795

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

PYSEC-2021-795

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37684

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

PYSEC-2021-795

CVEs:CVE-2021-37684

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37684

Open SourceCoalition ESS < 30%MEDIUM2021-08-12

FPE in TFLite pooling operations

CVEs:CVE-2021-37684

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-37684

Open SourceCoalition ESS < 30%CRITICAL2021-08-12

TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementations of pooling in TFLite are vulnerable to division by 0 errors as there are no checks for divisors not being 0. We have patched the issue in Gi...

CVEs:CVE-2021-37684

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-0407

Open SourceCoalition ESS < 30%HIGH2021-08-18

In clk driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05479659; ...

CVEs:CVE-2021-0407

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0626

Open SourceCoalition ESS < 30%HIGH2021-08-18

In ged, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05687510; Issue ID: ...

CVEs:CVE-2021-0626

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0573

Open SourceCoalition ESS < 30%HIGH2021-08-03

In asf extractor, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...

CVEs:CVE-2021-0573

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0574

Open SourceCoalition ESS < 30%HIGH2021-08-03

In asf extractor, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...

CVEs:CVE-2021-0574

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0576

Open SourceCoalition ESS < 30%HIGH2021-08-03

In flv extractor, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...

CVEs:CVE-2021-0576

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0593

Open SourceCoalition ESS < 30%HIGH2021-08-03

In sendDevicePickedIntent of DevicePickerFragment.java, there is a possible way to invoke a privileged broadcast receiver due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction...

CVEs:CVE-2021-0593

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-187231635

GoogleCoalition ESS < 30%HIGH2021-08-01

ASB-A-187231635

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-187234876

GoogleCoalition ESS < 30%HIGH2021-08-01

ASB-A-187234876

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-187236084

GoogleCoalition ESS < 30%HIGH2021-08-01

ASB-A-187236084

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-0639

Open SourceCoalition ESS < 30%MEDIUM2021-08-03

In multiple functions of libl3oemcrypto.cpp, there is a possible weakness in the existing obfuscation mechanism due to the way sensitive data is handled. This could lead to local information disclosure with no additional execution privileges needed. Us...

CVEs:CVE-2021-0639

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-190724551

GoogleCoalition ESS < 30%MEDIUM2021-08-01

ASB-A-190724551

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-0408

Open SourceCoalition ESS < 30%MEDIUM2021-08-18

In asf extractor, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05...

CVEs:CVE-2021-0408

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0627

Open SourceCoalition ESS < 30%HIGH2021-08-18

In OMA DRM, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05722434; Issue ID: A...

CVEs:CVE-2021-0627

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0628

Open SourceCoalition ESS < 30%HIGH2021-08-18

In OMA DRM, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05722454; Issue...

CVEs:CVE-2021-0628

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0584

Open SourceCoalition ESS < 30%HIGH2021-08-03

In verifyBufferObject of Parcel.cpp, there is a possible out of bounds read due to an improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2021-0584

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0415

Open SourceCoalition ESS < 30%MEDIUM2021-08-18

In memory management driver, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. ...

CVEs:CVE-2021-0415

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0416

Open SourceCoalition ESS < 30%MEDIUM2021-08-18

In memory management driver, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05...

CVEs:CVE-2021-0416

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0417

Open SourceCoalition ESS < 30%MEDIUM2021-08-18

In memory management driver, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05...

CVEs:CVE-2021-0417

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0418

Open SourceCoalition ESS < 30%MEDIUM2021-08-18

In memory management driver, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05...

CVEs:CVE-2021-0418

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0419

Open SourceCoalition ESS < 30%MEDIUM2021-08-18

In memory management driver, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05...

CVEs:CVE-2021-0419

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0420

Open SourceCoalition ESS < 30%MEDIUM2021-08-18

In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403...

CVEs:CVE-2021-0420

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0641

Open SourceCoalition ESS < 30%MEDIUM2021-08-03

In getAvailableSubscriptionInfoList of SubscriptionController.java, there is a possible disclosure of unique identifiers due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. ...

CVEs:CVE-2021-0641

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-38591

Open SourceCoalition ESS < 30%HIGH2021-08-12

An issue was discovered on LG mobile devices with Android OS P and Q software for mt6762/mt6765/mt6883. Attackers can change some of the NvRAM content by leveraging the misconfiguration of a debug command. The LG ID is LVE-SMP-210005 (August 2021).

CVEs:CVE-2021-38591

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25443

Open SourceCoalition ESS < 30%CRITICAL2021-08-05

A use after free vulnerability in conn_gadget driver prior to SMR AUG-2021 Release 1 allows malicious action by an attacker.

CVEs:CVE-2021-25443

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.