Advisories
Project ZeroExploitedCISA KEV listed2021-08-24
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
CVEs:CVE-2021-30860
GoogleExploitedCISA KEV listedCRITICAL2021-08-24
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code exe...
CVEs:CVE-2021-30860
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| mac_os_x |
affected |
apple |
— |
— |
| poppler |
affected |
freedesktop |
— |
— |
| watchos |
affected |
apple |
— |
— |
| xpdf |
affected |
xpdfreader |
— |
— |
GoogleExploitedCISA KEV listedHIGH2021-08-11
CVEs:CVE-2021-36948
Project ZeroExploitedCISA KEV listed2021-08-11
Windows Update Medic Service Elevation of Privilege Vulnerability
CVEs:CVE-2021-36948
GoogleExploitedCISA KEV listedCRITICAL2021-08-11
Windows Update Medic Service Elevation of Privilege Vulnerability
CVEs:CVE-2021-36948
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| windows_10_1809 |
affected |
microsoft |
— |
— |
| windows_10_1909 |
affected |
microsoft |
— |
— |
| windows_10_2004 |
affected |
microsoft |
— |
— |
| windows_10_20h2 |
affected |
microsoft |
— |
— |
| windows_10_21h1 |
affected |
microsoft |
— |
— |
| windows_server_2004 |
affected |
microsoft |
— |
— |
| windows_server_2019 |
affected |
microsoft |
— |
— |
| windows_server_20h2 |
affected |
microsoft |
— |
— |
GoogleExploitedCISA KEV listedCRITICAL2021-08-24
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 15.0.2 and iPadOS 15.0.2, macOS Monterey 12.0.1, iOS 14.8.1 and iPadOS 14.8.1, tvOS 15.1, watchOS 8.1, macOS Big Sur 11.6.1. An application may be able to...
CVEs:CVE-2021-30883
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
Project ZeroExploitedCISA KEV listed2021-08-24
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 15.0.2 and iPadOS 15.0.2, macOS Monterey 12.0.1, iOS 14.8.1 and iPadOS 14.8.1, tvOS 15.1, watchOS 8.1, macOS Big Sur 11.6.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..
CVEs:CVE-2021-30883
GoogleExploitedCISA KEV listedCRITICAL2021-08-24
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that ...
CVEs:CVE-2021-30858
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
Project ZeroExploitedCISA KEV listed2021-08-24
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
CVEs:CVE-2021-30858
Open SourceExploitedCISA KEV listedHIGH2021-08-03
DEBIAN-CVE-2021-30563
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleExploitedCISA KEV listedCRITICAL2021-08-24
A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 12.5.5, iOS 14.4 and iPadOS 14.4, macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, Security Update 2021-006 Catalina. A...
CVEs:CVE-2021-30869
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| mac_os_x |
affected |
apple |
— |
— |
Project ZeroExploitedCISA KEV listed2021-08-24
A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 12.5.5, iOS 14.4 and iPadOS 14.4, macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, Security Update 2021-006 Catalina. A malicious application may be able to execute arbitrary code with kernel privileges. Apple is aware of reports that an exploit for this issue exists in the wild.
CVEs:CVE-2021-30869
GoogleExploitedCISA KEV listedHIGH2021-08-24
A deserialization issue was addressed through improved validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 12.5.5, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. A sandboxed process may be able to circumvent sandbox ...
CVEs:CVE-2021-31010
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| mac_os_x |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
Project ZeroExploitedCISA KEV listed2021-08-24
A deserialization issue was addressed through improved validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 12.5.5, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. A sandboxed process may be able to circumvent sandbox restrictions. Apple was aware of a report that this issue may have been actively exploited at the time of release..
CVEs:CVE-2021-31010
GoogleExploitedCISA KEV listedCRITICAL2021-08-24
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 15.2 and iPadOS 15.2. An application may be able to execute arbitrary code with kernel privileges.
CVEs:CVE-2021-30983
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
Project ZeroExploitedCISA KEV listed2021-08-24
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 15.2 and iPadOS 15.2. An application may be able to execute arbitrary code with kernel privileges.
CVEs:CVE-2021-30983
Open SourceWeaponized exploitCRITICAL2021-08-17
Security update for SUSE Manager Client Tools
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ansible |
affected |
openSUSE:Leap 15.2 |
ansible |
— |
| dracut-saltboot |
affected |
openSUSE:Leap 15.2 |
dracut-saltboot |
— |
| golang-github-prometheus-prometheus |
affected |
openSUSE:Leap 15.2 |
golang-github-prometheus-prometheus |
— |
Open SourceWeaponized exploitCRITICAL2021-08-12
Security update for SUSE Manager Client Tools
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ansible |
affected |
SUSE:Manager Client Tools 15 |
ansible |
— |
| dracut-saltboot |
affected |
SUSE:Manager Client Tools 15 |
dracut-saltboot |
— |
| golang-github-prometheus-prometheus |
affected |
SUSE:Manager Client Tools 15 |
golang-github-prometheus-prometheus |
— |
| mgr-cfg |
affected |
SUSE:Manager Client Tools 15 |
mgr-cfg |
— |
| mgr-custom-info |
affected |
SUSE:Manager Client Tools 15 |
mgr-custom-info |
— |
| mgr-osad |
affected |
SUSE:Manager Client Tools 15 |
mgr-osad |
— |
| mgr-push |
affected |
SUSE:Manager Client Tools 15 |
mgr-push |
— |
| mgr-virtualization |
affected |
SUSE:Manager Client Tools 15 |
mgr-virtualization |
— |
| rhnlib |
affected |
SUSE:Manager Client Tools 15 |
rhnlib |
— |
| spacecmd |
affected |
SUSE:Manager Client Tools 15 |
spacecmd |
— |
| spacewalk-client-tools |
affected |
SUSE:Manager Client Tools 15 |
spacewalk-client-tools |
— |
| spacewalk-koan |
affected |
SUSE:Manager Client Tools 15 |
spacewalk-koan |
— |
| spacewalk-oscap |
affected |
SUSE:Manager Client Tools 15 |
spacewalk-oscap |
— |
| suseRegisterInfo |
affected |
SUSE:Manager Client Tools 15 |
suseRegisterInfo |
— |
| uyuni-common-libs |
affected |
SUSE:Manager Client Tools 15 |
uyuni-common-libs |
— |
Open SourceWeaponized exploitHIGH2021-08-12
Security update for SUSE Manager Client Tools
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-prometheus-prometheus |
affected |
SUSE:Manager Client Tools 12 |
golang-github-prometheus-prometheus |
— |
| grafana |
affected |
SUSE:Manager Client Tools 12 |
grafana |
— |
| mgr-cfg |
affected |
SUSE:Manager Client Tools 12 |
mgr-cfg |
— |
| mgr-custom-info |
affected |
SUSE:Manager Client Tools 12 |
mgr-custom-info |
— |
| mgr-osad |
affected |
SUSE:Manager Client Tools 12 |
mgr-osad |
— |
| mgr-push |
affected |
SUSE:Manager Client Tools 12 |
mgr-push |
— |
| mgr-virtualization |
affected |
SUSE:Manager Client Tools 12 |
