Google Security Advisories · November 2021 — Google Security Advisories
510 advisories 315 CVEs 17 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2021-11. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 17 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2021-42321

GoogleExploitedCISA KEV listedCRITICAL2021-11-09

Microsoft Exchange Server Remote Code Execution Vulnerability

CVEs:CVE-2021-42321

Affected products

ProductStatusVendorPackageEcosystem
exchange_server affected microsoft
Upstream advisory

CVE-2021-42292

GoogleExploitedCISA KEV listedHIGH2021-11-09

Microsoft Excel Security Feature Bypass Vulnerability

CVEs:CVE-2021-42292

Affected products

ProductStatusVendorPackageEcosystem
365_apps affected microsoft
excel affected microsoft
office affected microsoft
office_2016 affected microsoft
office_2019 affected microsoft
office_2021 affected microsoft
office_long_term_servicing_channel affected microsoft
Upstream advisory

DEBIAN-CVE-2021-38003

Open SourceExploitedCISA KEV listedHIGH2021-11-23

DEBIAN-CVE-2021-38003

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:11 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

openSUSE-SU-2021:1462-1

Open SourceExploitedCISA KEV listedCRITICAL2021-11-08

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP3 chromium
chromium affected openSUSE:Leap 15.2 chromium
chromium affected openSUSE:Leap 15.3 chromium
Upstream advisory

DEBIAN-CVE-2021-38000

Open SourceExploitedCISA KEV listedMEDIUM2021-11-23

DEBIAN-CVE-2021-38000

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
Upstream advisory

CVE-2021-1048

Project ZeroExploitedCISA KEV listed2021-11-02

In ep_loop_check_proc of eventpoll.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-204573007References: Upstream kernel

CVEs:CVE-2021-1048

Upstream advisory

CVE-2021-1048

Open SourceExploitedCISA KEV listedHIGH2021-11-02

In ep_loop_check_proc of eventpoll.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Pr...

CVEs:CVE-2021-1048

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-204573007

GoogleExploitedCISA KEV listedHIGH2021-11-01

ASB-A-204573007

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2021-0920

Project ZeroExploitedCISA KEV listed2021-11-02

In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-196926917References: Upstream kernel

CVEs:CVE-2021-0920

Upstream advisory

CVE-2021-0920

Open SourceExploitedCISA KEV listedHIGH2021-11-02

In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidV...

CVEs:CVE-2021-0920

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
linux_kernel affected linux
Upstream advisory

ASB-A-196926917

GoogleExploitedCISA KEV listedHIGH2021-11-01

ASB-A-196926917

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

DEBIAN-CVE-2021-38004

Open SourceActive exploitation (sightings)CRITICAL2021-11-23

DEBIAN-CVE-2021-38004

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-38004

GoogleActive exploitation (sightings)CRITICAL2021-11-23

Insufficient policy enforcement in Autofill in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2021-38004

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

DEBIAN-CVE-2021-38001

Open SourcePoC exploitHIGH2021-11-23

DEBIAN-CVE-2021-38001

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

ALSA-2021:4743

GooglePoC exploitCRITICAL2021-11-18

Moderate: llvm-toolset:rhel8 security update

Affected products

ProductStatusVendorPackageEcosystem
clang affected AlmaLinux:8 clang
clang-analyzer affected AlmaLinux:8 clang-analyzer
clang-devel affected AlmaLinux:8 clang-devel
clang-libs affected AlmaLinux:8 clang-libs
clang-resource-filesystem affected AlmaLinux:8 clang-resource-filesystem
clang-tools-extra affected AlmaLinux:8 clang-tools-extra
compiler-rt affected AlmaLinux:8 compiler-rt
git-clang-format affected AlmaLinux:8 git-clang-format
libomp affected AlmaLinux:8 libomp
libomp-devel affected AlmaLinux:8 libomp-devel
libomp-test affected AlmaLinux:8 libomp-test
lld affected AlmaLinux:8 lld
lldb affected AlmaLinux:8 lldb
lldb-devel affected AlmaLinux:8 lldb-devel
lld-devel affected AlmaLinux:8 lld-devel
lld-libs affected AlmaLinux:8 lld-libs
lld-test affected AlmaLinux:8 lld-test
llvm affected AlmaLinux:8 llvm
llvm-devel affected AlmaLinux:8 llvm-devel
llvm-doc affected AlmaLinux:8 llvm-doc
llvm-googletest affected AlmaLinux:8 llvm-googletest
llvm-libs affected AlmaLinux:8 llvm-libs
llvm-static affected AlmaLinux:8 llvm-static
llvm-test affected AlmaLinux:8 llvm-test
llvm-toolset affected AlmaLinux:8 llvm-toolset
python3-clang affected AlmaLinux:8 python3-clang
python3-lit affected AlmaLinux:8 python3-lit
python3-lldb affected AlmaLinux:8 python3-lldb
Upstream advisory

GHSA-f5f7-6478-qm6p

Open SourcePoC exploitHIGH2021-11-01

Files or Directories Accessible to External Parties in kubernetes

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

GHSA-f5f7-6478-qm6p

Open SourcePoC exploitHIGH2021-11-01

Files or Directories Accessible to External Parties in kubernetes

Affected products

ProductStatusVendorPackageEcosystem
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubernetes affected k8s.io k8s.io/kubernetes
kubernetes-dns-node-cache-1.17 affected chainguard kubernetes-dns-node-cache-1.17
Upstream advisory

OESA-2021-1443

Open SourcePoC exploit2021-11-26

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:20.03-LTS-SP1 golang
golang affected openEuler:20.03-LTS-SP2 golang
Upstream advisory

AZL-6451

Open SourcePoC exploitHIGH2021-11-08

CVE-2021-41771 affecting package golang for versions less than 1.17.8-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-79102

Open SourcePoC exploitHIGH2021-11-08

CVE-2021-41771 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

CVE-2021-41771

GooglePoC exploitHIGH2021-11-08

ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 Accesses a Memory Location After the End of a Buffer, aka an out-of-bounds slice situation.

CVEs:CVE-2021-41771

Affected products

ProductStatusVendorPackageEcosystem
debian_linux affected debian
fedora affected fedoraproject
go affected golang
Upstream advisory

DEBIAN-CVE-2021-41771

Open SourcePoC exploitHIGH2021-11-08

DEBIAN-CVE-2021-41771

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
Upstream advisory

RLSA-2021:4156

Open SourcePoC exploitHIGH2021-11-09

Moderate: go-toolset:rhel8 security, bug fix, and enhancement update

Affected products

ProductStatusVendorPackageEcosystem
delve affected Rocky Linux:8 delve
golang affected Rocky Linux:8 golang
go-toolset affected Rocky Linux:8 go-toolset
Upstream advisory

AZL-6452

Open SourcePoC exploitHIGH2021-11-08

CVE-2021-41772 affecting package golang for versions less than 1.17.8-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

CVE-2021-41772

GooglePoC exploitHIGH2021-11-08

Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing an invalid name or an empty filename field.

CVEs:CVE-2021-41772

Affected products

ProductStatusVendorPackageEcosystem
fedora affected fedoraproject
go affected golang
timesten_in-memory_database affected oracle
Upstream advisory

DEBIAN-CVE-2021-37980

Open SourcePoC exploitHIGH2021-11-02

DEBIAN-CVE-2021-37980

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-38008

GooglePoC exploitCRITICAL2021-11-22

Use after free in media in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-38008

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-42308

Open SourcePoC exploitHIGH2021-11-09

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVEs:CVE-2021-42308

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2021-43221

Open SourcePoC exploitCRITICAL2021-11-09

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVEs:CVE-2021-43221

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2021-38013

GooglePoC exploitCRITICAL2021-11-22

Heap buffer overflow in fingerprint recognition in Google Chrome on ChromeOS prior to 96.0.4664.45 allowed a remote attacker who had compromised a WebUI renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2021-38013

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-38005

GooglePoC exploitCRITICAL2021-11-22

Use after free in loader in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-38005

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-38006

GooglePoC exploitCRITICAL2021-11-22

Use after free in storage foundation in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-38006

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-38007

GooglePoC exploitHIGH2021-11-22

Type confusion in V8 in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-38007

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-38012

GooglePoC exploitHIGH2021-11-22

Type confusion in V8 in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-38012

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-38010

GooglePoC exploitMEDIUM2021-11-22

Inappropriate implementation in service workers in Google Chrome prior to 96.0.4664.45 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.