mgr-virtualization |
— |
| rhnlib |
affected |
SUSE:Manager Client Tools 12 |
rhnlib |
— |
| spacecmd |
affected |
SUSE:Manager Client Tools 12 |
spacecmd |
— |
| spacewalk-client-tools |
affected |
SUSE:Manager Client Tools 12 |
spacewalk-client-tools |
— |
| spacewalk-koan |
affected |
SUSE:Manager Client Tools 12 |
spacewalk-koan |
— |
| spacewalk-oscap |
affected |
SUSE:Manager Client Tools 12 |
spacewalk-oscap |
— |
| suseRegisterInfo |
affected |
SUSE:Manager Client Tools 12 |
suseRegisterInfo |
— |
| uyuni-common-libs |
affected |
SUSE:Manager Client Tools 12 |
uyuni-common-libs |
— |
Open SourceWeaponized exploitCRITICAL2021-08-12
Security update for golang-github-prometheus-prometheus
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-prometheus-prometheus |
affected |
openSUSE:Leap 15.3 |
golang-github-prometheus-prometheus |
— |
Open SourceWeaponized exploitCRITICAL2021-08-12
Security update for golang-github-prometheus-prometheus
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-prometheus-prometheus |
affected |
SUSE:Enterprise Storage 6 |
golang-github-prometheus-prometheus |
— |
Open SourceActive exploitation (sightings)CRITICAL2021-08-30
Authorization Policy Bypass Due to Case Insensitive Host Comparison
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| cert-manager-istio-csr |
affected |
wolfi |
cert-manager-istio-csr |
— |
| cert-manager-istio-csr |
affected |
chainguard |
cert-manager-istio-csr |
— |
| cert-manager-istio-csr-fips |
affected |
chainguard |
cert-manager-istio-csr-fips |
— |
| istio |
affected |
istio.io |
istio.io/istio |
— |
| istio-cni-1.21 |
affected |
wolfi |
istio-cni-1.21 |
— |
| istio-cni-1.21 |
affected |
chainguard |
istio-cni-1.21 |
— |
| istio-cni-1.22 |
affected |
chainguard |
istio-cni-1.22 |
— |
| istio-cni-1.22 |
affected |
wolfi |
istio-cni-1.22 |
— |
| istio-fips-1.21 |
affected |
chainguard |
istio-fips-1.21 |
— |
| istio-operator-1.20 |
affected |
chainguard |
istio-operator-1.20 |
— |
| istio-operator-1.20 |
affected |
wolfi |
istio-operator-1.20 |
— |
| istio-operator-1.21 |
affected |
chainguard |
istio-operator-1.21 |
— |
| istio-operator-1.21 |
affected |
wolfi |
istio-operator-1.21 |
— |
| istio-operator-1.22 |
affected |
wolfi |
istio-operator-1.22 |
— |
| istio-operator-1.22 |
affected |
chainguard |
istio-operator-1.22 |
— |
| istio-pilot-agent-1.21 |
affected |
wolfi |
istio-pilot-agent-1.21 |
— |
| istio-pilot-agent-1.21 |
affected |
chainguard |
istio-pilot-agent-1.21 |
— |
| istio-pilot-agent-1.22 |
affected |
wolfi |
istio-pilot-agent-1.22 |
— |
| istio-pilot-agent-1.22 |
affected |
chainguard |
istio-pilot-agent-1.22 |
— |
| istio-pilot-discovery-1.21 |
affected |
wolfi |
istio-pilot-discovery-1.21 |
— |
| istio-pilot-discovery-1.21 |
affected |
chainguard |
istio-pilot-discovery-1.21 |
— |
| istio-pilot-discovery-1.22 |
affected |
chainguard |
istio-pilot-discovery-1.22 |
— |
| istio-pilot-discovery-1.22 |
affected |
wolfi |
istio-pilot-discovery-1.22 |
— |
| kgateway-2.3 |
affected |
chainguard |
kgateway-2.3 |
— |
| kgateway-2.4 |
affected |
chainguard |
kgateway-2.4 |
— |
| kgateway-fips-2.3 |
affected |
chainguard |
kgateway-fips-2.3 |
— |
| kgateway-fips-2.4 |
affected |
chainguard |
kgateway-fips-2.4 |
— |
Open SourceActive exploitation (sightings)CRITICAL2021-08-30
Authorization Policy Bypass Due to Case Insensitive Host Comparison
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| istio |
affected |
istio.io |
istio.io/istio |
— |
Open SourceActive exploitation (sightings)CRITICAL2021-08-24
Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies and aggregate telemetry data. According to [RFC 4343](https://datatracker.ietf.org/doc/html/rfc4343), Is...
CVEs:CVE-2021-39155
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| istio |
affected |
istio |
— |
— |
Open SourceActive exploitation (sightings)HIGH2021-08-24
Authorization Policy Bypass Due to Case Insensitive Host Comparison
CVEs:CVE-2021-39155
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| istio |
affected |
istio.io |
istio.io/istio |
— |
Open SourceActive exploitation (sightings)HIGH2021-08-30
Istio Fragments in Path May Lead to Authorization Policy Bypass
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| istio |
affected |
istio.io |
istio.io/istio |
— |
Open SourceActive exploitation (sightings)HIGH2021-08-30
Istio Fragments in Path May Lead to Authorization Policy Bypass
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| cert-manager-istio-csr |
affected |
chainguard |
cert-manager-istio-csr |
— |
| cert-manager-istio-csr |
affected |
wolfi |
cert-manager-istio-csr |
— |
| cert-manager-istio-csr-fips |
affected |
chainguard |
cert-manager-istio-csr-fips |
— |
| istio |
affected |
istio.io |
istio.io/istio |
— |
| istio-cni-1.21 |
affected |
wolfi |
istio-cni-1.21 |
— |
| istio-cni-1.21 |
affected |
chainguard |
istio-cni-1.21 |
— |
| istio-cni-1.22 |
affected |
chainguard |
istio-cni-1.22 |
— |
| istio-cni-1.22 |
affected |
wolfi |
istio-cni-1.22 |
— |
| istio-fips-1.21 |
affected |
chainguard |
istio-fips-1.21 |
— |
| istio-operator-1.20 |
affected |
wolfi |
istio-operator-1.20 |
— |
| istio-operator-1.20 |
affected |
chainguard |
istio-operator-1.20 |
— |
| istio-operator-1.21 |
affected |
wolfi |
istio-operator-1.21 |
— |
| istio-operator-1.21 |
affected |
chainguard |
istio-operator-1.21 |
— |
| istio-operator-1.22 |
affected |
chainguard |
istio-operator-1.22 |
— |
| istio-operator-1.22 |
affected |
wolfi |
istio-operator-1.22 |
— |
| istio-pilot-agent-1.21 |
affected |
wolfi |
istio-pilot-agent-1.21 |
— |
| istio-pilot-agent-1.21 |
affected |
chainguard |
istio-pilot-agent-1.21 |
— |
| istio-pilot-agent-1.22 |
affected |
wolfi |
istio-pilot-agent-1.22 |
— |
| istio-pilot-agent-1.22 |
affected |
chainguard |
istio-pilot-agent-1.22 |
— |
| istio-pilot-discovery-1.21 |
affected |
chainguard |
istio-pilot-discovery-1.21 |
— |
| istio-pilot-discovery-1.21 |
affected |
wolfi |
istio-pilot-discovery-1.21 |
— |
| istio-pilot-discovery-1.22 |
affected |
wolfi |
istio-pilot-discovery-1.22 |
— |
| istio-pilot-discovery-1.22 |
affected |
chainguard |
istio-pilot-discovery-1.22 |
— |
| kgateway-2.3 |
affected |
chainguard |
kgateway-2.3 |
— |
| kgateway-2.4 |
affected |
chainguard |
kgateway-2.4 |
— |
| kgateway-fips-2.3 |
affected |
chainguard |
kgateway-fips-2.3 |
— |
| kgateway-fips-2.4 |
affected |
chainguard |
kgateway-fips-2.4 |
— |
Open SourceActive exploitation (sightings)HIGH2021-08-24
Istio Fragments in Path May Lead to Authorization Policy Bypass
CVEs:CVE-2021-39156
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| istio |
affected |
istio.io |
istio.io/istio |
— |
Open SourceActive exploitation (sightings)CRITICAL2021-08-24
Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies and aggregate telemetry data. Istio 1.11.0, 1.10.3 and below, and 1.9.7 and below contain a remotely exp...
CVEs:CVE-2021-39156
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| istio |
affected |
istio |
— |
— |
GoogleActive exploitation (sightings)2021-08-01
ASB-A-175037520
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel:Qualcomm |
affected |
Android |
:linux_kernel:Qualcomm |
— |
Open SourcePoC exploitCRITICAL2021-08-03
DEBIAN-CVE-2021-30560
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| libxslt |
affected |
Debian:11 |
libxslt |
— |
| libxslt |
affected |
Debian:12 |
libxslt |
— |
| libxslt |
affected |
Debian:13 |
libxslt |
— |
| libxslt |
affected |
Debian:14 |
libxslt |
— |
Open SourcePoC exploitHIGH2021-08-10
Moderate: go-toolset:rhel8 security, bug fix, and enhancement update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| delve |
affected |
Rocky Linux:8 |
delve |
— |
| golang |
affected |
Rocky Linux:8 |
golang |
— |
| go-toolset |
affected |
Rocky Linux:8 |
go-toolset |
— |
Open SourcePoC exploitCRITICAL2021-08-10
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP3 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.3 |
chromium |
— |
Open SourcePoC exploitCRITICAL2021-08-10
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
openSUSE:Leap 15.2 |
chromium |
— |
Open SourcePoC exploitCRITICAL2021-08-03
DEBIAN-CVE-2021-30573
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourcePoC exploitHIGH2021-08-07
CVE-2021-29923 affecting package golang 1.25.7-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:3 |
golang |
— |
GooglePoC exploitHIGH2021-08-07
Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation...
CVEs:CVE-2021-29923
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| fedora |
affected |
fedoraproject |
— |
— |
| go |
affected |
golang |
— |
— |
| timesten_in-memory_database |
affected |
oracle |
— |
— |
GooglePoC exploitHIGH2021-08-07
CVEs:CVE-2021-29923
Open SourcePoC exploitHIGH2021-08-07
DEBIAN-CVE-2021-29923
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-1.15 |
affected |
Debian:11 |
golang-1.15 |
— |
Open SourcePoC exploitHIGH2021-08-02
CVE-2021-33196 affecting package golang 1.25.7-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:3 |
golang |
— |
Open SourcePoC exploitHIGH2021-08-02
DEBIAN-CVE-2021-33196
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-1.15 |
affected |
Debian:11 |
golang-1.15 |
— |
Open SourcePoC exploitCRITICAL2021-08-02
CVE-2021-33195 affecting package golang 1.25.7-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:3 |
golang |
— |
Open SourcePoC exploitCRITICAL2021-08-02
DEBIAN-CVE-2021-33195
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-1.15 |
affected |
Debian:11 |
golang-1.15 |
— |
GooglePoC exploitMEDIUM2021-08-08
Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic upon an ErrAbortHandler abort.
CVEs:CVE-2021-36221
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| go |
affected |
golang |
— |
— |
| scalance_lpe9403_firmware |
affected |
siemens |
— |
— |
| timesten_in-memory_database |
affected |
oracle |
— |
— |
GooglePoC exploitMEDIUM2021-08-08
CVEs:CVE-2021-36221
Open SourcePoC exploitMEDIUM2021-08-08
DEBIAN-CVE-2021-36221
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-1.15 |
affected |
Debian:11 |
golang-1.15 |
— |
Open SourcePoC exploitMEDIUM2021-08-02
CVE-2021-33197 affecting package golang 1.25.7-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:3 |
golang |
— |
Open SourcePoC exploitMEDIUM2021-08-02
DEBIAN-CVE-2021-33197
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-1.15 |
affected |
Debian:11 |
golang-1.15 |
— |
GooglePoC exploitHIGH2021-08-01
ASB-A-171705902
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel: |
affected |
Android |
:linux_kernel: |
— |
GooglePoC exploitHIGH2021-08-01
ASB-A-175193031
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel: |
affected |
Android |
:linux_kernel: |
— |
Open SourcePoC exploitCRITICAL2021-08-25
Arbitrary code execution due to YAML deserialization
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourcePoC exploitCRITICAL2021-08-25
Arbitrary code execution due to YAML deserialization
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourcePoC exploitHIGH2021-08-12
PYSEC-2021-300
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourcePoC exploitHIGH2021-08-12
PYSEC-2021-591
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourcePoC exploitHIGH2021-08-12
PYSEC-2021-789
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourcePoC exploitCRITICAL2021-08-12
Arbitrary code execution due to YAML deserialization
CVEs:CVE-2021-37678
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourcePoC exploitCRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions TensorFlow and Keras can be tricked to perform arbitrary code execution when deserializing a Keras model from YAML format. The [implementation](https://github.c...
CVEs:CVE-2021-37678
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourcePoC exploitCRITICAL2021-08-12
PYSEC-2021-789
CVEs:CVE-2021-37678
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
GooglePoC exploitNONE2021-08-01
ASB-A-183188047
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel: |
affected |
Android |
:linux_kernel: |
— |
Open SourcePoC exploitHIGH2021-08-03
In BITSTREAM_FLUSH of ih264e_bitstream.h, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploita...
CVEs:CVE-2021-0519
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2021-08-03
CVEs:CVE-2021-0519
Open SourcePoC exploitHIGH2021-08-03
In noteAtomLogged of StatsdStats.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitatio...
CVEs:CVE-2021-0640
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2021-08-03
CVEs:CVE-2021-0640
GooglePoC exploitHIGH2021-08-03
CVEs:CVE-2021-0646
Open SourcePoC exploitHIGH2021-08-03
In sqlite3_str_vappendf of sqlite3.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege if the user can also inject a printf into a privileged process's SQL with no additional exe...
CVEs:CVE-2021-0646
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-26
DEBIAN-CVE-2021-30598
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-23
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP3 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.3 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-20
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
openSUSE:Leap 15.2 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2021-08-17
Type confusion in V8 in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
CVEs:CVE-2021-30598
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%HIGH2021-08-17
CVEs:CVE-2021-30598
Open SourceCoalition ESS < 30%MEDIUM2021-08-03
DEBIAN-CVE-2021-30582
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-26
DEBIAN-CVE-2021-30599
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2021-08-17
CVEs:CVE-2021-30599
GoogleCoalition ESS < 30%CRITICAL2021-08-17
Type confusion in V8 in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
CVEs:CVE-2021-30599
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-03
DEBIAN-CVE-2021-30561
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-26
DEBIAN-CVE-2021-30603
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2021-08-17
CVEs:CVE-2021-30603
GoogleCoalition ESS < 30%HIGH2021-08-17
Data race in WebAudio in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30603
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Uncontrolled memory consumption in protobuf
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| protobuf |
affected |
crates.io |
protobuf |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Uncontrolled memory consumption in protobuf
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| protobuf |
affected |
crates.io |
protobuf |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-02
DEBIAN-CVE-2021-33198
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-1.15 |
affected |
Debian:11 |
golang-1.15 |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-26
DEBIAN-CVE-2021-30590
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2021-08-04
Heap buffer overflow in Bookmarks in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30590
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%HIGH2021-08-04
CVEs:CVE-2021-30590
Open SourceCoalition ESS < 30%CRITICAL2021-08-26
DEBIAN-CVE-2021-30600
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2021-08-17
Use after free in Printing in Google Chrome prior to 92.0.4515.159 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30600
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%HIGH2021-08-17
CVEs:CVE-2021-30600
Open SourceCoalition ESS < 30%CRITICAL2021-08-26
DEBIAN-CVE-2021-30591
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-26
DEBIAN-CVE-2021-30604
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2021-08-17
CVEs:CVE-2021-30604
GoogleCoalition ESS < 30%CRITICAL2021-08-17
Use after free in ANGLE in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30604
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2021-08-04
Use after free in File System API in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30591
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%HIGH2021-08-04
CVEs:CVE-2021-30591
Open SourceCoalition ESS < 30%HIGH2021-08-26
DEBIAN-CVE-2021-30602
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2021-08-17
CVEs:CVE-2021-30602
GoogleCoalition ESS < 30%HIGH2021-08-17
Use after free in WebRTC in Google Chrome prior to 92.0.4515.159 allowed an attacker who convinced a user to visit a malicious website to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30602
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-26
DEBIAN-CVE-2021-30592
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2021-08-04
Out of bounds write in Tab Groups in Google Chrome prior to 92.0.4515.131 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page.
CVEs:CVE-2021-30592
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%HIGH2021-08-04
CVEs:CVE-2021-30592
Open SourceCoalition ESS < 30%HIGH2021-08-03
DEBIAN-CVE-2021-30588
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-26
DEBIAN-CVE-2021-30593
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2021-08-04
Out of bounds read in Tab Strip in Google Chrome prior to 92.0.4515.131 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted HTML page.