CVEs:CVE-2021-38010

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-38022

GooglePoC exploitMEDIUM2021-11-22

Inappropriate implementation in WebAuthentication in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2021-38022

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-38014

GooglePoC exploitCRITICAL2021-11-22

Out of bounds write in Swiftshader in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-38014

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-38009

GooglePoC exploitMEDIUM2021-11-22

Inappropriate implementation in cache in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2021-38009

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-38019

GooglePoC exploitCRITICAL2021-11-22

Insufficient policy enforcement in CORS in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2021-38019

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-38011

GooglePoC exploitCRITICAL2021-11-22

Use after free in storage foundation in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-38011

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-38016

GooglePoC exploitCRITICAL2021-11-22

Insufficient policy enforcement in background fetch in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass same origin policy via a crafted HTML page.

CVEs:CVE-2021-38016

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-38017

GooglePoC exploitCRITICAL2021-11-22

Insufficient policy enforcement in iframe sandbox in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

CVEs:CVE-2021-38017

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-38021

GooglePoC exploitMEDIUM2021-11-22

Inappropriate implementation in referrer in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

CVEs:CVE-2021-38021

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-38018

GooglePoC exploitMEDIUM2021-11-22

Inappropriate implementation in navigation in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

CVEs:CVE-2021-38018

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-38020

GooglePoC exploitCRITICAL2021-11-22

Insufficient policy enforcement in contacts picker in Google Chrome on Android prior to 96.0.4664.45 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2021-38020

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-38015

GooglePoC exploitHIGH2021-11-22

Inappropriate implementation in input in Google Chrome prior to 96.0.4664.45 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.

CVEs:CVE-2021-38015

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-0928

Open SourcePoC exploitHIGH2021-11-02

In createFromParcel of OutputConfiguration.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User i...

CVEs:CVE-2021-0928

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-rg3m-hqc5-344v

Open SourcePoC exploitHIGH2021-11-10

`SparseFillEmptyRows` heap OOB

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-rg3m-hqc5-344v

Open SourcePoC exploitHIGH2021-11-10

`SparseFillEmptyRows` heap OOB

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-374m-jm66-3vj8

Open SourcePoC exploitHIGH2021-11-10

Heap OOB in `SparseBinCount`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-374m-jm66-3vj8

Open SourcePoC exploitHIGH2021-11-10

Heap OOB in `SparseBinCount`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-416

Open SourcePoC exploitCRITICAL2021-11-05

PYSEC-2021-416

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-418

Open SourcePoC exploitCRITICAL2021-11-05

PYSEC-2021-418

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-633

Open SourcePoC exploitCRITICAL2021-11-05

PYSEC-2021-633

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-635

Open SourcePoC exploitCRITICAL2021-11-05

PYSEC-2021-635

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-831

Open SourcePoC exploitCRITICAL2021-11-05

PYSEC-2021-831

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-833

Open SourcePoC exploitCRITICAL2021-11-05

PYSEC-2021-833

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41226

Open SourcePoC exploitHIGH2021-11-05

Heap OOB in `SparseBinCount`

CVEs:CVE-2021-41226

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41226

Open SourcePoC exploitCRITICAL2021-11-05

TensorFlow is an open source platform for machine learning. In affected versions the implementation of `SparseBinCount` is vulnerable to a heap OOB access. This is because of missing validation between the elements of the `values` argument and the shap...

CVEs:CVE-2021-41226

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-41226

Open SourcePoC exploitHIGH2021-11-05

PYSEC-2021-833

CVEs:CVE-2021-41226

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41224

Open SourcePoC exploitHIGH2021-11-05

PYSEC-2021-831

CVEs:CVE-2021-41224

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41224

Open SourcePoC exploitCRITICAL2021-11-05

TensorFlow is an open source platform for machine learning. In affected versions the implementation of `SparseFillEmptyRows` can be made to trigger a heap OOB access. This occurs whenever the size of `indices` does not match the size of `values`. The f...

CVEs:CVE-2021-41224

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-41224

Open SourcePoC exploitHIGH2021-11-05

`SparseFillEmptyRows` heap OOB

CVEs:CVE-2021-41224

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-m342-ff57-4jcc

Open SourcePoC exploitHIGH2021-11-10

Heap OOB read in `tf.raw_ops.SparseCountSparseOutput`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-m342-ff57-4jcc

Open SourcePoC exploitHIGH2021-11-10

Heap OOB read in `tf.raw_ops.SparseCountSparseOutput`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-402

Open SourcePoC exploitCRITICAL2021-11-05

PYSEC-2021-402

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-619

Open SourcePoC exploitCRITICAL2021-11-05

PYSEC-2021-619

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-817

Open SourcePoC exploitCRITICAL2021-11-05

PYSEC-2021-817

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41210

Open SourcePoC exploitHIGH2021-11-05

PYSEC-2021-817

CVEs:CVE-2021-41210

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41210

Open SourcePoC exploitHIGH2021-11-05

Heap OOB read in `tf.raw_ops.SparseCountSparseOutput`

CVEs:CVE-2021-41210

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41210

Open SourcePoC exploitCRITICAL2021-11-05

TensorFlow is an open source platform for machine learning. In affected versions the shape inference functions for `SparseCountSparseOutput` can trigger a read outside of bounds of heap allocated array. The fix will be included in TensorFlow 2.7.0. We ...

CVEs:CVE-2021-41210

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-20166

Open SourcePoC exploitHIGH2021-11-09

In various methods of kernel base drivers, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2022-20166

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-34423

Open SourceCoalition ESS < 30%CRITICAL2021-11-24

A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings ...

CVEs:CVE-2021-34423

Affected products

ProductStatusVendorPackageEcosystem
android_meeting_sdk affected zoom
android_video_sdk affected zoom
controllers_for_zoom_rooms affected zoom
hybrid_mmr affected zoom
hybrid_zproxy affected zoom
iphone_os_meeting_sdk affected zoom
iphone_os_video_sdk affected zoom
macos_meeting_sdk affected zoom
macos_video_sdk affected zoom
meetings affected zoom
meetings_for_blackberry affected zoom
meetings_for_chrome_os affected zoom
meetings_for_intune affected zoom
rooms_for_conference_rooms affected zoom
vdi_azure_virtual_desktop affected zoom
vdi_citrix affected zoom
vdi_vmware affected zoom
vdi_windows_meeting_client affected zoom
virtual_desktop_infrastructure affected zoom
windows_meeting_sdk affected zoom
windows_video_sdk affected zoom
zoom_on-premise_meeting_connector_controller affected zoom
zoom_on-premise_meeting_connector_mmr affected zoom
zoom_on-premise_recording_connector affected zoom
zoom_on-premise_virtual_room_connector affected zoom
zoom_on-premise_virtual_room_connector_load_balancer affected zoom
Upstream advisory

DEBIAN-CVE-2021-37979

Open SourceCoalition ESS < 30%CRITICAL2021-11-02

DEBIAN-CVE-2021-37979

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-34424

Open SourceCoalition ESS < 30%HIGH2021-11-24

A vulnerability was discovered in the Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (...

CVEs:CVE-2021-34424

Affected products

ProductStatusVendorPackageEcosystem
android_meeting_sdk affected zoom
android_video_sdk affected zoom
controllers_for_zoom_rooms affected zoom
hybrid_mmr affected zoom
hybrid_zproxy affected zoom
iphone_os_meeting_sdk affected zoom
iphone_os_video_sdk affected zoom
macos_meeting_sdk affected zoom
macos_video_sdk affected zoom
meetings affected zoom
meetings_for_blackberry affected zoom
meetings_for_chrome_os affected zoom
meetings_for_intune affected zoom
rooms_for_conference_rooms affected zoom
vdi_azure_virtual_desktop affected zoom
vdi_citrix affected zoom
vdi_vmware affected zoom
virtual_desktop_infrastructure affected zoom
windows_meeting_sdk affected zoom
windows_video_sdk affected zoom
zoom_on-premise_meeting_connector_controller affected zoom
zoom_on-premise_meeting_connector_mmr affected zoom
zoom_on-premise_recording_connector affected zoom
zoom_on-premise_virtual_room_connector affected zoom
zoom_on-premise_virtual_room_connector_load_balancer affected zoom
Upstream advisory

CVE-2021-0889

Open SourceCoalition ESS < 30%HIGH2021-11-02

In Android TV , there is a possible silent pairing due to lack of rate limiting in the pairing flow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Andro...

CVEs:CVE-2021-0889

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-180745296

GoogleCoalition ESS < 30%HIGH2021-11-01

ASB-A-180745296

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

DEBIAN-CVE-2021-37981

Open SourceCoalition ESS < 30%CRITICAL2021-11-02

DEBIAN-CVE-2021-37981

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-37978

Open SourceCoalition ESS < 30%CRITICAL2021-11-02

DEBIAN-CVE-2021-37978

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-37984

Open SourceCoalition ESS < 30%CRITICAL2021-11-02

DEBIAN-CVE-2021-37984

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-39346

GoogleCoalition ESS < 30%HIGH2021-11-01

The Google Maps Easy WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/modules/marker_groups/views/tpl/mgrEditMarkerGroup.php file which allowed att...