CVEs:CVE-2021-30593
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%HIGH2021-08-04
CVEs:CVE-2021-30593
Open SourceCoalition ESS < 30%CRITICAL2021-08-26
DEBIAN-CVE-2021-30601
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2021-08-17
CVEs:CVE-2021-30601
GoogleCoalition ESS < 30%CRITICAL2021-08-17
Use after free in Extensions API in Google Chrome prior to 92.0.4515.159 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30601
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-03
DEBIAN-CVE-2021-30584
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-03
DEBIAN-CVE-2021-30565
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2022-01-18
CVEs:CVE-2021-38783
Open SourceCoalition ESS < 30%HIGH2021-08-09
There is a Out-of-Bound Write in the Allwinner R818 SoC Android Q SDK V1.0 camera driver "/dev/cedar_dev" through iotcl cmd IOCTL_SET_PROC_INFO and IOCTL_COPY_PROC_INFO, which could cause a system crash or EoP.
CVEs:CVE-2021-38783
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android_q_sdk |
affected |
allwinnertech |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-03
DEBIAN-CVE-2021-30583
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2022-01-18
CVEs:CVE-2021-38784
Open SourceCoalition ESS < 30%HIGH2021-08-09
There is a NULL pointer dereference in the syscall open_exec function of Allwinner R818 SoC Android Q SDK V1.0 that could executable a malicious file to cause a system crash.
CVEs:CVE-2021-38784
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android_q_sdk |
affected |
allwinnertech |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-01-19
CVEs:CVE-2021-38786
Open SourceCoalition ESS < 30%HIGH2021-08-09
There is a NULL pointer dereference in media/libcedarc/vdecoder of Allwinner R818 SoC Android Q SDK V1.0, which could cause a media crash (denial of service).
CVEs:CVE-2021-38786
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android_q_sdk |
affected |
allwinnertech |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-03
DEBIAN-CVE-2021-30578
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-03
DEBIAN-CVE-2021-30566
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-03
DEBIAN-CVE-2021-30541
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-26
DEBIAN-CVE-2021-30596
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2021-08-04
Incorrect security UI in Navigation in Google Chrome on Android prior to 92.0.4515.131 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVEs:CVE-2021-30596
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%2021-08-04
CVEs:CVE-2021-30596
Open SourceCoalition ESS < 30%MEDIUM2021-08-03
DEBIAN-CVE-2021-30587
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-03
DEBIAN-CVE-2021-30574
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-03
DEBIAN-CVE-2021-30575
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-03
DEBIAN-CVE-2021-30579
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-03
DEBIAN-CVE-2021-30572
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-03
DEBIAN-CVE-2021-30589
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-03
DEBIAN-CVE-2021-30568
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-03
DEBIAN-CVE-2021-30564
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-03
DEBIAN-CVE-2021-30585
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-03
DEBIAN-CVE-2021-30569
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-03
DEBIAN-CVE-2021-30580
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-03
DEBIAN-CVE-2021-30559
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-03
DEBIAN-CVE-2021-30562
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-26
DEBIAN-CVE-2021-30594
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-26
DEBIAN-CVE-2021-30597
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2021-08-04
Use after free in Page Info UI in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via physical access to the device.
CVEs:CVE-2021-30594
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%2021-08-04
CVEs:CVE-2021-30594
GoogleCoalition ESS < 30%2021-08-04
CVEs:CVE-2021-30597
GoogleCoalition ESS < 30%HIGH2021-08-04
Use after free in Browser UI in Google Chrome on Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via physical access to the device.
CVEs:CVE-2021-30597
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-03
DEBIAN-CVE-2021-30581
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-03
DEBIAN-CVE-2021-30576
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-03
DEBIAN-CVE-2021-30571
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-03
DEBIAN-CVE-2021-30567
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-03
DEBIAN-CVE-2021-30586
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-03
DEBIAN-CVE-2021-30577
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%2021-08-30
CVEs:CVE-2021-24438
GoogleCoalition ESS < 30%HIGH2021-08-30
The ShareThis Dashboard for Google Analytics WordPress plugin before 2.5.2 does not sanitise or escape the 'ga_action' parameter in the stats view before outputting it back in an attribute when the plugin is connected to a Google Analytics account, lea...
CVEs:CVE-2021-24438
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| dashboard_for_google_analytics |
affected |
sharethis |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-05
An IV reuse vulnerability in keymaster prior to SMR AUG-2021 Release 1 allows decryption of custom keyblob with privileged process.
CVEs:CVE-2021-25444
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2021-08-05
CVEs:CVE-2021-25444
GoogleCoalition ESS < 30%HIGH2021-08-03
CVEs:CVE-2021-0591
Open SourceCoalition ESS < 30%HIGH2021-08-03
In sendReplyIntentToReceiver of BluetoothPermissionActivity.java, there is a possible way to invoke privileged broadcast receivers due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User in...
CVEs:CVE-2021-0591
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2021-08-03
CVEs:CVE-2021-0645
Open SourceCoalition ESS < 30%HIGH2021-08-03
In shouldBlockFromTree of ExternalStorageProvider.java, there is a possible permissions bypass. This could lead to local escalation of privilege, allowing an app to read private app directories in external storage, which should be restricted in Android...
CVEs:CVE-2021-0645
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-03
In onResume of VoicemailSettingsFragment.java, there is a possible way to retrieve a trackable identifier without permissions due to a missing permission check. This could lead to local information disclosure with no additional execution privileges nee...
CVEs:CVE-2021-0642
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2021-08-03
CVEs:CVE-2021-0642
GoogleCoalition ESS < 30%2021-08-03
CVEs:CVE-2021-0578
Open SourceCoalition ESS < 30%MEDIUM2021-08-03
In wifi driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure to a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitatio...
CVEs:CVE-2021-0578
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2021-08-03
CVEs:CVE-2021-0579
Open SourceCoalition ESS < 30%MEDIUM2021-08-03
In wifi driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure to a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitatio...
CVEs:CVE-2021-0579
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-03
In wifi driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure to a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitatio...
CVEs:CVE-2021-0580
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2021-08-03
CVEs:CVE-2021-0580
Open SourceCoalition ESS < 30%MEDIUM2021-08-03
In wifi driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure to a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitatio...
CVEs:CVE-2021-0581
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2021-08-03
CVEs:CVE-2021-0581
Open SourceCoalition ESS < 30%MEDIUM2021-08-03
In wifi driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure to a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitatio...
CVEs:CVE-2021-0582
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2021-08-03
CVEs:CVE-2021-0582
GoogleCoalition ESS < 30%MEDIUM2021-08-01
ASB-A-187149601
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2021-08-01
ASB-A-187161772
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2021-08-01
ASB-A-187231636
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2021-08-01
ASB-A-187231637
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2021-08-01
ASB-A-187231638
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Heap OOB in TFLite's `Gather*` implementations
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Heap OOB in TFLite's `Gather*` implementations
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-309
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-600
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-798
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions TFLite's [`GatherNd` implementation](https://github.com/tensorflow/tensorflow/blob/149562d49faa709ea80df1d99fc41d005b81082a/tensorflow/lite/kernels/gather_nd.cc...
CVEs:CVE-2021-37687
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
Heap OOB in TFLite's `Gather*` implementations
CVEs:CVE-2021-37687
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
PYSEC-2021-798
CVEs:CVE-2021-37687
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Reference binding to nullptr in boosted trees
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Reference binding to nullptr in boosted trees
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-284
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-575
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-773
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
Reference binding to nullptr in boosted trees
CVEs:CVE-2021-37662
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
PYSEC-2021-773
CVEs:CVE-2021-37662
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can generate undefined behavior via a reference binding to nullptr in `BoostedTreesCalculateBestGainsPerFeature` and similar attack can occur in `Bo...
CVEs:CVE-2021-37662
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Incorrect validation of `SaveV2` inputs
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Incorrect validation of `SaveV2` inputs
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-270
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-561
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-759
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions the code for `tf.raw_ops.SaveV2` does not properly validate the inputs and an attacker can trigger a null pointer dereference. The [implementation](https://gith...
CVEs:CVE-2021-37648
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
PYSEC-2021-759
CVEs:CVE-2021-37648
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
Incorrect validation of `SaveV2` inputs
CVEs:CVE-2021-37648
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Incomplete validation in MKL requantization
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Incomplete validation in MKL requantization
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-287
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-578
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-776
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions due to incomplete validation in MKL implementation of requantization, an attacker can trigger undefined behavior via binding a reference to a null pointer or ca...
CVEs:CVE-2021-37665
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
Incomplete validation in MKL requantization
CVEs:CVE-2021-37665
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
PYSEC-2021-776
CVEs:CVE-2021-37665
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-25
Segfault and heap buffer overflow in `{Experimental,}DatasetToTFRecord`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-25
Segfault and heap buffer overflow in `{Experimental,}DatasetToTFRecord`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-272
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-563
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-761
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
Segfault and heap buffer overflow in `{Experimental,}DatasetToTFRecord`
CVEs:CVE-2021-37650
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
PYSEC-2021-761
CVEs:CVE-2021-37650
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation for `tf.raw_ops.ExperimentalDatasetToTFRecord` and `tf.raw_ops.DatasetToTFRecord` can trigger heap buffer overflow and segmentation fault. Th...
CVEs:CVE-2021-37650
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Heap OOB in nested `tf.map_fn` with `RaggedTensor`s
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Heap OOB in nested `tf.map_fn` with `RaggedTensor`s
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-301
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-592
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-790
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
PYSEC-2021-790
CVEs:CVE-2021-37679
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions it is possible to nest a `tf.map_fn` within another `tf.map_fn` call. However, if the input tensor is a `RaggedTensor` and there is no function signature provid...
CVEs:CVE-2021-37679
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
Heap OOB in nested `tf.map_fn` with `RaggedTensor`s
CVEs:CVE-2021-37679
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-25
Use of unitialized value in TFLite
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-25
Use of unitialized value in TFLite
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-304
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-595
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-793
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
PYSEC-2021-793
CVEs:CVE-2021-37682
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions all TFLite operations that use quantization can be made to use unitialized values. [For example](https://github.com/tensorflow/tensorflow/blob/460e000de3a83278f...
CVEs:CVE-2021-37682
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
Use of unitialized value in TFLite
CVEs:CVE-2021-37682
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Incomplete validation in `MaxPoolGrad`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Incomplete validation in `MaxPoolGrad`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-296
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-587
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-785
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can trigger a denial of service via a segmentation fault in `tf.raw_ops.MaxPoolGrad` caused by missing validation. The [implementation](https://gith...
CVEs:CVE-2021-37674
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
Incomplete validation in `MaxPoolGrad`
CVEs:CVE-2021-37674
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
PYSEC-2021-785
CVEs:CVE-2021-37674
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Reference binding to nullptr and heap OOB in binary cwise ops
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Reference binding to nullptr and heap OOB in binary cwise ops
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-281
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-572
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-770
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
PYSEC-2021-770
CVEs:CVE-2021-37659
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause undefined behavior via binding a reference to null pointer in all binary cwise operations that don't require broadcasting (e.g., gradients...
CVEs:CVE-2021-37659
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
Reference binding to nullptr and heap OOB in binary cwise ops
CVEs:CVE-2021-37659
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Crash in NMS ops caused by integer conversion to unsigned
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Crash in NMS ops caused by integer conversion to unsigned
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-291
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-582
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-780
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
PYSEC-2021-780
CVEs:CVE-2021-37669
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
Crash in NMS ops caused by integer conversion to unsigned
CVEs:CVE-2021-37669
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause denial of service in applications serving models using `tf.raw_ops.NonMaxSuppressionV5` by triggering a division by 0. The [implementation...
CVEs:CVE-2021-37669
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Heap buffer overflow in `FractionalAvgPoolGrad`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Heap buffer overflow in `FractionalAvgPoolGrad`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
PYSEC-2021-273
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
PYSEC-2021-564
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
PYSEC-2021-762
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
PYSEC-2021-762
CVEs:CVE-2021-37651
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
Heap buffer overflow in `FractionalAvgPoolGrad`
CVEs:CVE-2021-37651
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation for `tf.raw_ops.FractionalAvgPoolGrad` can be tricked into accessing data outside of bounds of heap allocated buffers. The [implementation](h...
CVEs:CVE-2021-37651
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Null pointer dereference and heap OOB read in operations restoring tensors
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Null pointer dereference and heap OOB read in operations restoring tensors
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-25
Use after free in boosted trees creation
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-25
Use after free in boosted trees creation
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Incomplete validation in `QuantizeV2`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Incomplete validation in `QuantizeV2`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Reference binding to nullptr in `RaggedTensorToVariant`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Reference binding to nullptr in `RaggedTensorToVariant`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Reference binding to nullptr in unicode encoding
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Reference binding to nullptr in unicode encoding
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Reference binding to nullptr in map operations
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Reference binding to nullptr in map operations
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Reference binding to nullptr in shape inference
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Reference binding to nullptr in shape inference
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
NPE in TFLite
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
NPE in TFLite
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Infinite loop in TFLite
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Infinite loop in TFLite
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-285
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-576
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-774
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions due to incomplete validation in `tf.raw_ops.QuantizeV2`, an attacker can trigger undefined behavior via binding a reference to a null pointer or can access data...
CVEs:CVE-2021-37663
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
Incomplete validation in `QuantizeV2`
CVEs:CVE-2021-37663
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
PYSEC-2021-774
CVEs:CVE-2021-37663
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-274
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-288
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-289
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-293
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-298
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-303
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-308
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-565
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-579
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-580
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-584
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-589
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-594
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-599
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-763
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-777
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-778
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-782
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-787
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-792
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-797
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
PYSEC-2021-792
CVEs:CVE-2021-37681
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of SVDF in TFLite is [vulnerable to a null pointer error](https://github.com/tensorflow/tensorflow/blob/460e000de3a83278fb00b61a16d161b1964f1...
CVEs:CVE-2021-37681
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
NPE in TFLite
CVEs:CVE-2021-37681
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions the strided slice implementation in TFLite has a logic bug which can allow an attacker to trigger an infinite loop. This arises from newly introduced support fo...
CVEs:CVE-2021-37686
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
Infinite loop in TFLite
CVEs:CVE-2021-37686
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
PYSEC-2021-797
CVEs:CVE-2021-37686
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
PYSEC-2021-787
CVEs:CVE-2021-37676
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
Reference binding to nullptr in shape inference
CVEs:CVE-2021-37676
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause undefined behavior via binding a reference to null pointer in `tf.raw_ops.SparseFillEmptyRows`. The shape inference [implementation](https...
CVEs:CVE-2021-37676
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
PYSEC-2021-782
CVEs:CVE-2021-37671
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause undefined behavior via binding a reference to null pointer in `tf.raw_ops.Map*` and `tf.raw_ops.OrderedMap*` operations. The [implementati...
CVEs:CVE-2021-37671
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
Reference binding to nullptr in map operations
CVEs:CVE-2021-37671
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
PYSEC-2021-777
CVEs:CVE-2021-37666
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
Reference binding to nullptr in `RaggedTensorToVariant`
CVEs:CVE-2021-37666
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause undefined behavior via binding a reference to null pointer in `tf.raw_ops.RaggedTensorToVariant`. The [implementation](https://github.com/...
CVEs:CVE-2021-37666
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
Reference binding to nullptr in unicode encoding
CVEs:CVE-2021-37667
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
PYSEC-2021-778
CVEs:CVE-2021-37667
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause undefined behavior via binding a reference to null pointer in `tf.raw_ops.UnicodeEncode`. The [implementation](https://github.com/tensorfl...
CVEs:CVE-2021-37667
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
PYSEC-2021-763
CVEs:CVE-2021-37652
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation for `tf.raw_ops.BoostedTreesCreateEnsemble` can result in a use after free error if an attacker supplies specially crafted arguments. The [im...