CVEs:CVE-2021-39346

Affected products

ProductStatusVendorPackageEcosystem
easy_google_maps affected supsystic
Upstream advisory

DEBIAN-CVE-2021-37997

Open SourceCoalition ESS < 30%CRITICAL2021-11-23

DEBIAN-CVE-2021-37997

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-37998

Open SourceCoalition ESS < 30%CRITICAL2021-11-23

DEBIAN-CVE-2021-37998

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
Upstream advisory

DEBIAN-CVE-2021-38002

Open SourceCoalition ESS < 30%CRITICAL2021-11-23

DEBIAN-CVE-2021-38002

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-37992

Open SourceCoalition ESS < 30%HIGH2021-11-02

DEBIAN-CVE-2021-37992

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-0925

Open SourceCoalition ESS < 30%HIGH2021-11-02

In rw_t4t_sm_detect_ndef of rw_t4t.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure due to a limited change in behavior based on the out of bounds data with no additional exec...

CVEs:CVE-2021-0925

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2021-37999

Open SourceCoalition ESS < 30%MEDIUM2021-11-23

DEBIAN-CVE-2021-37999

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:11 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-37986

Open SourceCoalition ESS < 30%CRITICAL2021-11-02

DEBIAN-CVE-2021-37986

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-0650

Open SourceCoalition ESS < 30%HIGH2021-11-02

In WT_InterpolateNoLoop of eas_wtengine.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploita...

CVEs:CVE-2021-0650

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2021-37982

Open SourceCoalition ESS < 30%CRITICAL2021-11-02

DEBIAN-CVE-2021-37982

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-37983

Open SourceCoalition ESS < 30%CRITICAL2021-11-02

DEBIAN-CVE-2021-37983

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-37985

Open SourceCoalition ESS < 30%CRITICAL2021-11-02

DEBIAN-CVE-2021-37985

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-37977

Open SourceCoalition ESS < 30%CRITICAL2021-11-02

DEBIAN-CVE-2021-37977

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-37987

Open SourceCoalition ESS < 30%CRITICAL2021-11-02

DEBIAN-CVE-2021-37987

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-37988

Open SourceCoalition ESS < 30%CRITICAL2021-11-02

DEBIAN-CVE-2021-37988

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-37993

Open SourceCoalition ESS < 30%CRITICAL2021-11-02

DEBIAN-CVE-2021-37993

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-37989

Open SourceCoalition ESS < 30%MEDIUM2021-11-02

DEBIAN-CVE-2021-37989

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-37994

Open SourceCoalition ESS < 30%MEDIUM2021-11-02

DEBIAN-CVE-2021-37994

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-37995

Open SourceCoalition ESS < 30%MEDIUM2021-11-02

DEBIAN-CVE-2021-37995

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
Upstream advisory

DEBIAN-CVE-2021-37991

Open SourceCoalition ESS < 30%HIGH2021-11-02

DEBIAN-CVE-2021-37991

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6492

GoogleCoalition ESS < 30%CRITICAL2021-11-02

Use after free in ANGLE in Google Chrome prior to 83.0.4103.97 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2020-6492

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2020-6492

Open SourceCoalition ESS < 30%CRITICAL2021-11-02

DEBIAN-CVE-2020-6492

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-24594

GoogleCoalition ESS < 30%CRITICAL2021-11-08

The Translate WordPress – Google Language Translator WordPress plugin before 6.0.12 does not sanitise and escape some of its settings before outputting it in various pages, allowing high privilege users to perform Cross-Site Scripting attacks even wh...

CVEs:CVE-2021-24594

Affected products

ProductStatusVendorPackageEcosystem
google_language_translator affected gtranslate
Upstream advisory

CVE-2020-16048

GoogleCoalition ESS < 30%HIGH2021-11-02

Out of bounds read in ANGLE allowed a remote attacker to obtain sensitive data via a crafted HTML page.

CVEs:CVE-2020-16048

Affected products

ProductStatusVendorPackageEcosystem
angle affected google
Upstream advisory

DEBIAN-CVE-2021-37990

Open SourceCoalition ESS < 30%MEDIUM2021-11-02

DEBIAN-CVE-2021-37990

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-37996

Open SourceCoalition ESS < 30%MEDIUM2021-11-02

DEBIAN-CVE-2021-37996

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-0930

Open SourceCoalition ESS < 30%HIGH2021-11-02

In phNxpNciHal_process_ext_rsp of phNxpNciHal_ext.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over NFC with no additional execution privileges needed. User interaction is not neede...

CVEs:CVE-2021-0930

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-hfm8-2q22-h7hv

GoogleCoalition ESS < 30%CRITICAL2021-11-15

Cross-site Scripting in pegasus/google-for-jobs

Affected products

ProductStatusVendorPackageEcosystem
google-for-jobs affected pegasus pegasus/google-for-jobs
google-for-jobs affected pegasus pegasus/google-for-jobs
Upstream advisory

GHSA-hfm8-2q22-h7hv

GoogleCoalition ESS < 30%CRITICAL2021-11-15

Cross-site Scripting in pegasus/google-for-jobs

Affected products

ProductStatusVendorPackageEcosystem
google-for-jobs affected pegasus pegasus/google-for-jobs
Upstream advisory

CVE-2021-43561

GoogleCoalition ESS < 30%CRITICAL2021-11-10

An XSS issue was discovered in the google_for_jobs (aka Google for Jobs) extension before 1.5.1 and 2.x before 2.1.1 for TYPO3. The extension fails to properly encode user input for output in HTML context. A TYPO3 backend user account is required to ex...

CVEs:CVE-2021-43561

Affected products

ProductStatusVendorPackageEcosystem
google_for_jobs affected pega-sus
Upstream advisory

CVE-2021-43561

GoogleCoalition ESS < 30%MEDIUM2021-11-10

Cross-site Scripting in pegasus/google-for-jobs

CVEs:CVE-2021-43561

Affected products

ProductStatusVendorPackageEcosystem
google-for-jobs affected pegasus pegasus/google-for-jobs
Upstream advisory

CVE-2021-1045

Open SourceCoalition ESS < 30%HIGH2021-11-02

Product: AndroidVersions: Android kernelAndroid ID: A-195580473References: N/A

CVEs:CVE-2021-1045

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-195580473

GoogleCoalition ESS < 30%2021-11-01

PUB-A-195580473

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-0918

Open SourceCoalition ESS < 30%HIGH2021-11-02

In gatt_process_notification of gatt_cl.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed fo...

CVEs:CVE-2021-0918

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-22565

GoogleCoalition ESS < 30%MEDIUM2021-11-10

Insufficient Granularity of Access Control in github.com/google/exposure-notifications-verification-server

CVEs:CVE-2021-22565

Affected products

ProductStatusVendorPackageEcosystem
google/exposure-notifications-verification-server affected github.com github.com/google/exposure-notifications-verification-server
Upstream advisory

CVE-2021-22565

GoogleCoalition ESS < 30%MEDIUM2021-11-10

An attacker could prematurely expire a verification code, making it unusable by the patient, making the patient unable to upload their TEKs to generate exposure notifications. We recommend upgrading the Exposure Notification server to V1.1.2 or greater.

CVEs:CVE-2021-22565

Affected products

ProductStatusVendorPackageEcosystem
exposure_notification_verification_server affected google
Upstream advisory

GHSA-wx8q-rgfr-cf6v

GoogleCoalition ESS < 30%MEDIUM2021-11-10

Insufficient Granularity of Access Control in github.com/google/exposure-notifications-verification-server

Affected products

ProductStatusVendorPackageEcosystem
google/exposure-notifications-verification-server affected github.com github.com/google/exposure-notifications-verification-server
Upstream advisory

GHSA-wx8q-rgfr-cf6v

GoogleCoalition ESS < 30%MEDIUM2021-11-10

Insufficient Granularity of Access Control in github.com/google/exposure-notifications-verification-server

Affected products

ProductStatusVendorPackageEcosystem
google/exposure-notifications-verification-server affected github.com github.com/google/exposure-notifications-verification-server
Upstream advisory

CVE-2021-0933

Open SourceCoalition ESS < 30%HIGH2021-11-02

In onCreate of CompanionDeviceActivity.java or DeviceChooserActivity.java, there is a possible way for HTML tags to interfere with a consent dialog due to improper input validation. This could lead to remote escalation of privilege, confusing the user ...