CVEs:CVE-2021-37652
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
Use after free in boosted trees creation
CVEs:CVE-2021-37652
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
PYSEC-2021-261
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
PYSEC-2021-552
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
PYSEC-2021-750
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
PYSEC-2021-750
CVEs:CVE-2021-37639
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. When restoring tensors via raw APIs, if the tensor name is not provided, TensorFlow can be tricked into dereferencing a null pointer. Alternatively, attackers can read memory outsid...
CVEs:CVE-2021-37639
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
Null pointer dereference and heap OOB read in operations restoring tensors
CVEs:CVE-2021-37639
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-25
Heap OOB in `SdcaOptimizerV2`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-25
Heap OOB in `SdcaOptimizerV2`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Heap OOB in TFLite
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Heap OOB in TFLite
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-25
Segfault on strings tensors with mistmatched dimensions, due to Go code
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-25
Segfault on strings tensors with mistmatched dimensions, due to Go code
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-294
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-307
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-314
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-585
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-598
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-605
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-783
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-796
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-803
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
PYSEC-2021-803
CVEs:CVE-2021-37692
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
Segfault on strings tensors with mistmatched dimensions, due to Go code
CVEs:CVE-2021-37692
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions under certain conditions, Go code can trigger a segfault in string deallocation. For string tensors, `C.TF_TString_Dealloc` is called during garbage collection ...
CVEs:CVE-2021-37692
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
Heap OOB in `SdcaOptimizerV2`
CVEs:CVE-2021-37672
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
PYSEC-2021-783
CVEs:CVE-2021-37672
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can read from outside of bounds of heap allocated data by sending specially crafted illegal arguments to `tf.raw_ops.SdcaOptimizerV2`. The [implemen...
CVEs:CVE-2021-37672
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions TFLite's [`expand_dims.cc`](https://github.com/tensorflow/tensorflow/blob/149562d49faa709ea80df1d99fc41d005b81082a/tensorflow/lite/kernels/expand_dims.cc#L36-L5...
CVEs:CVE-2021-37685
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
Heap OOB in TFLite
CVEs:CVE-2021-37685
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
PYSEC-2021-796
CVEs:CVE-2021-37685
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-25
Heap OOB in `UpperBound` and `LowerBound`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-25
Heap OOB in `UpperBound` and `LowerBound`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-292
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-583
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-781
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
Heap OOB in `UpperBound` and `LowerBound`
CVEs:CVE-2021-37670
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
PYSEC-2021-781
CVEs:CVE-2021-37670
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can read from outside of bounds of heap allocated data by sending specially crafted illegal arguments to `tf.raw_ops.UpperBound`. The [implementatio...
CVEs:CVE-2021-37670
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Heap out of bounds access in sparse reduction operations
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Heap out of bounds access in sparse reduction operations
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Null pointer dereference in `RaggedTensorToTensor`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Null pointer dereference in `RaggedTensorToTensor`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Heap OOB in `RaggedGather`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Heap OOB in `RaggedGather`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-25
Heap OOB and CHECK fail in `ResourceGather`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-25
Heap OOB and CHECK fail in `ResourceGather`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-25
Heap OOB in `ResourceScatterUpdate`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-25
Heap OOB in `ResourceScatterUpdate`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Reference binding to nullptr in `RaggedTensorToSparse`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Reference binding to nullptr in `RaggedTensorToSparse`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Reference binding to nullptr in `MatrixDiagV*` ops
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Reference binding to nullptr in `MatrixDiagV*` ops
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Reference binding to nullptr in `MatrixSetDiagV*` ops
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Reference binding to nullptr in `MatrixSetDiagV*` ops
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Heap OOB in boosted trees
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Heap OOB in boosted trees
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-257
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-263
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-276
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-277
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-278
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-279
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-280
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-286
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-548
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-554
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-567
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-568
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-569
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-570
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-571
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-577
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-746
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-752
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-765
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-766
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-767
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-768
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-769
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-775
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause undefined behavior via binding a reference to null pointer in `tf.raw_ops.RaggedTensorToSparse`. The [implementation](https://github.com/t...
CVEs:CVE-2021-37656
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
PYSEC-2021-767
CVEs:CVE-2021-37656
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
Reference binding to nullptr in `RaggedTensorToSparse`
CVEs:CVE-2021-37656
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause undefined behavior via binding a reference to null pointer in all operations of type `tf.raw_ops.MatrixDiagV*`. The [implementation](https...
CVEs:CVE-2021-37657
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
Reference binding to nullptr in `MatrixDiagV*` ops
CVEs:CVE-2021-37657
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
PYSEC-2021-768
CVEs:CVE-2021-37657
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause undefined behavior via binding a reference to null pointer in all operations of type `tf.raw_ops.MatrixSetDiagV*`. The [implementation](ht...
CVEs:CVE-2021-37658
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
Reference binding to nullptr in `MatrixSetDiagV*` ops
CVEs:CVE-2021-37658
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
PYSEC-2021-769
CVEs:CVE-2021-37658
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can trigger a crash via a `CHECK`-fail in debug builds of TensorFlow using `tf.raw_ops.ResourceGather` or a read from outside the bounds of heap all...
CVEs:CVE-2021-37654
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
Heap OOB and CHECK fail in `ResourceGather`
CVEs:CVE-2021-37654
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
PYSEC-2021-765
CVEs:CVE-2021-37654
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
Heap OOB in `RaggedGather`
CVEs:CVE-2021-37641
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions if the arguments to `tf.raw_ops.RaggedGather` don't determine a valid ragged tensor code can trigger a read from outside of bounds of heap allocated buffers. Th...
CVEs:CVE-2021-37641
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
PYSEC-2021-752
CVEs:CVE-2021-37641
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of sparse reduction operations in TensorFlow can trigger accesses outside of bounds of heap allocated data. The [implementation](https://gith...
CVEs:CVE-2021-37635
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
PYSEC-2021-746
CVEs:CVE-2021-37635
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
Heap out of bounds access in sparse reduction operations
CVEs:CVE-2021-37635
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
PYSEC-2021-775
CVEs:CVE-2021-37664
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can read from outside of bounds of heap allocated data by sending specially crafted illegal arguments to `BoostedTreesSparseCalculateBestFeatureSpli...
CVEs:CVE-2021-37664
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
Heap OOB in boosted trees
CVEs:CVE-2021-37664
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
Heap OOB in `ResourceScatterUpdate`
CVEs:CVE-2021-37655
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can trigger a read from outside of bounds of heap allocated data by sending invalid arguments to `tf.raw_ops.ResourceScatterUpdate`. The [implementa...
CVEs:CVE-2021-37655
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
PYSEC-2021-766
CVEs:CVE-2021-37655
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-260
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-551
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-749
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
Null pointer dereference in `RaggedTensorToTensor`
CVEs:CVE-2021-37638
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
PYSEC-2021-749
CVEs:CVE-2021-37638
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. Sending invalid argument for `row_partition_types` of `tf.raw_ops.RaggedTensorToTensor` API results in a null pointer dereference and undefined behavior. The [implementation](https:...
CVEs:CVE-2021-37638
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Null pointer dereference in TFLite
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Null pointer dereference in TFLite
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Null pointer dereference in TFLite MLIR optimizations
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Null pointer dereference in TFLite MLIR optimizations
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-310
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-311
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-601
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-602
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-799
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-800
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can craft a TFLite model that would trigger a null pointer dereference, which would result in a crash and denial of service. This is caused by the M...
CVEs:CVE-2021-37689
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
Null pointer dereference in TFLite MLIR optimizations
CVEs:CVE-2021-37689
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
PYSEC-2021-800
CVEs:CVE-2021-37689
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can craft a TFLite model that would trigger a null pointer dereference, which would result in a crash and denial of service. The [implementation](ht...
CVEs:CVE-2021-37688
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
PYSEC-2021-799
CVEs:CVE-2021-37688
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
Null pointer dereference in TFLite
CVEs:CVE-2021-37688
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-25
Use after free and segfault in shape inference functions
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-25
Use after free and segfault in shape inference functions
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-13
PYSEC-2021-312
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-13
PYSEC-2021-603
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-13
PYSEC-2021-801
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
Use after free and segfault in shape inference functions
CVEs:CVE-2021-37690
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions when running shape functions, some functions (such as `MutableHashTableShape`) produce extra output information in the form of a `ShapeAndType` struct. The shap...
CVEs:CVE-2021-37690
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
PYSEC-2021-801
CVEs:CVE-2021-37690
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Null pointer dereference in `CompressElement`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Null pointer dereference in `CompressElement`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Null pointer dereference in `MatrixDiagPartOp`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Null pointer dereference in `MatrixDiagPartOp`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Null pointer dereference in `SparseTensorSliceDataset`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Null pointer dereference in `SparseTensorSliceDataset`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Null pointer dereference in `UncompressElement`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Null pointer dereference in `UncompressElement`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Division by 0 in most convolution operators
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Division by 0 in most convolution operators
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-297
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-588
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-786
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
Division by 0 in most convolution operators
CVEs:CVE-2021-37675
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
PYSEC-2021-786
CVEs:CVE-2021-37675
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions most implementations of convolution operators in TensorFlow are affected by a division by 0 vulnerability where an attacker can trigger a denial of service via ...
CVEs:CVE-2021-37675
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-259
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-265
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-269
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-271
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-550
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-556
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-560
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-562
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-748
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-754
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-758
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-760
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. It is possible to trigger a null pointer dereference in TensorFlow by passing an invalid input to `tf.raw_ops.CompressElement`. The [implementation](https://github.com/tensorflow/te...
CVEs:CVE-2021-37637
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
Null pointer dereference in `CompressElement`
CVEs:CVE-2021-37637
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
PYSEC-2021-748
CVEs:CVE-2021-37637
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
Null pointer dereference in `UncompressElement`
CVEs:CVE-2021-37649
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. The code for `tf.raw_ops.UncompressElement` can be made to trigger a null pointer dereference. The [implementation](https://github.com/tensorflow/tensorflow/blob/f24faa153ad31a4b515...
CVEs:CVE-2021-37649
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
PYSEC-2021-760
CVEs:CVE-2021-37649
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
PYSEC-2021-758
CVEs:CVE-2021-37647
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. When a user does not supply arguments that determine a valid sparse tensor, `tf.raw_ops.SparseTensorSliceDataset` implementation can be made to dereference a null pointer. The [impl...
CVEs:CVE-2021-37647
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
Null pointer dereference in `SparseTensorSliceDataset`
CVEs:CVE-2021-37647
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
Null pointer dereference in `MatrixDiagPartOp`
CVEs:CVE-2021-37643
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. If a user does not provide a valid padding value to `tf.raw_ops.MatrixDiagPartOp`, then the code triggers a null pointer dereference (if input is empty) or produces invalid behavior...
CVEs:CVE-2021-37643
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
PYSEC-2021-754
CVEs:CVE-2021-37643
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
GoogleCoalition ESS < 30%2021-08-01
ASB-A-187074483
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel:Qualcomm |
affected |
Android |
:linux_kernel:Qualcomm |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-25
Division by 0 in `ResourceScatterDiv`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-25
Division by 0 in `ResourceScatterDiv`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-25
Bad alloc in `StringNGrams` caused by integer conversion
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-25
Bad alloc in `StringNGrams` caused by integer conversion
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-25
Division by 0 in inplace operations
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-25
Division by 0 in inplace operations
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-25
Crash caused by integer conversion to unsigned
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-25
Crash caused by integer conversion to unsigned
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
FPE in `tf.raw_ops.UnravelIndex`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
FPE in `tf.raw_ops.UnravelIndex`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
`CHECK`-fail in `MapStage`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
`CHECK`-fail in `MapStage`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-25
FPE in TFLite division operations
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-25
FPE in TFLite division operations
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-290
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-295
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-305
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-581
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-586
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-596
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-779
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-784
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-794
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
`CHECK`-fail in `MapStage`
CVEs:CVE-2021-37673
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can trigger a denial of service via a `CHECK`-fail in `tf.raw_ops.MapStage`. The [implementation](https://github.com/tensorflow/tensorflow/blob/460e...
CVEs:CVE-2021-37673
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
PYSEC-2021-784
CVEs:CVE-2021-37673
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of division in TFLite is [vulnerable to a division by 0 error](https://github.com/tensorflow/tensorflow/blob/460e000de3a83278fb00b61a16d161b1...
CVEs:CVE-2021-37683
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
PYSEC-2021-794
CVEs:CVE-2021-37683
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
FPE in TFLite division operations
CVEs:CVE-2021-37683
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
PYSEC-2021-779
CVEs:CVE-2021-37668
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause denial of service in applications serving models using `tf.raw_ops.UnravelIndex` by triggering a division by 0. The [implementation](https...
CVEs:CVE-2021-37668
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
FPE in `tf.raw_ops.UnravelIndex`
CVEs:CVE-2021-37668
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-268
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-283
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-559
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-574
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-757
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-772
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of `tf.raw_ops.StringNGrams` is vulnerable to an integer overflow issue caused by converting a signed integer value to an unsigned one and th...
CVEs:CVE-2021-37646
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
Bad alloc in `StringNGrams` caused by integer conversion
CVEs:CVE-2021-37646
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
PYSEC-2021-757
CVEs:CVE-2021-37646
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
Crash caused by integer conversion to unsigned
CVEs:CVE-2021-37661
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause a denial of service in `boosted_trees_create_quantile_stream_resource` by using negative arguments. The [implementation](https://github.co...
CVEs:CVE-2021-37661
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
PYSEC-2021-772
CVEs:CVE-2021-37661
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-264
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-282
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-555
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-573
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-753
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-771
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause a floating point exception by calling inplace operations with crafted arguments that would result in a division by 0. The [implementation]...
CVEs:CVE-2021-37660
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
Division by 0 in inplace operations
CVEs:CVE-2021-37660
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
PYSEC-2021-771
CVEs:CVE-2021-37660
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
PYSEC-2021-753
CVEs:CVE-2021-37642
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
Division by 0 in `ResourceScatterDiv`
CVEs:CVE-2021-37642
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of `tf.raw_ops.ResourceScatterDiv` is vulnerable to a division by 0 error. The [implementation](https://github.com/tensorflow/tensorflow/blob...
CVEs:CVE-2021-37642
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-25
Floating point exception in `SparseDenseCwiseDiv`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-25
Floating point exception in `SparseDenseCwiseDiv`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-25
Integer division by 0 in sparse reshaping
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-25
Integer division by 0 in sparse reshaping
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-25
`std::abort` raised from `TensorListReserve`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-25
`std::abort` raised from `TensorListReserve`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-25
Integer overflow due to conversion to unsigned
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-25
Integer overflow due to conversion to unsigned
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-25
Division by 0 in `ResourceGather`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-25
Division by 0 in `ResourceGather`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Division by zero in TFLite
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Division by zero in TFLite
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
FPE in LSH in TFLite
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
FPE in LSH in TFLite
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-313
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-604
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-802
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can craft a TFLite model that would trigger a division by zero error in LSH [implementation](https://github.com/tensorflow/tensorflow/blob/149562d49...
CVEs:CVE-2021-37691
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
PYSEC-2021-802
CVEs:CVE-2021-37691
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
FPE in LSH in TFLite
CVEs:CVE-2021-37691
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-302
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-593
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-791
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
PYSEC-2021-791
CVEs:CVE-2021-37680
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
Division by zero in TFLite
CVEs:CVE-2021-37680
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of fully connected layers in TFLite is [vulnerable to a division by zero error](https://github.com/tensorflow/tensorflow/blob/460e000de3a8327...
CVEs:CVE-2021-37680
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-266
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-267
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-557
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-558
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-755
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-756
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of `tf.raw_ops.QuantizeAndDequantizeV4Grad` is vulnerable to an integer overflow issue caused by converting a signed integer value to an unsi...