CVEs:CVE-2021-0933

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-prcg-wp5q-rv7p

Open SourceCoalition ESS < 30%HIGH2021-11-10

Crashes due to overflow and `CHECK`-fail in ops with large tensor shapes

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-prcg-wp5q-rv7p

Open SourceCoalition ESS < 30%HIGH2021-11-10

Crashes due to overflow and `CHECK`-fail in ops with large tensor shapes

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-390

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-390

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-607

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-607

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-805

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-805

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41197

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

TensorFlow is an open source platform for machine learning. In affected versions TensorFlow allows tensor to have a large number of dimensions and each dimension can be as large as desired. However, the total number of elements in a tensor must fit wit...

CVEs:CVE-2021-41197

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-41197

Open SourceCoalition ESS < 30%HIGH2021-11-05

Crashes due to overflow and `CHECK`-fail in ops with large tensor shapes

CVEs:CVE-2021-41197

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41197

Open SourceCoalition ESS < 30%MEDIUM2021-11-05

PYSEC-2021-805

CVEs:CVE-2021-41197

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-j86v-p27c-73fm

Open SourceCoalition ESS < 30%HIGH2021-11-10

Unitialized access in `EinsumHelper::ParseEquation`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-j86v-p27c-73fm

Open SourceCoalition ESS < 30%HIGH2021-11-10

Unitialized access in `EinsumHelper::ParseEquation`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-394

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-394

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-611

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-611

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-809

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-809

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41201

Open SourceCoalition ESS < 30%HIGH2021-11-05

PYSEC-2021-809

CVEs:CVE-2021-41201

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41201

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

TensorFlow is an open source platform for machine learning. In affeced versions during execution, `EinsumHelper::ParseEquation()` is supposed to set the flags in `input_has_ellipsis` vector and `*output_has_ellipsis` boolean to indicate whether there i...

CVEs:CVE-2021-41201

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-41201

Open SourceCoalition ESS < 30%HIGH2021-11-05

Unitialized access in `EinsumHelper::ParseEquation`

CVEs:CVE-2021-41201

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-h67m-xg8f-fxcf

Open SourceCoalition ESS < 30%HIGH2021-11-10

Deadlock in mutually recursive `tf.function` objects

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-h67m-xg8f-fxcf

Open SourceCoalition ESS < 30%HIGH2021-11-10

Deadlock in mutually recursive `tf.function` objects

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-405

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-405

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-622

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-622

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-820

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-820

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41213

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

TensorFlow is an open source platform for machine learning. In affected versions the code behind `tf.function` API can be made to deadlock when two `tf.function` decorated Python functions are mutually recursive. This occurs due to using a non-reentran...

CVEs:CVE-2021-41213

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-41213

Open SourceCoalition ESS < 30%MEDIUM2021-11-05

PYSEC-2021-820

CVEs:CVE-2021-41213

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41213

Open SourceCoalition ESS < 30%HIGH2021-11-05

Deadlock in mutually recursive `tf.function` objects

CVEs:CVE-2021-41213

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-m539-j985-hcr8

Open SourceCoalition ESS < 30%HIGH2021-11-10

Crash in `max_pool3d` when size argument is 0 or negative

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-m539-j985-hcr8

Open SourceCoalition ESS < 30%HIGH2021-11-10

Crash in `max_pool3d` when size argument is 0 or negative

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-2p25-55c9-h58q

Open SourceCoalition ESS < 30%HIGH2021-11-10

Overflow/crash in `tf.tile` when tiling tensor is large

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-2p25-55c9-h58q

Open SourceCoalition ESS < 30%HIGH2021-11-10

Overflow/crash in `tf.tile` when tiling tensor is large

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-5hx2-qx8j-qjqm

Open SourceCoalition ESS < 30%HIGH2021-11-10

Overflow/crash in `tf.image.resize` when size is large

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-5hx2-qx8j-qjqm

Open SourceCoalition ESS < 30%HIGH2021-11-10

Overflow/crash in `tf.image.resize` when size is large

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-gh8h-7j2j-qv4f

Open SourceCoalition ESS < 30%HIGH2021-11-10

Incomplete validation in `tf.summary.create_file_writer`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-gh8h-7j2j-qv4f

Open SourceCoalition ESS < 30%HIGH2021-11-10

Incomplete validation in `tf.summary.create_file_writer`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-j8c8-67vp-6mx7

Open SourceCoalition ESS < 30%MEDIUM2021-11-10

Arbitrary memory read in `ImmutableConst`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-j8c8-67vp-6mx7

Open SourceCoalition ESS < 30%MEDIUM2021-11-10

Arbitrary memory read in `ImmutableConst`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-419

Open SourceCoalition ESS < 30%HIGH2021-11-05

PYSEC-2021-419

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-636

Open SourceCoalition ESS < 30%HIGH2021-11-05

PYSEC-2021-636

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-834

Open SourceCoalition ESS < 30%HIGH2021-11-05

PYSEC-2021-834

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41227

Open SourceCoalition ESS < 30%MEDIUM2021-11-05

PYSEC-2021-834

CVEs:CVE-2021-41227

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41227

Open SourceCoalition ESS < 30%HIGH2021-11-05

TensorFlow is an open source platform for machine learning. In affected versions the `ImmutableConst` operation in TensorFlow can be tricked into reading arbitrary memory contents. This is because the `tstring` TensorFlow string class has a special cas...

CVEs:CVE-2021-41227

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-41227

Open SourceCoalition ESS < 30%MEDIUM2021-11-05

Arbitrary memory read in `ImmutableConst`

CVEs:CVE-2021-41227

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-389

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-389

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-391

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-391

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-392

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-392

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-393

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-393

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-606

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-606

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-608

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-608

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-609

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-609

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-610

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-610

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-804

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-804

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-806

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-806

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-807

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-807

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-808

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-808

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41200

Open SourceCoalition ESS < 30%HIGH2021-11-05

Incomplete validation in `tf.summary.create_file_writer`

CVEs:CVE-2021-41200

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41200

Open SourceCoalition ESS < 30%MEDIUM2021-11-05

PYSEC-2021-808

CVEs:CVE-2021-41200

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41200

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

TensorFlow is an open source platform for machine learning. In affected versions if `tf.summary.create_file_writer` is called with non-scalar arguments code crashes due to a `CHECK`-fail. The fix will be included in TensorFlow 2.7.0. We will also cherr...

CVEs:CVE-2021-41200

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-41198

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

TensorFlow is an open source platform for machine learning. In affected versions if `tf.tile` is called with a large input argument then the TensorFlow process will crash due to a `CHECK`-failure caused by an overflow. The number of elements in the out...

CVEs:CVE-2021-41198

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-41198

Open SourceCoalition ESS < 30%MEDIUM2021-11-05

PYSEC-2021-806

CVEs:CVE-2021-41198

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41198

Open SourceCoalition ESS < 30%HIGH2021-11-05

Overflow/crash in `tf.tile` when tiling tensor is large

CVEs:CVE-2021-41198

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41199

Open SourceCoalition ESS < 30%HIGH2021-11-05

Overflow/crash in `tf.image.resize` when size is large

CVEs:CVE-2021-41199

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41199

Open SourceCoalition ESS < 30%MEDIUM2021-11-05

PYSEC-2021-807

CVEs:CVE-2021-41199

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41199

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

TensorFlow is an open source platform for machine learning. In affected versions if `tf.image.resize` is called with a large input argument then the TensorFlow process will crash due to a `CHECK`-failure caused by an overflow. The number of elements in...

CVEs:CVE-2021-41199

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-41196

Open SourceCoalition ESS < 30%MEDIUM2021-11-05

PYSEC-2021-804

CVEs:CVE-2021-41196

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41196

Open SourceCoalition ESS < 30%HIGH2021-11-05

Crash in `max_pool3d` when size argument is 0 or negative

CVEs:CVE-2021-41196

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41196

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

TensorFlow is an open source platform for machine learning. In affected versions the Keras pooling layers can trigger a segfault if the size of the pool is 0 or if a dimension is negative. This is due to the TensorFlow's implementation of pooling opera...

CVEs:CVE-2021-41196

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

GHSA-cqv6-3phm-hcwx

Open SourceCoalition ESS < 30%HIGH2021-11-10

Access to invalid memory during shape inference in `Cudnn*` ops

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-cqv6-3phm-hcwx

Open SourceCoalition ESS < 30%HIGH2021-11-10

Access to invalid memory during shape inference in `Cudnn*` ops

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-413

Open SourceCoalition ESS < 30%HIGH2021-11-05

PYSEC-2021-413

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-630

Open SourceCoalition ESS < 30%HIGH2021-11-05

PYSEC-2021-630

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-828

Open SourceCoalition ESS < 30%HIGH2021-11-05

PYSEC-2021-828

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41221

Open SourceCoalition ESS < 30%HIGH2021-11-05

Access to invalid memory during shape inference in `Cudnn*` ops

CVEs:CVE-2021-41221

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41221

Open SourceCoalition ESS < 30%HIGH2021-11-05

PYSEC-2021-828

CVEs:CVE-2021-41221

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41221

Open SourceCoalition ESS < 30%HIGH2021-11-05

TensorFlow is an open source platform for machine learning. In affected versions the shape inference code for the `Cudnn*` operations in TensorFlow can be tricked into accessing invalid memory, via a heap buffer overflow. This occurs because the ranks ...

CVEs:CVE-2021-41221

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

GHSA-vwhq-49r4-gj9v

Open SourceCoalition ESS < 30%HIGH2021-11-10

Reference binding to `nullptr` in `tf.ragged.cross`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-vwhq-49r4-gj9v

Open SourceCoalition ESS < 30%HIGH2021-11-10

Reference binding to `nullptr` in `tf.ragged.cross`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-3rcw-9p9x-582v

Open SourceCoalition ESS < 30%CRITICAL2021-11-10

Code injection in `saved_model_cli`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-3rcw-9p9x-582v

Open SourceCoalition ESS < 30%CRITICAL2021-11-10

Code injection in `saved_model_cli`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-420

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-420

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-637

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-637

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-835

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-835

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41228

Open SourceCoalition ESS < 30%HIGH2021-11-05

PYSEC-2021-835

CVEs:CVE-2021-41228

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41228

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

TensorFlow is an open source platform for machine learning. In affected versions TensorFlow's `saved_model_cli` tool is vulnerable to a code injection as it calls `eval` on user supplied strings. This can be used by attackers to run arbitrary code on t...

CVEs:CVE-2021-41228

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-41228

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

Code injection in `saved_model_cli`

CVEs:CVE-2021-41228

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-406

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-406

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-623

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-623

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-821

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-821

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41214

Open SourceCoalition ESS < 30%HIGH2021-11-05

PYSEC-2021-821

CVEs:CVE-2021-41214

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41214

Open SourceCoalition ESS < 30%HIGH2021-11-05

Reference binding to `nullptr` in `tf.ragged.cross`

CVEs:CVE-2021-41214

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41214

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

TensorFlow is an open source platform for machine learning. In affected versions the shape inference code for `tf.ragged.cross` has an undefined behavior due to binding a reference to `nullptr`. The fix will be included in TensorFlow 2.7.0. We will als...

CVEs:CVE-2021-41214

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

GHSA-cq76-mxrc-vchh

Open SourceCoalition ESS < 30%HIGH2021-11-10

Crash in `tf.math.segment_*` operations

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-cq76-mxrc-vchh

Open SourceCoalition ESS < 30%HIGH2021-11-10

Crash in `tf.math.segment_*` operations

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-842

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-842

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-844

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-844

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-846

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-846

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41195

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

TensorFlow is an open source platform for machine learning. In affected versions the implementation of `tf.math.segment_*` operations results in a `CHECK`-fail related abort (and denial of service) if a segment id in `segment_ids` is large. This is sim...

CVEs:CVE-2021-41195

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-41195

Open SourceCoalition ESS < 30%HIGH2021-11-05

Crash in `tf.math.segment_*` operations

CVEs:CVE-2021-41195

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41195

Open SourceCoalition ESS < 30%MEDIUM2021-11-05

PYSEC-2021-846

CVEs:CVE-2021-41195

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-4f99-p9c2-3j8x

Open SourceCoalition ESS < 30%HIGH2021-11-10

Undefined behavior via `nullptr` reference binding in sparse matrix multiplication

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-4f99-p9c2-3j8x

Open SourceCoalition ESS < 30%HIGH2021-11-10

Undefined behavior via `nullptr` reference binding in sparse matrix multiplication

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-gpfh-jvf9-7wg5

Open SourceCoalition ESS < 30%CRITICAL2021-11-10

Use after free / memory leak in `CollectiveReduceV2`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-gpfh-jvf9-7wg5

Open SourceCoalition ESS < 30%CRITICAL2021-11-10

Use after free / memory leak in `CollectiveReduceV2`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-412

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-412

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-629

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-629

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-827

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-827

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41220

Open SourceCoalition ESS < 30%HIGH2021-11-05

PYSEC-2021-827

CVEs:CVE-2021-41220

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41220

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

Use after free / memory leak in `CollectiveReduceV2`

CVEs:CVE-2021-41220

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41220

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

TensorFlow is an open source platform for machine learning. In affected versions the async implementation of `CollectiveReduceV2` suffers from a memory leak and a use after free. This occurs due to the asynchronous computation and the fact that objects...

CVEs:CVE-2021-41220

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

PYSEC-2021-411

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-411

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-628

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-628

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-826

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-826

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41219

Open SourceCoalition ESS < 30%HIGH2021-11-05

PYSEC-2021-826

CVEs:CVE-2021-41219

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41219

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

TensorFlow is an open source platform for machine learning. In affected versions the code for sparse matrix multiplication is vulnerable to undefined behavior via binding a reference to `nullptr`. This occurs whenever the dimensions of `a` or `b` are 0...

CVEs:CVE-2021-41219

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-41219

Open SourceCoalition ESS < 30%HIGH2021-11-05

Undefined behavior via `nullptr` reference binding in sparse matrix multiplication

CVEs:CVE-2021-41219

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-xrqm-fpgr-6hhx

Open SourceCoalition ESS < 30%HIGH2021-11-10

Overflow/crash in `tf.range`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-xrqm-fpgr-6hhx

Open SourceCoalition ESS < 30%HIGH2021-11-10

Overflow/crash in `tf.range`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-395

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-395

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-612

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-612

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-810

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-810

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41202

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

TensorFlow is an open source platform for machine learning. In affected versions while calculating the size of the output within the `tf.range` kernel, there is a conditional statement of type `int64 = condition ? int64 : double`. Due to C++ implicit c...

CVEs:CVE-2021-41202

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-41202

Open SourceCoalition ESS < 30%HIGH2021-11-05

Overflow/crash in `tf.range`

CVEs:CVE-2021-41202

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41202

Open SourceCoalition ESS < 30%MEDIUM2021-11-05

PYSEC-2021-810

CVEs:CVE-2021-41202

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-cvgx-3v3q-m36c

Open SourceCoalition ESS < 30%HIGH2021-11-10

Heap OOB in shape inference for `QuantizeV2`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-cvgx-3v3q-m36c

Open SourceCoalition ESS < 30%HIGH2021-11-10

Heap OOB in shape inference for `QuantizeV2`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-fr77-rrx3-cp7g

Open SourceCoalition ESS < 30%HIGH2021-11-10

Heap OOB read in `tf.ragged.cross`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-fr77-rrx3-cp7g

Open SourceCoalition ESS < 30%HIGH2021-11-10

Heap OOB read in `tf.ragged.cross`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-f54p-f6jp-4rhr

Open SourceCoalition ESS < 30%HIGH2021-11-10

Heap OOB in `FusedBatchNorm` kernels

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-f54p-f6jp-4rhr

Open SourceCoalition ESS < 30%HIGH2021-11-10

Heap OOB in `FusedBatchNorm` kernels

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-403

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-403

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-404

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-404

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-415

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-415

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-620

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-620

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-621

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-621

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-632

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-632

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-818

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-818

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-819

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-819

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-830

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-830

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41223

Open SourceCoalition ESS < 30%HIGH2021-11-05

Heap OOB in `FusedBatchNorm` kernels

CVEs:CVE-2021-41223

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41223

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

TensorFlow is an open source platform for machine learning. In affected versions the implementation of `FusedBatchNorm` kernels is vulnerable to a heap OOB access. The fix will be included in TensorFlow 2.7.0. We will also cherrypick this commit on Ten...

CVEs:CVE-2021-41223

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-41223

Open SourceCoalition ESS < 30%HIGH2021-11-05

PYSEC-2021-830

CVEs:CVE-2021-41223

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41212

Open SourceCoalition ESS < 30%HIGH2021-11-05

PYSEC-2021-819

CVEs:CVE-2021-41212

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41212

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

TensorFlow is an open source platform for machine learning. In affected versions the shape inference code for `tf.ragged.cross` can trigger a read outside of bounds of heap allocated array. The fix will be included in TensorFlow 2.7.0. We will also che...

CVEs:CVE-2021-41212

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-41212

Open SourceCoalition ESS < 30%HIGH2021-11-05

Heap OOB read in `tf.ragged.cross`

CVEs:CVE-2021-41212

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41211

Open SourceCoalition ESS < 30%HIGH2021-11-05

PYSEC-2021-818

CVEs:CVE-2021-41211

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41211

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

TensorFlow is an open source platform for machine learning. In affected versions the shape inference code for `QuantizeV2` can trigger a read outside of bounds of heap allocated array. This occurs whenever `axis` is a negative value less than `-1`. In ...

CVEs:CVE-2021-41211

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-41211

Open SourceCoalition ESS < 30%HIGH2021-11-05

Heap OOB in shape inference for `QuantizeV2`

CVEs:CVE-2021-41211

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-7r94-xv9v-63jw

Open SourceCoalition ESS < 30%MEDIUM2021-11-10

A use of uninitialized value vulnerability in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-7r94-xv9v-63jw

Open SourceCoalition ESS < 30%MEDIUM2021-11-10

A use of uninitialized value vulnerability in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-417

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-417

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-634

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-634

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-832

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-832

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41225

Open SourceCoalition ESS < 30%MEDIUM2021-11-05

PYSEC-2021-832

CVEs:CVE-2021-41225

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41225

Open SourceCoalition ESS < 30%MEDIUM2021-11-05

A use of uninitialized value vulnerability in Tensorflow

CVEs:CVE-2021-41225

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41225

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

TensorFlow is an open source platform for machine learning. In affected versions TensorFlow's Grappler optimizer has a use of unitialized variable. If the `train_nodes` vector (obtained from the saved model that gets optimized) does not contain a `Dequ...

CVEs:CVE-2021-41225

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

GHSA-7pxj-m4jf-r6h2

Open SourceCoalition ESS < 30%CRITICAL2021-11-10

Missing validation during checkpoint loading

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-7pxj-m4jf-r6h2

Open SourceCoalition ESS < 30%CRITICAL2021-11-10

Missing validation during checkpoint loading

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-396

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-396

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-613

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-613

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-811

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-811

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41203

Open SourceCoalition ESS < 30%HIGH2021-11-05

PYSEC-2021-811

CVEs:CVE-2021-41203

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41203

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

Missing validation during checkpoint loading

CVEs:CVE-2021-41203

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41203

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

TensorFlow is an open source platform for machine learning. In affected versions an attacker can trigger undefined behavior, integer overflows, segfaults and `CHECK`-fail crashes if they can change saved checkpoints from outside of TensorFlow. This is ...

CVEs:CVE-2021-41203

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

GHSA-x3v8-c8qx-3j3r

Open SourceCoalition ESS < 30%MEDIUM2021-11-10

Null pointer exception in `DeserializeSparse`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-x3v8-c8qx-3j3r

Open SourceCoalition ESS < 30%MEDIUM2021-11-10

Null pointer exception in `DeserializeSparse`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-5crj-c72x-m7gq

Open SourceCoalition ESS < 30%HIGH2021-11-10

Null pointer exception when `Exit` node is not preceded by `Enter` op

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-5crj-c72x-m7gq

Open SourceCoalition ESS < 30%HIGH2021-11-10

Null pointer exception when `Exit` node is not preceded by `Enter` op

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-cpf4-wx82-gxp6

Open SourceCoalition ESS < 30%MEDIUM2021-11-10

Segfault due to negative splits in `SplitV`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-cpf4-wx82-gxp6

Open SourceCoalition ESS < 30%MEDIUM2021-11-10

Segfault due to negative splits in `SplitV`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-414

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-414

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-631

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-631

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-829

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-829

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41222

Open SourceCoalition ESS < 30%MEDIUM2021-11-05

Segfault due to negative splits in `SplitV`

CVEs:CVE-2021-41222

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41222

Open SourceCoalition ESS < 30%MEDIUM2021-11-05

PYSEC-2021-829

CVEs:CVE-2021-41222

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41222

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

TensorFlow is an open source platform for machine learning. In affected versions the implementation of `SplitV` can trigger a segfault is an attacker supplies negative arguments. This occurs whenever `size_splits` contains more than one value and at le...

CVEs:CVE-2021-41222

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

PYSEC-2021-407

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-407

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-409

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-409

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-624

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-624

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-626

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-626

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-822

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-822

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-824

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-824

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41215

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

TensorFlow is an open source platform for machine learning. In affected versions the shape inference code for `DeserializeSparse` can trigger a null pointer dereference. This is because the shape inference function assumes that the `serialize_sparse` t...

CVEs:CVE-2021-41215

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-41215

Open SourceCoalition ESS < 30%MEDIUM2021-11-05

Null pointer exception in `DeserializeSparse`

CVEs:CVE-2021-41215

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41215

Open SourceCoalition ESS < 30%MEDIUM2021-11-05

PYSEC-2021-822

CVEs:CVE-2021-41215

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41217

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

TensorFlow is an open source platform for machine learning. In affected versions the process of building the control flow graph for a TensorFlow model is vulnerable to a null pointer exception when nodes that should be paired are not. This occurs becau...

CVEs:CVE-2021-41217

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-41217

Open SourceCoalition ESS < 30%HIGH2021-11-05

Null pointer exception when `Exit` node is not preceded by `Enter` op

CVEs:CVE-2021-41217

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41217

Open SourceCoalition ESS < 30%MEDIUM2021-11-05

PYSEC-2021-824

CVEs:CVE-2021-41217

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-pgcq-h79j-2f69

Open SourceCoalition ESS < 30%HIGH2021-11-10

Incomplete validation of shapes in multiple TF ops

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-pgcq-h79j-2f69

Open SourceCoalition ESS < 30%HIGH2021-11-10

Incomplete validation of shapes in multiple TF ops

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-843

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-843

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-845

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-845

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-847

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-847

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41206

Open SourceCoalition ESS < 30%HIGH2021-11-05

Incomplete validation of shapes in multiple TF ops

CVEs:CVE-2021-41206

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41206

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

TensorFlow is an open source platform for machine learning. In affected versions several TensorFlow operations are missing validation for the shapes of the tensor arguments involved in the call. Depending on the API, this can result in undefined behavi...

CVEs:CVE-2021-41206

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-41206

Open SourceCoalition ESS < 30%HIGH2021-11-05

PYSEC-2021-847

CVEs:CVE-2021-41206

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-57wx-m983-2f88

Open SourceCoalition ESS < 30%CRITICAL2021-11-10

Incomplete validation in boosted trees code

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-57wx-m983-2f88

Open SourceCoalition ESS < 30%CRITICAL2021-11-10

Incomplete validation in boosted trees code

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-400

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-400

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-617

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-617

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-815

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-815

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41208

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

Incomplete validation in boosted trees code

CVEs:CVE-2021-41208

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41208

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-815

CVEs:CVE-2021-41208

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41208

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

TensorFlow is an open source platform for machine learning. In affected versions the code for boosted trees in TensorFlow is still missing validation. As a result, attackers can trigger denial of service (via dereferencing `nullptr`s or via `CHECK`-fai...

CVEs:CVE-2021-41208

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-0434

Open SourceCoalition ESS < 30%HIGH2021-11-02

In onReceive of BluetoothPermissionRequest.java, there is a possible phishing attack allowing a malicious Bluetooth device to acquire permissions based on insufficient information presented to the user in the consent dialog. This could lead to local es...

CVEs:CVE-2021-0434

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-3ff2-r28g-w7h9

Open SourceCoalition ESS < 30%CRITICAL2021-11-10

Heap buffer overflow in `Transpose`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-3ff2-r28g-w7h9

Open SourceCoalition ESS < 30%CRITICAL2021-11-10

Heap buffer overflow in `Transpose`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-408

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-408

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-625

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-625

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-823

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-823

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41216

Open SourceCoalition ESS < 30%MEDIUM2021-11-05

PYSEC-2021-823

CVEs:CVE-2021-41216

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41216

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

Heap buffer overflow in `Transpose`

CVEs:CVE-2021-41216

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41216

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

TensorFlow is an open source platform for machine learning. In affected versions the shape inference function for `Transpose` is vulnerable to a heap buffer overflow. This occurs whenever `perm` contains negative elements. The shape inference function ...

CVEs:CVE-2021-41216

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-0929

Open SourceCoalition ESS < 30%HIGH2021-11-02

In ion_dma_buf_end_cpu_access and related functions of ion.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not ne...

CVEs:CVE-2021-0929

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-187527909

GoogleCoalition ESS < 30%HIGH2021-11-01

ASB-A-187527909

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2021-0924

Open SourceCoalition ESS < 30%HIGH2021-11-02

In xhci_vendor_get_ops of xhci.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Pro...

CVEs:CVE-2021-0924

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-194461020

GoogleCoalition ESS < 30%NONE2021-11-01

ASB-A-194461020

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

GHSA-49rx-x2rw-pc6f

Open SourceCoalition ESS < 30%HIGH2021-11-10

Heap OOB read in all `tf.raw_ops.QuantizeAndDequantizeV*` ops

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-49rx-x2rw-pc6f

Open SourceCoalition ESS < 30%HIGH2021-11-10

Heap OOB read in all `tf.raw_ops.QuantizeAndDequantizeV*` ops

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-398

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-398

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-615

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-615

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-813

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-813

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41205

Open SourceCoalition ESS < 30%HIGH2021-11-05

Heap OOB read in all `tf.raw_ops.QuantizeAndDequantizeV*` ops

CVEs:CVE-2021-41205

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41205

Open SourceCoalition ESS < 30%HIGH2021-11-05

PYSEC-2021-813

CVEs:CVE-2021-41205

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41205

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

TensorFlow is an open source platform for machine learning. In affected versions the shape inference functions for the `QuantizeAndDequantizeV*` operations can trigger a read outside of bounds of heap allocated array. The fix will be included in Tensor...

CVEs:CVE-2021-41205

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

PUB-A-187084058

GoogleCoalition ESS < 30%2021-11-01

PUB-A-187084058

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

PUB-A-187084382

GoogleCoalition ESS < 30%2021-11-01

PUB-A-187084382

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

GHSA-786j-5qwq-r36x

Open SourceCoalition ESS < 30%CRITICAL2021-11-10

Segfault while copying constant resource tensor

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-786j-5qwq-r36x

Open SourceCoalition ESS < 30%CRITICAL2021-11-10

Segfault while copying constant resource tensor

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-7v94-64hj-m82h

Open SourceCoalition ESS < 30%MEDIUM2021-11-10

FPE in `ParallelConcat`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-7v94-64hj-m82h

Open SourceCoalition ESS < 30%MEDIUM2021-11-10

FPE in `ParallelConcat`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-6hpv-v2rx-c5g6

Open SourceCoalition ESS < 30%MEDIUM2021-11-10

FPE in convolutions with zero size filters

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-6hpv-v2rx-c5g6

Open SourceCoalition ESS < 30%MEDIUM2021-11-10

FPE in convolutions with zero size filters

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-399

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-399

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-401

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-401

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-616

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-616

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-618

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-618

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-814

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-814

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-816

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-816

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41207

Open SourceCoalition ESS < 30%MEDIUM2021-11-05

PYSEC-2021-814

CVEs:CVE-2021-41207

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41207

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

TensorFlow is an open source platform for machine learning. In affected versions the implementation of `ParallelConcat` misses some input validation and can produce a division by 0. The fix will be included in TensorFlow 2.7.0. We will also cherrypick ...

CVEs:CVE-2021-41207

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-41207

Open SourceCoalition ESS < 30%MEDIUM2021-11-05

FPE in `ParallelConcat`

CVEs:CVE-2021-41207

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41209

Open SourceCoalition ESS < 30%MEDIUM2021-11-05

FPE in convolutions with zero size filters

CVEs:CVE-2021-41209

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41209

Open SourceCoalition ESS < 30%MEDIUM2021-11-05

PYSEC-2021-816

CVEs:CVE-2021-41209

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41209

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

TensorFlow is an open source platform for machine learning. In affected versions the implementations for convolution operators trigger a division by 0 if passed empty filter tensor arguments. The fix will be included in TensorFlow 2.7.0. We will also c...

CVEs:CVE-2021-41209

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

PYSEC-2021-397

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-397

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-614

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-614

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-812

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-812

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41204

Open SourceCoalition ESS < 30%MEDIUM2021-11-05

PYSEC-2021-812

CVEs:CVE-2021-41204

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41204

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

Segfault while copying constant resource tensor

CVEs:CVE-2021-41204

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41204

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

TensorFlow is an open source platform for machine learning. In affected versions during TensorFlow's Grappler optimizer phase, constant folding might attempt to deep copy a resource tensor. This results in a segfault, as these tensors are supposed to n...

CVEs:CVE-2021-41204

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-0931

Open SourceCoalition ESS < 30%MEDIUM2021-11-02

In getAlias of BluetoothDevice.java, there is a possible way to create misleading permission dialogs due to missing data filtering. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for ex...

CVEs:CVE-2021-0931

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-9crf-c6qr-r273

Open SourceCoalition ESS < 30%MEDIUM2021-11-10

Integer division by 0 in `tf.raw_ops.AllToAll`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-9crf-c6qr-r273

Open SourceCoalition ESS < 30%MEDIUM2021-11-10

Integer division by 0 in `tf.raw_ops.AllToAll`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2021-410

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-410

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2021-627

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-627

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2021-825

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

PYSEC-2021-825

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41218

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

TensorFlow is an open source platform for machine learning. In affected versions the shape inference code for `AllToAll` can be made to execute a division by 0. This occurs whenever the `split_count` argument is 0. The fix will be included in TensorFlo...

CVEs:CVE-2021-41218

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-41218

Open SourceCoalition ESS < 30%MEDIUM2021-11-05

Integer division by 0 in `tf.raw_ops.AllToAll`

CVEs:CVE-2021-41218

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-41218

Open SourceCoalition ESS < 30%MEDIUM2021-11-05

PYSEC-2021-825

CVEs:CVE-2021-41218

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-0657

Open SourceCoalition ESS < 30%HIGH2021-11-18

In apusys, there is a possible out of bounds write due to a stack-based buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672103; ...

CVEs:CVE-2021-0657

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0927

Open SourceCoalition ESS < 30%HIGH2021-11-02

In requestChannelBrowsable of TvInputManagerService.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not n...

CVEs:CVE-2021-0927

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-189824175

GoogleCoalition ESS < 30%NONE2021-11-01

ASB-A-189824175

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-0921

Open SourceCoalition ESS < 30%HIGH2021-11-02

In ParsingPackageImpl of ParsingPackageImpl.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User ...

CVEs:CVE-2021-0921

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0620

Open SourceCoalition ESS < 30%HIGH2021-11-18

In asf extractor, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05489...

CVEs:CVE-2021-0620

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0622

Open SourceCoalition ESS < 30%HIGH2021-11-18

In asf extractor, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05489...

CVEs:CVE-2021-0622

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0624

Open SourceCoalition ESS < 30%HIGH2021-11-18

In flv extractor, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05594...

CVEs:CVE-2021-0624

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-195570681

GoogleCoalition ESS < 30%HIGH2021-11-01

PUB-A-195570681

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-0668

Open SourceCoalition ESS < 30%HIGH2021-11-18

In apusys, there is a possible memory corruption due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05670521; Issue I...

CVEs:CVE-2021-0668

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0669

Open SourceCoalition ESS < 30%HIGH2021-11-18

In apusys, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05681550; Issue ID: ALPS0...

CVEs:CVE-2021-0669

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0670

Open SourceCoalition ESS < 30%HIGH2021-11-18

In apusys, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05654663; Issue ID: ALPS0...

CVEs:CVE-2021-0670

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0671

Open SourceCoalition ESS < 30%HIGH2021-11-18

In apusys, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05664273; Issue ID:...

CVEs:CVE-2021-0671

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0629

Open SourceCoalition ESS < 30%HIGH2021-11-18

In mdlactl driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05776625; Issue I...

CVEs:CVE-2021-0629

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0649

Open SourceCoalition ESS < 30%HIGH2021-11-02

In stopVpnProfile of Vpn.java, there is a possible VPN profile reset due to a permissions bypass. This could lead to local escalation of privilege CONTROL_ALWAYS_ON_VPN with no additional execution privileges needed. User interaction is not needed for ...

CVEs:CVE-2021-0649

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0932

Open SourceCoalition ESS < 30%HIGH2021-11-02

In showNotification of NavigationModeController.java, there is a possible confused deputy due to an unsafe PendingIntent. This could lead to local escalation of privilege that allows actions performed as the System UI with User execution privileges nee...

CVEs:CVE-2021-0932

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0799

Open SourceCoalition ESS < 30%HIGH2021-11-02

In ActivityThread.java, there is a possible way to collide the content provider's authorities. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: And...

CVEs:CVE-2021-0799

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0658

Open SourceCoalition ESS < 30%HIGH2021-11-18

In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue I...

CVEs:CVE-2021-0658

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0659

Open SourceCoalition ESS < 30%MEDIUM2021-11-18

In apusys, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05687559; Issue ...

CVEs:CVE-2021-0659

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0665

Open SourceCoalition ESS < 30%MEDIUM2021-11-18

In apusys, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672113; Issue ...

CVEs:CVE-2021-0665

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0666

Open SourceCoalition ESS < 30%MEDIUM2021-11-18

In apusys, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672086; Issue ...

CVEs:CVE-2021-0666

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1042

Open SourceCoalition ESS < 30%HIGH2021-11-02

In dsi_panel_debugfs_read_cmdset of dsi_panel.c, there is a possible disclosure of freed kernel heap memory due to a use after free. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed...

CVEs:CVE-2021-1042

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-187851056

GoogleCoalition ESS < 30%HIGH2021-11-01

PUB-A-187851056

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-0655

Open SourceCoalition ESS < 30%HIGH2021-11-18

In mdlactl driver, there is a possible memory corruption due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05673424...

CVEs:CVE-2021-0655

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0656

Open SourceCoalition ESS < 30%HIGH2021-11-18

In edma driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05709376; Issue ID: ...

CVEs:CVE-2021-0656

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0664

Open SourceCoalition ESS < 30%HIGH2021-11-18

In ccu, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05827158; Issue ID: ALPS0582...

CVEs:CVE-2021-0664

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0667

Open SourceCoalition ESS < 30%HIGH2021-11-18

In apusys, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05670581; Issue ID: ALPS0...

CVEs:CVE-2021-0667

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25503

Open SourceCoalition ESS < 30%CRITICAL2021-11-05

Improper input validation vulnerability in HDCP prior to SMR Nov-2021 Release 1 allows attackers to arbitrary code execution.

CVEs:CVE-2021-25503

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1043

Open SourceCoalition ESS < 30%MEDIUM2021-11-02

In TBD of TBD, there is a possible downgrade attack due to under utilized anti-rollback protections. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product...

CVEs:CVE-2021-1043

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-194697257

GoogleCoalition ESS < 30%MEDIUM2021-11-01

PUB-A-194697257

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-0621

Open SourceCoalition ESS < 30%HIGH2021-11-18

In asf extractor, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05489178...

CVEs:CVE-2021-0621

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0623

Open SourceCoalition ESS < 30%HIGH2021-11-18

In asf extractor, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05489178...

CVEs:CVE-2021-0623

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0619

Open SourceCoalition ESS < 30%MEDIUM2021-11-18

In ape extractor, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05561...

CVEs:CVE-2021-0619

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0653

Open SourceCoalition ESS < 30%MEDIUM2021-11-02

In enqueueNotification of NetworkPolicyManagerService.java, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. Us...

CVEs:CVE-2021-0653

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0926

Open SourceCoalition ESS < 30%HIGH2021-11-02

In onCreate of NfcImportVCardActivity.java, there is a possible way to add a contact without user's consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interac...

CVEs:CVE-2021-0926

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0672

Open SourceCoalition ESS < 30%MEDIUM2021-11-02

In Browser app, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Andro...

CVEs:CVE-2021-0672

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1041

Open SourceCoalition ESS < 30%HIGH2021-11-02

In (TBD) of (TBD), there is a possible out of bounds read due to memory corruption. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions...

CVEs:CVE-2021-1041

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-199678035

GoogleCoalition ESS < 30%MEDIUM2021-11-01

ASB-A-199678035

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-182950799

GoogleCoalition ESS < 30%HIGH2021-11-01

PUB-A-182950799

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-0919

Open SourceCoalition ESS < 30%HIGH2021-11-02

In getService of IServiceManager.cpp, there is a possible unhandled exception due to an integer overflow. This could lead to local denial of service making the lockscreen unusable with no additional execution privileges needed. User interaction is need...

CVEs:CVE-2021-0919

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0923

Open SourceCoalition ESS < 30%HIGH2021-11-02

In createOrUpdate of Permission.java, there is a possible way to gain internal permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not neede...

CVEs:CVE-2021-0923

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0922

Open SourceCoalition ESS < 30%HIGH2021-11-02

In enforceCrossUserOrProfilePermission of PackageManagerService.java, there is a possible bypass of INTERACT_ACROSS_PROFILES permission due to a missing permission check. This could lead to local escalation of privilege with no additional execution pri...

CVEs:CVE-2021-0922

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25500

Open SourceCoalition ESS < 30%HIGH2021-11-05

A missing input validation in HDCP LDFW prior to SMR Nov-2021 Release 1 allows attackers to overwrite TZASC allowing TEE compromise.

CVEs:CVE-2021-25500

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25501

Open SourceCoalition ESS < 30%MEDIUM2021-11-05

An improper access control vulnerability in SCloudBnRReceiver in SecTelephonyProvider prior to SMR Nov-2021 Release 1 allows untrusted application to call some protected providers.

CVEs:CVE-2021-25501

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25502

Open SourceCoalition ESS < 30%HIGH2021-11-05

A vulnerability of storing sensitive information insecurely in Property Settings prior to SMR Nov-2021 Release 1 allows attackers to read ESN value without priviledge.

CVEs:CVE-2021-25502

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-191191879

GoogleEPSS <= 49%HIGH2021-11-01

PUB-A-191191879

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

MGASA-2021-0516

Open SourceAll remainingHIGH2021-11-20

Updated chromium-browser-stable packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:8 chromium-browser-stable
Upstream advisory

ALEA-2021:4233

GoogleAll remainingHIGH2021-11-09

llvm-toolset:rhel8 bug fix and enhancement update

Affected products

ProductStatusVendorPackageEcosystem
compiler-rt affected AlmaLinux:8 compiler-rt
libomp affected AlmaLinux:8 libomp
libomp-devel affected AlmaLinux:8 libomp-devel
libomp-test affected AlmaLinux:8 libomp-test
lld affected AlmaLinux:8 lld
lldb affected AlmaLinux:8 lldb
lldb-devel affected AlmaLinux:8 lldb-devel
lld-devel affected AlmaLinux:8 lld-devel
lld-libs affected AlmaLinux:8 lld-libs
lld-test affected AlmaLinux:8 lld-test
llvm affected AlmaLinux:8 llvm
llvm-devel affected AlmaLinux:8 llvm-devel
llvm-doc affected AlmaLinux:8 llvm-doc
llvm-googletest affected AlmaLinux:8 llvm-googletest
llvm-libs affected AlmaLinux:8 llvm-libs
llvm-static affected AlmaLinux:8 llvm-static
llvm-test affected AlmaLinux:8 llvm-test
llvm-toolset affected AlmaLinux:8 llvm-toolset
python3-lit affected AlmaLinux:8 python3-lit
python3-lldb affected AlmaLinux:8 python3-lldb
Upstream advisory

ALEA-2021:4229

GoogleAll remainingHIGH2021-11-09

google-noto-emoji-fonts and pango bug fix and enhancement update

Affected products

ProductStatusVendorPackageEcosystem
google-noto-emoji-color-fonts affected AlmaLinux:8 google-noto-emoji-color-fonts
google-noto-emoji-fonts affected AlmaLinux:8 google-noto-emoji-fonts
pango affected AlmaLinux:8 pango
pango-devel affected AlmaLinux:8 pango-devel
Upstream advisory

ALBA-2021:4193

Open SourceAll remainingHIGH2021-11-09

rsyslog and its related dependencies bug fix and enhancement update

Affected products

ProductStatusVendorPackageEcosystem
libfastjson affected AlmaLinux:8 libfastjson
liblognorm affected AlmaLinux:8 liblognorm
liblognorm-doc affected AlmaLinux:8 liblognorm-doc
librelp affected AlmaLinux:8 librelp
rsyslog affected AlmaLinux:8 rsyslog
rsyslog-crypto affected AlmaLinux:8 rsyslog-crypto
rsyslog-doc affected AlmaLinux:8 rsyslog-doc
rsyslog-elasticsearch affected AlmaLinux:8 rsyslog-elasticsearch
rsyslog-gnutls affected AlmaLinux:8 rsyslog-gnutls
rsyslog-gssapi affected AlmaLinux:8 rsyslog-gssapi
rsyslog-kafka affected AlmaLinux:8 rsyslog-kafka
rsyslog-mmaudit affected AlmaLinux:8 rsyslog-mmaudit
rsyslog-mmjsonparse affected AlmaLinux:8 rsyslog-mmjsonparse
rsyslog-mmkubernetes affected AlmaLinux:8 rsyslog-mmkubernetes
rsyslog-mmnormalize affected AlmaLinux:8 rsyslog-mmnormalize
rsyslog-mmsnmptrapd affected AlmaLinux:8 rsyslog-mmsnmptrapd
rsyslog-mysql affected AlmaLinux:8 rsyslog-mysql
rsyslog-omamqp1 affected AlmaLinux:8 rsyslog-omamqp1
rsyslog-openssl affected AlmaLinux:8 rsyslog-openssl
rsyslog-pgsql affected AlmaLinux:8 rsyslog-pgsql
rsyslog-relp affected AlmaLinux:8 rsyslog-relp
rsyslog-snmp affected AlmaLinux:8 rsyslog-snmp
rsyslog-udpspoof affected AlmaLinux:8 rsyslog-udpspoof
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.