CVEs:CVE-2021-37645
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
PYSEC-2021-756
CVEs:CVE-2021-37645
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
Integer overflow due to conversion to unsigned
CVEs:CVE-2021-37645
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
`std::abort` raised from `TensorListReserve`
CVEs:CVE-2021-37644
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
PYSEC-2021-755
CVEs:CVE-2021-37644
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions providing a negative element to `num_elements` list argument of `tf.raw_ops.TensorListReserve` causes the runtime to abort the process due to reallocating a `st...
CVEs:CVE-2021-37644
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-258
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-262
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-275
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-549
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-553
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-566
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-747
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-751
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-764
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
PYSEC-2021-764
CVEs:CVE-2021-37653
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can trigger a crash via a floating point exception in `tf.raw_ops.ResourceGather`. The [implementation](https://github.com/tensorflow/tensorflow/blo...
CVEs:CVE-2021-37653
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
Division by 0 in `ResourceGather`
CVEs:CVE-2021-37653
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
Integer division by 0 in sparse reshaping
CVEs:CVE-2021-37640
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of `tf.raw_ops.SparseReshape` can be made to trigger an integral division by 0 exception. The [implementation](https://github.com/tensorflow/...
CVEs:CVE-2021-37640
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
PYSEC-2021-751
CVEs:CVE-2021-37640
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
Floating point exception in `SparseDenseCwiseDiv`
CVEs:CVE-2021-37636
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of `tf.raw_ops.SparseDenseCwiseDiv` is vulnerable to a division by 0 error. The [implementation](https://github.com/tensorflow/tensorflow/blo...
CVEs:CVE-2021-37636
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
PYSEC-2021-747
CVEs:CVE-2021-37636
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
GoogleCoalition ESS < 30%2021-08-02
CVEs:CVE-2021-22552
GoogleCoalition ESS < 30%MEDIUM2021-08-02
An untrusted memory read vulnerability in Asylo versions up to 0.6.1 allows an untrusted attacker to pass a syscall number in MessageReader that is then used by sysno() and can bypass validation. This can allow the attacker to read memory from within t...
CVEs:CVE-2021-22552
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| asylo |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Missing validation in shape inference for `Dequantize`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-25
Missing validation in shape inference for `Dequantize`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-299
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-590
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-788
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions the shape inference code for `tf.raw_ops.Dequantize` has a vulnerability that could trigger a denial of service via a segfault if an attacker provides invalid a...
CVEs:CVE-2021-37677
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
Missing validation in shape inference for `Dequantize`
CVEs:CVE-2021-37677
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
PYSEC-2021-788
CVEs:CVE-2021-37677
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
GoogleCoalition ESS < 30%2021-08-01
ASB-A-187073199
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel:Qualcomm |
affected |
Android |
:linux_kernel:Qualcomm |
— |
GoogleCoalition ESS < 30%NONE2021-08-01
PUB-A-168799695
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-25
FPE in TFLite pooling operations
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-25
FPE in TFLite pooling operations
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-306
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-597
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
PYSEC-2021-795
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
PYSEC-2021-795
CVEs:CVE-2021-37684
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-12
FPE in TFLite pooling operations
CVEs:CVE-2021-37684
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementations of pooling in TFLite are vulnerable to division by 0 errors as there are no checks for divisors not being 0. We have patched the issue in Gi...
CVEs:CVE-2021-37684
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2021-08-18
CVEs:CVE-2021-0407
Open SourceCoalition ESS < 30%HIGH2021-08-18
In clk driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05479659; ...
CVEs:CVE-2021-0407
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2021-08-18
CVEs:CVE-2021-0626
Open SourceCoalition ESS < 30%HIGH2021-08-18
In ged, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05687510; Issue ID: ...
CVEs:CVE-2021-0626
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2021-08-03
CVEs:CVE-2021-0573
Open SourceCoalition ESS < 30%HIGH2021-08-03
In asf extractor, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...
CVEs:CVE-2021-0573
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2021-08-03
CVEs:CVE-2021-0574
Open SourceCoalition ESS < 30%HIGH2021-08-03
In asf extractor, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...
CVEs:CVE-2021-0574
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-03
In flv extractor, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...
CVEs:CVE-2021-0576
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2021-08-03
CVEs:CVE-2021-0576
Open SourceCoalition ESS < 30%HIGH2021-08-03
In sendDevicePickedIntent of DevicePickerFragment.java, there is a possible way to invoke a privileged broadcast receiver due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction...
CVEs:CVE-2021-0593
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2021-08-03
CVEs:CVE-2021-0593
GoogleCoalition ESS < 30%HIGH2021-08-01
ASB-A-187231635
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2021-08-01
ASB-A-187234876
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2021-08-01
ASB-A-187236084
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%2021-08-03
CVEs:CVE-2021-0639
Open SourceCoalition ESS < 30%MEDIUM2021-08-03
In multiple functions of libl3oemcrypto.cpp, there is a possible weakness in the existing obfuscation mechanism due to the way sensitive data is handled. This could lead to local information disclosure with no additional execution privileges needed. Us...
CVEs:CVE-2021-0639
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2021-08-01
ASB-A-190724551
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-18
In asf extractor, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05...
CVEs:CVE-2021-0408
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2021-08-18
CVEs:CVE-2021-0408
GoogleCoalition ESS < 30%2021-08-18
CVEs:CVE-2021-0627
Open SourceCoalition ESS < 30%HIGH2021-08-18
In OMA DRM, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05722434; Issue ID: A...
CVEs:CVE-2021-0627
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2021-08-18
CVEs:CVE-2021-0628
Open SourceCoalition ESS < 30%HIGH2021-08-18
In OMA DRM, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05722454; Issue...
CVEs:CVE-2021-0628
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2021-08-03
CVEs:CVE-2021-0584
Open SourceCoalition ESS < 30%HIGH2021-08-03
In verifyBufferObject of Parcel.cpp, there is a possible out of bounds read due to an improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploita...
CVEs:CVE-2021-0584
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2021-08-18
CVEs:CVE-2021-0415
Open SourceCoalition ESS < 30%MEDIUM2021-08-18
In memory management driver, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. ...
CVEs:CVE-2021-0415
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2021-08-18
In memory management driver, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05...
CVEs:CVE-2021-0416
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2021-08-18
CVEs:CVE-2021-0416
Open SourceCoalition ESS < 30%MEDIUM2021-08-18
In memory management driver, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05...
CVEs:CVE-2021-0417
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2021-08-18
CVEs:CVE-2021-0417
Open SourceCoalition ESS < 30%MEDIUM2021-08-18
In memory management driver, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05...
CVEs:CVE-2021-0418
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2021-08-18
CVEs:CVE-2021-0418
GoogleCoalition ESS < 30%2021-08-18
CVEs:CVE-2021-0419
Open SourceCoalition ESS < 30%MEDIUM2021-08-18
In memory management driver, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05...
CVEs:CVE-2021-0419
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2021-08-18
CVEs:CVE-2021-0420
Open SourceCoalition ESS < 30%MEDIUM2021-08-18
In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403...
CVEs:CVE-2021-0420
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2021-08-03
CVEs:CVE-2021-0641
Open SourceCoalition ESS < 30%MEDIUM2021-08-03
In getAvailableSubscriptionInfoList of SubscriptionController.java, there is a possible disclosure of unique identifiers due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. ...
CVEs:CVE-2021-0641
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2021-08-12
An issue was discovered on LG mobile devices with Android OS P and Q software for mt6762/mt6765/mt6883. Attackers can change some of the NvRAM content by leveraging the misconfiguration of a debug command. The LG ID is LVE-SMP-210005 (August 2021).
CVEs:CVE-2021-38591
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2021-08-12
CVEs:CVE-2021-38591
GoogleCoalition ESS < 30%2021-08-05
CVEs:CVE-2021-25443
Open SourceCoalition ESS < 30%CRITICAL2021-08-05
A use after free vulnerability in conn_gadget driver prior to SMR AUG-2021 Release 1 allows malicious action by an attacker.
CVEs:CVE-2021-25443
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |