Google Security Advisories · September 2022 — Google Security Advisories
628 advisories 335 CVEs 23 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2022-09. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 23 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2022-41082

GoogleExploitedCISA KEV listedCRITICAL2022-09-13

Microsoft Exchange Server Remote Code Execution Vulnerability

CVEs:CVE-2022-41082

Affected products

ProductStatusVendorPackageEcosystem
exchange_server affected microsoft
Upstream advisory

CVE-2022-41040

GoogleExploitedCISA KEV listedCRITICAL2022-09-13

Microsoft Exchange Server Elevation of Privilege Vulnerability

CVEs:CVE-2022-41040

Affected products

ProductStatusVendorPackageEcosystem
exchange_server affected microsoft
Upstream advisory

CVE-2022-3236

GoogleExploitedCISA KEV listedCRITICAL2022-09-23

A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older.

CVEs:CVE-2022-3236

Affected products

ProductStatusVendorPackageEcosystem
firewall affected sophos
Upstream advisory

CVE-2022-3236

Project ZeroExploitedCISA KEV listed2022-09-23

A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older.

CVEs:CVE-2022-3236

Upstream advisory

DEBIAN-CVE-2022-3038

Open SourceExploitedCISA KEV listedCRITICAL2022-09-26

DEBIAN-CVE-2022-3038

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

openSUSE-SU-2022:10120-1

Open SourceExploitedCISA KEV listedCRITICAL2022-09-12

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP3 chromium
chromium affected openSUSE:Leap 15.3 chromium
Upstream advisory

openSUSE-SU-2022:10119-1

Open SourceExploitedCISA KEV listedCRITICAL2022-09-12

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected openSUSE:Leap 15.4 chromium
Upstream advisory

MGASA-2022-0318

Open SourceExploitedCISA KEV listedCRITICAL2022-09-04

Updated chromium-browser-stable packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:8 chromium-browser-stable
Upstream advisory

DSA-5223-1

Open SourceExploitedCISA KEV listed2022-09-01

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
Upstream advisory

DEBIAN-CVE-2022-3075

Open SourceExploitedCISA KEV listedCRITICAL2022-09-26

DEBIAN-CVE-2022-3075

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DSA-5225-1

Open SourceExploitedCISA KEV listed2022-09-06

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
Upstream advisory

CVE-2022-3075

GoogleExploitedCISA KEV listedCRITICAL2022-09-05

Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2022-3075

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-3075

Project ZeroExploitedCISA KEV listed2022-09-05

Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2022-3075

Upstream advisory

CVE-2022-32917

GoogleExploitedCISA KEV listedCRITICAL2022-09-12

The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a repo...

CVEs:CVE-2022-32917

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2022-32917

Project ZeroExploitedCISA KEV listed2022-09-12

The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..

CVEs:CVE-2022-32917

Upstream advisory

DEBIAN-CVE-2022-2856

Open SourceExploitedCISA KEV listedMEDIUM2022-09-26

DEBIAN-CVE-2022-2856

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-40083

Open SourceWeaponized exploitCRITICAL2022-09-28

DEBIAN-CVE-2022-40083

Affected products

ProductStatusVendorPackageEcosystem
golang-github-labstack-echo affected Debian:13 golang-github-labstack-echo
golang-github-labstack-echo affected Debian:12 golang-github-labstack-echo
golang-github-labstack-echo affected Debian:14 golang-github-labstack-echo
Upstream advisory

SUSE-SU-2022:3178-1

Open SourceWeaponized exploitCRITICAL2022-09-08

Important security update for SUSE Manager Client Tools

Affected products

ProductStatusVendorPackageEcosystem
ansible affected openSUSE:Leap 15.3 ansible
ansible affected openSUSE:Leap 15.4 ansible
ansible affected SUSE:Manager Proxy Module 4.3 ansible
ansible affected SUSE:Manager Client Tools 15 ansible
ansible affected SUSE:Manager Proxy Module 4.2 ansible
dracut-saltboot affected SUSE:Manager Client Tools 15 dracut-saltboot
dracut-saltboot affected openSUSE:Leap 15.4 dracut-saltboot
dracut-saltboot affected openSUSE:Leap 15.3 dracut-saltboot
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server 15-LTSS golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise High Performance Computing 15-LTSS golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise High Performance Computing 15-ESPOS golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server for SAP Applications 15 golang-github-prometheus-node_exporter
golang-github-QubitProducts-exporter_exporter affected SUSE:Manager Proxy Module 4.2 golang-github-QubitProducts-exporter_exporter
golang-github-QubitProducts-exporter_exporter affected SUSE:Manager Proxy Module 4.3 golang-github-QubitProducts-exporter_exporter
golang-github-QubitProducts-exporter_exporter affected SUSE:Manager Server Module 4.2 golang-github-QubitProducts-exporter_exporter
golang-github-QubitProducts-exporter_exporter affected SUSE:Manager Server Module 4.3 golang-github-QubitProducts-exporter_exporter
golang-github-QubitProducts-exporter_exporter affected openSUSE:Leap 15.4 golang-github-QubitProducts-exporter_exporter
golang-github-QubitProducts-exporter_exporter affected openSUSE:Leap 15.3 golang-github-QubitProducts-exporter_exporter
golang-github-QubitProducts-exporter_exporter affected SUSE:Manager Client Tools 15 golang-github-QubitProducts-exporter_exporter
mgr-daemon affected SUSE:Manager Client Tools 15 mgr-daemon
mgr-virtualization affected SUSE:Manager Client Tools 15 mgr-virtualization
prometheus-blackbox_exporter affected SUSE:Manager Proxy Module 4.2 prometheus-blackbox_exporter
prometheus-blackbox_exporter affected SUSE:Manager Client Tools 15 prometheus-blackbox_exporter
prometheus-blackbox_exporter affected openSUSE:Leap 15.4 prometheus-blackbox_exporter
prometheus-blackbox_exporter affected SUSE:Manager Proxy Module 4.3 prometheus-blackbox_exporter
python-hwdata affected SUSE:Manager Proxy Module 4.1 python-hwdata
python-hwdata affected SUSE:Manager Client Tools 15 python-hwdata
python-hwdata affected SUSE:Manager Proxy Module 4.2 python-hwdata
python-hwdata affected SUSE:Manager Proxy Module 4.3 python-hwdata
python-hwdata affected SUSE:Manager Server Module 4.1 python-hwdata
python-hwdata affected SUSE:Manager Server Module 4.2 python-hwdata
python-hwdata affected SUSE:Manager Server Module 4.3 python-hwdata
python-hwdata affected openSUSE:Leap 15.3 python-hwdata
python-hwdata affected openSUSE:Leap 15.4 python-hwdata
spacecmd affected openSUSE:Leap 15.3 spacecmd
spacecmd affected openSUSE:Leap 15.4 spacecmd
spacecmd affected SUSE:Manager Client Tools 15 spacecmd
spacewalk-client-tools affected SUSE:Manager Client Tools 15 spacewalk-client-tools
uyuni-common-libs affected SUSE:Manager Client Tools 15 uyuni-common-libs
uyuni-proxy-systemd-services affected SUSE:Manager Client Tools 15 uyuni-proxy-systemd-services
wire affected openSUSE:Leap 15.4 wire
zypp-plugin-spacewalk affected SUSE:Manager Client Tools 15 zypp-plugin-spacewalk
zypp-plugin-spacewalk affected SUSE:Manager Proxy Module 4.1 zypp-plugin-spacewalk
zypp-plugin-spacewalk affected SUSE:Manager Proxy Module 4.2 zypp-plugin-spacewalk
zypp-plugin-spacewalk affected SUSE:Manager Proxy Module 4.3 zypp-plugin-spacewalk
Upstream advisory

DSA-5230-1

Open SourcePoC exploit2022-09-15

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
Upstream advisory

MGASA-2022-0340

GooglePoC exploitHIGH2022-09-21

Updated google-gson packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
google-gson affected Mageia:8 google-gson
Upstream advisory

DLA-3100-1

GooglePoC exploit2022-09-07

libgoogle-gson-java - security update

Affected products

ProductStatusVendorPackageEcosystem
libgoogle-gson-java affected Debian:10 libgoogle-gson-java
Upstream advisory

DSA-5227-1

GooglePoC exploit2022-09-07

libgoogle-gson-java - security update

Affected products

ProductStatusVendorPackageEcosystem
libgoogle-gson-java affected Debian:11 libgoogle-gson-java
Upstream advisory

OESA-2022-1939

Open SourcePoC exploitHIGH2022-09-23

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:20.03-LTS-SP1 golang
golang affected openEuler:20.03-LTS-SP3 golang
golang affected openEuler:22.03-LTS golang
Upstream advisory

GO-2022-0969

Open SourcePoC exploitHIGH2022-09-12

Denial of service in net/http and golang.org/x/net/http2

Affected products

ProductStatusVendorPackageEcosystem
dynamic-localpv-provisioner affected chainguard dynamic-localpv-provisioner
dynamic-localpv-provisioner affected wolfi dynamic-localpv-provisioner
dynamic-localpv-provisioner-fips affected chainguard dynamic-localpv-provisioner-fips
grpcurl affected wolfi grpcurl
grpcurl affected chainguard grpcurl
hey affected chainguard hey
hey affected wolfi hey
k3d affected wolfi k3d
k3d affected chainguard k3d
kubeflow affected chainguard kubeflow
kubeflow affected wolfi kubeflow
kubeflow-fips affected chainguard kubeflow-fips
kubeflow-katib affected wolfi kubeflow-katib
kubeflow-katib affected chainguard kubeflow-katib
kube-state-metrics-2.6 affected chainguard kube-state-metrics-2.6
prometheus-postgres-exporter-0.10 affected chainguard prometheus-postgres-exporter-0.10
stdlib affected Go stdlib
terraform-provider-sendgrid affected wolfi terraform-provider-sendgrid
terraform-provider-sendgrid affected chainguard terraform-provider-sendgrid
terraform-provider-sendgrid-fips affected chainguard terraform-provider-sendgrid-fips
wireguard-go affected chainguard wireguard-go
wireguard-go affected wolfi wireguard-go
x/net affected golang.org golang.org/x/net
Upstream advisory

GHSA-69cg-p879-7622

Open SourcePoC exploitHIGH2022-09-07

golang.org/x/net/http2 Denial of Service vulnerability

Affected products

ProductStatusVendorPackageEcosystem
x/net affected golang.org golang.org/x/net
x/net/http2 affected golang.org golang.org/x/net/http2
Upstream advisory

GHSA-69cg-p879-7622

Open SourcePoC exploitHIGH2022-09-07

golang.org/x/net/http2 Denial of Service vulnerability

Affected products

ProductStatusVendorPackageEcosystem
dynamic-localpv-provisioner affected chainguard dynamic-localpv-provisioner
dynamic-localpv-provisioner affected wolfi dynamic-localpv-provisioner
dynamic-localpv-provisioner-fips affected chainguard dynamic-localpv-provisioner-fips
grpcurl affected wolfi grpcurl
grpcurl affected chainguard grpcurl
hey affected wolfi hey
hey affected chainguard hey
k3d affected wolfi k3d
k3d affected chainguard k3d
kubeflow affected wolfi kubeflow
kubeflow affected chainguard kubeflow
kubeflow-fips affected chainguard kubeflow-fips
kubeflow-katib affected wolfi kubeflow-katib
kubeflow-katib affected chainguard kubeflow-katib
kube-state-metrics-2.6 affected chainguard kube-state-metrics-2.6
prometheus-postgres-exporter-0.10 affected chainguard prometheus-postgres-exporter-0.10
terraform-provider-sendgrid affected wolfi terraform-provider-sendgrid
terraform-provider-sendgrid affected chainguard terraform-provider-sendgrid
terraform-provider-sendgrid-fips affected chainguard terraform-provider-sendgrid-fips
wireguard-go affected wolfi wireguard-go
wireguard-go affected chainguard wireguard-go
x/net affected golang.org golang.org/x/net
x/net affected golang.org
x/net/http2 affected golang.org golang.org/x/net/http2
Upstream advisory

AZL-10855

Open SourcePoC exploitHIGH2022-09-06

CVE-2022-27664 affecting package golang for versions less than 1.18.8-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-37328

Open SourcePoC exploitHIGH2022-09-06

CVE-2022-27664 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-52863

Open SourcePoC exploitHIGH2022-09-06

CVE-2022-27664 affecting package golang for versions less than 1.18.8-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

AZL-79106

Open SourcePoC exploitHIGH2022-09-06

CVE-2022-27664 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2022-27664

Open SourcePoC exploitHIGH2022-09-06

DEBIAN-CVE-2022-27664

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
golang-golang-x-net affected Debian:11 golang-golang-x-net
golang-golang-x-net affected Debian:12 golang-golang-x-net
golang-golang-x-net affected Debian:13 golang-golang-x-net
golang-golang-x-net affected Debian:14 golang-golang-x-net
Upstream advisory

CVE-2022-27664

Open SourcePoC exploitHIGH2022-09-06

golang.org/x/net/http2 Denial of Service vulnerability

CVEs:CVE-2022-27664

Affected products

ProductStatusVendorPackageEcosystem
x/net affected golang.org golang.org/x/net
x/net/http2 affected golang.org golang.org/x/net/http2
Upstream advisory

CVE-2022-27664

GooglePoC exploitHIGH2022-09-06

In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error.

CVEs:CVE-2022-27664

Affected products

ProductStatusVendorPackageEcosystem
fedora affected fedoraproject
go affected golang
Upstream advisory

CLSA-2022-1663184406

Open SourcePoC exploit2022-09-14

Fix CVE(s): CVE-2021-28861

Affected products

ProductStatusVendorPackageEcosystem
idle-python3.5 affected TuxCare:Ubuntu:16.04 idle-python3.5
libpython3.5 affected TuxCare:Ubuntu:16.04 libpython3.5
libpython3.5-dev affected TuxCare:Ubuntu:16.04 libpython3.5-dev
libpython3.5-minimal affected TuxCare:Ubuntu:16.04 libpython3.5-minimal
libpython3.5-stdlib affected TuxCare:Ubuntu:16.04 libpython3.5-stdlib
libpython3.5-testsuite affected TuxCare:Ubuntu:16.04 libpython3.5-testsuite
python3.5 affected TuxCare:Ubuntu:16.04 python3.5
python3.5-dev affected TuxCare:Ubuntu:16.04 python3.5-dev
python3.5-doc affected TuxCare:Ubuntu:16.04 python3.5-doc
python3.5-examples affected TuxCare:Ubuntu:16.04 python3.5-examples
python3.5-minimal affected TuxCare:Ubuntu:16.04 python3.5-minimal
python3.5-venv affected TuxCare:Ubuntu:16.04 python3.5-venv
Upstream advisory

CVE-2022-3172

GooglePoC exploitCRITICAL2022-09-18

A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This could lead to the client performing unexpected actions as well as forwarding the client's API server credentials to t...

CVEs:CVE-2022-3172

Affected products

ProductStatusVendorPackageEcosystem
apiserver affected kubernetes
Upstream advisory

DEBIAN-CVE-2022-3199

Open SourcePoC exploitCRITICAL2022-09-26

DEBIAN-CVE-2022-3199

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
Upstream advisory

openSUSE-SU-2022:10123-1

Open SourcePoC exploitCRITICAL2022-09-16

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.4 chromium
chromium affected SUSE:Package Hub 15 SP3 chromium
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected openSUSE:Leap 15.3 chromium
Upstream advisory

CVE-2022-3199

GooglePoC exploitCRITICAL2022-09-14

Use after free in Frames in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-3199

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

GHSA-8gq9-2x98-w8hf

Open SourcePoC exploitHIGH2022-09-23

protobuf-cpp and protobuf-python have potential Denial of Service issue

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected PyPI protobuf
Upstream advisory

GHSA-8gq9-2x98-w8hf

Open SourcePoC exploitHIGH2022-09-23

protobuf-cpp and protobuf-python have potential Denial of Service issue

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected PyPI protobuf
protobuf affected PyPI protobuf
Upstream advisory

AZL-13174

Open SourcePoC exploitHIGH2022-09-22

CVE-2022-1941 affecting package protobuf for versions less than 3.17.3-3

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected Azure Linux:2 protobuf
Upstream advisory

AZL-35125

Open SourcePoC exploitHIGH2022-09-22

CVE-2022-1941 affecting package protobuf for versions less than 25.3-1

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected Azure Linux:3 protobuf
Upstream advisory

AZL-38908

Open SourcePoC exploitHIGH2022-09-22

CVE-2022-1941 affecting package tensorflow for versions less than 2.16.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

DEBIAN-CVE-2022-1941

Open SourcePoC exploitHIGH2022-09-22

DEBIAN-CVE-2022-1941

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected Debian:11 protobuf
protobuf affected Debian:12 protobuf
protobuf affected Debian:13 protobuf
protobuf affected Debian:14 protobuf
Upstream advisory

CVE-2022-1941

Open SourcePoC exploitHIGH2022-09-22

A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 3.21.5 for protobuf-cpp, and versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 4....

CVEs:CVE-2022-1941

Affected products

ProductStatusVendorPackageEcosystem
debian_linux affected debian
fedora affected fedoraproject
protobuf-cpp affected google
protobuf-python affected google
Upstream advisory

CVE-2022-1941

Open SourcePoC exploitHIGH2022-09-22

protobuf-cpp and protobuf-python have potential Denial of Service issue

CVEs:CVE-2022-1941

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected PyPI protobuf
Upstream advisory

CVE-2022-1941

Open SourcePoC exploitHIGH2022-09-22

protobuf-cpp and protobuf-python have potential Denial of Service issue

CVEs:CVE-2022-1941

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected PyPI protobuf
Upstream advisory

GO-2022-0968

Open SourcePoC exploitNONE2022-09-13

Panic on malformed packets in golang.org/x/crypto/ssh

Affected products

ProductStatusVendorPackageEcosystem
dex-k8s-authenticator affected chainguard dex-k8s-authenticator
dynamic-localpv-provisioner affected chainguard dynamic-localpv-provisioner
dynamic-localpv-provisioner affected wolfi dynamic-localpv-provisioner
dynamic-localpv-provisioner-fips affected chainguard dynamic-localpv-provisioner-fips
k3d affected chainguard k3d
k3d affected wolfi k3d
kubeflow affected wolfi kubeflow
kubeflow affected chainguard kubeflow
kubeflow-fips affected chainguard kubeflow-fips
prometheus-postgres-exporter-0.10 affected chainguard prometheus-postgres-exporter-0.10
terraform-provider-sendgrid affected chainguard terraform-provider-sendgrid
terraform-provider-sendgrid affected wolfi terraform-provider-sendgrid
terraform-provider-sendgrid-fips affected chainguard terraform-provider-sendgrid-fips
x/crypto affected golang.org golang.org/x/crypto
Upstream advisory

GHSA-gwc9-m7rh-j2ww

Open SourcePoC exploitHIGH2022-09-07

x/crypto/ssh vulnerable to panic via malformed packets

Affected products

ProductStatusVendorPackageEcosystem
dex-k8s-authenticator affected chainguard dex-k8s-authenticator
dynamic-localpv-provisioner affected wolfi dynamic-localpv-provisioner
dynamic-localpv-provisioner affected chainguard dynamic-localpv-provisioner
dynamic-localpv-provisioner-fips affected chainguard dynamic-localpv-provisioner-fips
k3d affected chainguard k3d
k3d affected wolfi k3d
kubeflow affected wolfi kubeflow
kubeflow affected chainguard kubeflow
kubeflow-fips affected chainguard kubeflow-fips
prometheus-postgres-exporter-0.10 affected chainguard prometheus-postgres-exporter-0.10
terraform-provider-sendgrid affected chainguard terraform-provider-sendgrid
terraform-provider-sendgrid affected wolfi terraform-provider-sendgrid
terraform-provider-sendgrid-fips affected chainguard terraform-provider-sendgrid-fips
x/crypto affected golang.org golang.org/x/crypto
Upstream advisory

GHSA-gwc9-m7rh-j2ww

Open SourcePoC exploitHIGH2022-09-07

x/crypto/ssh vulnerable to panic via malformed packets

Affected products

ProductStatusVendorPackageEcosystem
x/crypto affected golang.org golang.org/x/crypto
Upstream advisory

DEBIAN-CVE-2021-43565

Open SourcePoC exploitHIGH2022-09-06

DEBIAN-CVE-2021-43565

Affected products

ProductStatusVendorPackageEcosystem
golang-go.crypto affected Debian:11 golang-go.crypto
golang-go.crypto affected Debian:12 golang-go.crypto
golang-go.crypto affected Debian:13 golang-go.crypto
golang-go.crypto affected Debian:14 golang-go.crypto
Upstream advisory

ASB-A-231494876

GooglePoC exploitHIGH2022-09-01

ASB-A-231494876

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

DSA-5244-1

Open SourcePoC exploit2022-09-28

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
Upstream advisory

CVE-2022-3317

GooglePoC exploitMEDIUM2022-09-27

Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 106.0.5249.62 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2022-3317

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

PUB-A-228694483

GooglePoC exploit2022-09-01

PUB-A-228694483

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

ASB-A-216408350

GooglePoC exploitNONE2022-09-01

ASB-A-216408350

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2021-25749

Open SourcePoC exploitHIGH2022-09-18

Windows workloads can run as ContainerAdministrator even when those workloads set the runAsNonRoot option to true.

CVEs:CVE-2021-25749

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
Upstream advisory

CVE-2022-20566

Open SourcePoC exploitHIGH2022-09-13

In l2cap_chan_put of l2cap_core, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Andro...

CVEs:CVE-2022-20566

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2019-5797

Open SourceCoalition ESS 30-63%CRITICAL2022-09-29

DEBIAN-CVE-2019-5797

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-2998

GoogleCoalition ESS < 30%CRITICAL2022-09-26

Use after free in Browser Creation in Google Chrome prior to 104.0.5112.101 allowed a remote attacker who had convinced a user to engage in a specific UI interaction to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-2998

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-2998

Open SourceCoalition ESS < 30%CRITICAL2022-09-26

DEBIAN-CVE-2022-2998

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-3842

GoogleCoalition ESS < 30%CRITICAL2022-09-14

Use after free in Passwords in Google Chrome prior to 105.0.5195.125 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-3842

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-2852

Open SourceCoalition ESS < 30%CRITICAL2022-09-26

DEBIAN-CVE-2022-2852

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-32190

Open SourceCoalition ESS < 30%HIGH2022-09-13

DEBIAN-CVE-2022-32190

Affected products

ProductStatusVendorPackageEcosystem
golang-1.19 affected Debian:12 golang-1.19
Upstream advisory

CVE-2022-32190

GoogleCoalition ESS < 30%HIGH2022-09-12

JoinPath and URL.JoinPath do not remove ../ path elements appended to a relative path. For example, JoinPath("https://go.dev", "../go") returns the URL "https://go.dev/../go", despite the JoinPath documentation stating that ../ path elements are remove...

CVEs:CVE-2022-32190

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

GO-2022-0988

Open SourceCoalition ESS < 30%2022-09-12

Failure to strip relative path components in net/url

Affected products

ProductStatusVendorPackageEcosystem
kubeflow-katib affected chainguard kubeflow-katib
kubeflow-katib affected wolfi kubeflow-katib
stdlib affected Go stdlib
Upstream advisory

DEBIAN-CVE-2022-2853

Open SourceCoalition ESS < 30%CRITICAL2022-09-26

DEBIAN-CVE-2022-2853

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GHSA-936v-cg49-m2g5

GoogleCoalition ESS < 30%CRITICAL2022-09-09

com.google.cloud.tools:jib-core vulnerable to Remote Code Execution (RCE)

Affected products

ProductStatusVendorPackageEcosystem
com.google.cloud.tools:jib-core affected Maven com.google.cloud.tools:jib-core
Upstream advisory

GHSA-936v-cg49-m2g5

GoogleCoalition ESS < 30%CRITICAL2022-09-09

com.google.cloud.tools:jib-core vulnerable to Remote Code Execution (RCE)

Affected products

ProductStatusVendorPackageEcosystem
com.google.cloud.tools:jib-core affected Maven com.google.cloud.tools:jib-core
Upstream advisory

CVE-2022-25914

GoogleCoalition ESS < 30%CRITICAL2022-09-08

com.google.cloud.tools:jib-core vulnerable to Remote Code Execution (RCE)

CVEs:CVE-2022-25914

Affected products

ProductStatusVendorPackageEcosystem
com.google.cloud.tools:jib-core affected Maven com.google.cloud.tools:jib-core
Upstream advisory

CVE-2022-25914

GoogleCoalition ESS < 30%CRITICAL2022-09-08

The package com.google.cloud.tools:jib-core before 0.22.0 are vulnerable to Remote Code Execution (RCE) via the isDockerInstalled function, due to attempting to execute input.

CVEs:CVE-2022-25914

Affected products

ProductStatusVendorPackageEcosystem
jib affected jib_project
Upstream advisory

DEBIAN-CVE-2022-3195

Open SourceCoalition ESS < 30%CRITICAL2022-09-26

DEBIAN-CVE-2022-3195

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-3195

GoogleCoalition ESS < 30%CRITICAL2022-09-14

Out of bounds write in Storage in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-3195

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2022-3045

Open SourceCoalition ESS < 30%HIGH2022-09-26

DEBIAN-CVE-2022-3045

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-3056

Open SourceCoalition ESS < 30%CRITICAL2022-09-26

DEBIAN-CVE-2022-3056

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-2238

Open SourceCoalition ESS < 30%HIGH2022-09-01

A vulnerability was found in the search-api container in Red Hat Advanced Cluster Management for Kubernetes when a query in the search filter gets parsed by the backend. This flaw allows an attacker to craft specific strings containing special characte...

CVEs:CVE-2022-2238

Affected products

ProductStatusVendorPackageEcosystem
advanced_cluster_management_for_kubernetes affected redhat
Upstream advisory

DEBIAN-CVE-2022-3196

Open SourceCoalition ESS < 30%CRITICAL2022-09-26

DEBIAN-CVE-2022-3196

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
Upstream advisory

CVE-2022-3196

GoogleCoalition ESS < 30%CRITICAL2022-09-14

Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)

CVEs:CVE-2022-3196

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2022-3197

Open SourceCoalition ESS < 30%CRITICAL2022-09-26

DEBIAN-CVE-2022-3197

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-3197

GoogleCoalition ESS < 30%CRITICAL2022-09-14

Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)

CVEs:CVE-2022-3197

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2022-3044

Open SourceCoalition ESS < 30%MEDIUM2022-09-26

DEBIAN-CVE-2022-3044

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-2860

Open SourceCoalition ESS < 30%CRITICAL2022-09-26

DEBIAN-CVE-2022-2860

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-3041

Open SourceCoalition ESS < 30%CRITICAL2022-09-26

DEBIAN-CVE-2022-3041

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-3040

Open SourceCoalition ESS < 30%CRITICAL2022-09-26

DEBIAN-CVE-2022-3040

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:11 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-38012

Open SourceCoalition ESS < 30%CRITICAL2022-09-02

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVEs:CVE-2022-38012

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

DEBIAN-CVE-2022-2858

Open SourceCoalition ESS < 30%CRITICAL2022-09-26

DEBIAN-CVE-2022-2858

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-2855

Open SourceCoalition ESS < 30%CRITICAL2022-09-26

DEBIAN-CVE-2022-2855

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GHSA-fpgf-pjjv-2qgm

Open SourceCoalition ESS < 30%HIGH2022-09-30

matrix-android-sdk2 vulnerable to Olm/Megolm protocol confusion

Affected products

ProductStatusVendorPackageEcosystem
org.matrix.android:matrix-android-sdk2 affected Maven org.matrix.android:matrix-android-sdk2
Upstream advisory

GHSA-fpgf-pjjv-2qgm

Open SourceCoalition ESS < 30%HIGH2022-09-30

matrix-android-sdk2 vulnerable to Olm/Megolm protocol confusion

Affected products

ProductStatusVendorPackageEcosystem
org.matrix.android:matrix-android-sdk2 affected Maven org.matrix.android:matrix-android-sdk2
Upstream advisory

CVE-2022-39248

Open SourceCoalition ESS < 30%HIGH2022-09-28

matrix-android-sdk2 vulnerable to Olm/Megolm protocol confusion

CVEs:CVE-2022-39248

Affected products

ProductStatusVendorPackageEcosystem
org.matrix.android:matrix-android-sdk2 affected Maven org.matrix.android:matrix-android-sdk2
Upstream advisory

CVE-2022-39248

GoogleCoalition ESS < 30%HIGH2022-09-28

matrix-android-sdk2 is the Matrix SDK for Android. Prior to version 1.5.1, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shiel...

CVEs:CVE-2022-39248

Affected products

ProductStatusVendorPackageEcosystem
software_development_kit affected matrix
Upstream advisory

DEBIAN-CVE-2022-2859

Open SourceCoalition ESS < 30%CRITICAL2022-09-26

DEBIAN-CVE-2022-2859

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-3046

Open SourceCoalition ESS < 30%CRITICAL2022-09-26

DEBIAN-CVE-2022-3046

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-3039

Open SourceCoalition ESS < 30%CRITICAL2022-09-26

DEBIAN-CVE-2022-3039

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-3052

Open SourceCoalition ESS < 30%CRITICAL2022-09-26

DEBIAN-CVE-2022-3052

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GHSA-79h2-q768-fpxr

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow segfault TFLite converter on per-channel quantized transposed convolutions

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-79h2-q768-fpxr

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow segfault TFLite converter on per-channel quantized transposed convolutions

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-36027

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow segfault TFLite converter on per-channel quantized transposed convolutions

CVEs:CVE-2022-36027

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-36027

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. When converting transposed convolutions using per-channel weight quantization the converter segfaults and crashes the Python process. We have patched the issue in GitHub commit aa0b852a4588cea...

CVEs:CVE-2022-36027

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-36027

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow segfault TFLite converter on per-channel quantized transposed convolutions

CVEs:CVE-2022-36027

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

DEBIAN-CVE-2022-3050

Open SourceCoalition ESS < 30%CRITICAL2022-09-26

DEBIAN-CVE-2022-3050

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-3443

GoogleCoalition ESS < 30%MEDIUM2022-09-27

Insufficient data validation in File System API in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass File System restrictions via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2022-3443

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-3444

GoogleCoalition ESS < 30%MEDIUM2022-09-27

Insufficient data validation in File System API in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass File System restrictions via a crafted HTML page and malicious file. (Chromium security severity: Low)

CVEs:CVE-2022-3444

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-3308

GoogleCoalition ESS < 30%CRITICAL2022-09-27

Insufficient policy enforcement in developer tools in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2022-3308

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-26447

Open SourceCoalition ESS < 30%CRITICAL2022-09-06

In BT firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06784478; Iss...

CVEs:CVE-2022-26447

Affected products

ProductStatusVendorPackageEcosystem
android affected google
yocto affected yoctoproject
Upstream advisory

ASB-A-237956326

GoogleCoalition ESS < 30%HIGH2022-09-01

ASB-A-237956326

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

DEBIAN-CVE-2022-3200

Open SourceCoalition ESS < 30%CRITICAL2022-09-26

DEBIAN-CVE-2022-3200

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-3200

GoogleCoalition ESS < 30%CRITICAL2022-09-14

Heap buffer overflow in Internals in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-3200

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-3304

GoogleCoalition ESS < 30%CRITICAL2022-09-27

Use after free in CSS in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-3304

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-mgmh-g2v6-mqw5

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` failure in `AvgPoolOp`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-mgmh-g2v6-mqw5

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` failure in `AvgPoolOp`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35941

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` failure in `AvgPoolOp`

CVEs:CVE-2022-35941

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35941

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` failure in `AvgPoolOp`

CVEs:CVE-2022-35941

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35941

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. The `AvgPoolOp` function takes an argument `ksize` that must be positive but is not checked. A negative `ksize` can trigger a `CHECK` failure and crash the program. We have patched the issue i...

CVEs:CVE-2022-35941

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

GHSA-7j3m-8g3c-9qqq

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to null-dereference in `mlir::tfg::TFOp::nameAttr`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-7j3m-8g3c-9qqq

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to null-dereference in `mlir::tfg::TFOp::nameAttr`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-36014

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to null-dereference in `mlir::tfg::TFOp::nameAttr`

CVEs:CVE-2022-36014

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-36014

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. When `mlir::tfg::TFOp::nameAttr` receives null type list attributes, it crashes. We have patched the issue in GitHub commits 3a754740d5414e362512ee981eefba41561a63a6 and a0f0b9a21c927093045709...

CVEs:CVE-2022-36014

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-36014

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to null-dereference in `mlir::tfg::TFOp::nameAttr`

CVEs:CVE-2022-36014

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-h5vq-gw2c-pq47

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` failures in `UnbatchGradOp`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-h5vq-gw2c-pq47

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` failures in `UnbatchGradOp`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35952

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` failures in `UnbatchGradOp`

CVEs:CVE-2022-35952

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35952

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. The `UnbatchGradOp` function takes an argument `id` that is assumed to be a scalar. A nonscalar `id` can trigger a `CHECK` failure and crash the program. It also requires its argument `batch_i...

CVEs:CVE-2022-35952

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-35952

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` failures in `UnbatchGradOp`

CVEs:CVE-2022-35952

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-2pvj-p485-cp3m

Open SourceCoalition ESS < 30%CRITICAL2022-09-30

matrix-android-sdk2 vulnerable to impersonation via forwarded Megolm sessions

Affected products

ProductStatusVendorPackageEcosystem
org.matrix.android:matrix-android-sdk2 affected Maven org.matrix.android:matrix-android-sdk2
Upstream advisory

GHSA-2pvj-p485-cp3m

Open SourceCoalition ESS < 30%CRITICAL2022-09-30

matrix-android-sdk2 vulnerable to impersonation via forwarded Megolm sessions

Affected products

ProductStatusVendorPackageEcosystem
org.matrix.android:matrix-android-sdk2 affected Maven org.matrix.android:matrix-android-sdk2
Upstream advisory

CVE-2022-39246

GoogleCoalition ESS < 30%CRITICAL2022-09-28

matrix-android-sdk2 is the Matrix SDK for Android. Prior to version 1.5.1, an attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some pl...

CVEs:CVE-2022-39246

Affected products

ProductStatusVendorPackageEcosystem
software_development_kit affected matrix
Upstream advisory

CVE-2022-39246

Open SourceCoalition ESS < 30%HIGH2022-09-28

matrix-android-sdk2 vulnerable to impersonation via forwarded Megolm sessions

CVEs:CVE-2022-39246

Affected products

ProductStatusVendorPackageEcosystem
org.matrix.android:matrix-android-sdk2 affected Maven org.matrix.android:matrix-android-sdk2
Upstream advisory

GHSA-x989-q2pq-4q5x

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to Int overflow in `RaggedRangeOp`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-x989-q2pq-4q5x

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to Int overflow in `RaggedRangeOp`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-v5xg-3q2c-c2r4

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` failure in `TensorListReserve` via missing validation

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-v5xg-3q2c-c2r4

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` failure in `TensorListReserve` via missing validation

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-828c-5j5q-vrjq

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to null-dereference in `mlir::tfg::GraphDefImporter::ConvertNodeDef`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-828c-5j5q-vrjq

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to null-dereference in `mlir::tfg::GraphDefImporter::ConvertNodeDef`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-g468-qj8g-vcjc

Open SourceCoalition ESS < 30%LOW2022-09-16

TensorFlow vulnerable to `CHECK`-fail in `tensorflow::full_type::SubstituteFromAttrs`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-g468-qj8g-vcjc

Open SourceCoalition ESS < 30%2022-09-16

TensorFlow vulnerable to `CHECK`-fail in `tensorflow::full_type::SubstituteFromAttrs`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-rh87-q4vg-m45j

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow vulnerable to integer overflow in math ops

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-rh87-q4vg-m45j

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow vulnerable to integer overflow in math ops

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-jvhc-5hhr-w3v5

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to assertion fail on MLIR empty edge names

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-jvhc-5hhr-w3v5

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to assertion fail on MLIR empty edge names

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35940

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to Int overflow in `RaggedRangeOp`

CVEs:CVE-2022-35940

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35940

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to Int overflow in `RaggedRangeOp`

CVEs:CVE-2022-35940

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35940

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. The `RaggedRangOp` function takes an argument `limits` that is eventually used to construct a `TensorShape` as an `int64`. If `limits` is a very large float, it can overflow when converted to ...

CVEs:CVE-2022-35940

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-35960

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. In `core/kernels/list_kernels.cc's TensorListReserve`, `num_elements` is assumed to be a tensor of size 1. When a `num_elements` of more than 1 element is provided, then `tf.raw_ops.TensorList...

CVEs:CVE-2022-35960

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-35960

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` failure in `TensorListReserve` via missing validation

CVEs:CVE-2022-35960

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35960

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` failure in `TensorListReserve` via missing validation

CVEs:CVE-2022-35960

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-36012

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. When `mlir::tfg::ConvertGenericFunctionToFunctionDef` is given empty function attributes, it crashes. We have patched the issue in GitHub commit ad069af92392efee1418c48ff561fd3070a03d7b. The f...

CVEs:CVE-2022-36012

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-36012

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to assertion fail on MLIR empty edge names

CVEs:CVE-2022-36012

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-36012

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to assertion fail on MLIR empty edge names

CVEs:CVE-2022-36012

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-36013

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to null-dereference in `mlir::tfg::GraphDefImporter::ConvertNodeDef`

CVEs:CVE-2022-36013

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-36013

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to null-dereference in `mlir::tfg::GraphDefImporter::ConvertNodeDef`

CVEs:CVE-2022-36013

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-36013

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. When `mlir::tfg::GraphDefImporter::ConvertNodeDef` tries to convert NodeDefs without an op name, it crashes. We have patched the issue in GitHub commit a0f0b9a21c9270930457095092f558fbad4c03e5...

CVEs:CVE-2022-36013

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-36015

Open SourceCoalition ESS < 30%2022-09-16

TensorFlow vulnerable to integer overflow in math ops

CVEs:CVE-2022-36015

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-36015

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. When `RangeSize` receives values that do not fit into an `int64_t`, it crashes. We have patched the issue in GitHub commit 37e64539cd29fcfb814c4451152a60f5d107b0f0. The fix will be included in...

CVEs:CVE-2022-36015

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-36015

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow vulnerable to integer overflow in math ops

CVEs:CVE-2022-36015

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-36016

Open SourceCoalition ESS < 30%2022-09-16

TensorFlow vulnerable to `CHECK`-fail in `tensorflow::full_type::SubstituteFromAttrs`

CVEs:CVE-2022-36016

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-36016

Open SourceCoalition ESS < 30%2022-09-16

TensorFlow vulnerable to `CHECK`-fail in `tensorflow::full_type::SubstituteFromAttrs`

CVEs:CVE-2022-36016

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-36016

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. When `tensorflow::full_type::SubstituteFromAttrs` receives a `FullTypeDef& t` that is not exactly three args, it triggers a `CHECK`-fail instead of returning a status. We have patched the issu...

CVEs:CVE-2022-36016

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

DEBIAN-CVE-2022-3043

Open SourceCoalition ESS < 30%CRITICAL2022-09-26

DEBIAN-CVE-2022-3043

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:11 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-3055

Open SourceCoalition ESS < 30%CRITICAL2022-09-26

DEBIAN-CVE-2022-3055

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-3051

Open SourceCoalition ESS < 30%CRITICAL2022-09-26

DEBIAN-CVE-2022-3051

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-2854

Open SourceCoalition ESS < 30%CRITICAL2022-09-26

DEBIAN-CVE-2022-2854

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-3307

GoogleCoalition ESS < 30%CRITICAL2022-09-27

Use after free in media in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-3307

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-2857

Open SourceCoalition ESS < 30%CRITICAL2022-09-26

DEBIAN-CVE-2022-2857

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-3313

GoogleCoalition ESS < 30%MEDIUM2022-09-27

Incorrect security UI in full screen in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2022-3313

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-3058

Open SourceCoalition ESS < 30%CRITICAL2022-09-26

DEBIAN-CVE-2022-3058

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-3306

GoogleCoalition ESS < 30%CRITICAL2022-09-27

Use after free in survey in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-3306

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-3201

Open SourceCoalition ESS < 30%MEDIUM2022-09-26

DEBIAN-CVE-2022-3201

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-3054

Open SourceCoalition ESS < 30%CRITICAL2022-09-26

DEBIAN-CVE-2022-3054

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-3201

GoogleCoalition ESS < 30%MEDIUM2022-09-14

Insufficient validation of untrusted input in DevTools in Google Chrome on Chrome OS prior to 105.0.5195.125 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted HTML page. (Chromium ...

CVEs:CVE-2022-3201

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2022-3198

Open SourceCoalition ESS < 30%CRITICAL2022-09-26

DEBIAN-CVE-2022-3198

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:11 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-3198

GoogleCoalition ESS < 30%CRITICAL2022-09-14

Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)

CVEs:CVE-2022-3198

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-3311

GoogleCoalition ESS < 30%CRITICAL2022-09-27

Use after free in import in Google Chrome prior to 106.0.5249.62 allowed a remote attacker who had compromised a WebUI process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2022-3311

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-3315

GoogleCoalition ESS < 30%HIGH2022-09-27

Type confusion in Blink in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2022-3315

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-4187

GoogleCoalition ESS < 30%CRITICAL2022-09-07

Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 108.0.5359.71 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2022-4187

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-3305

GoogleCoalition ESS < 30%CRITICAL2022-09-27

Use after free in survey in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-3305

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-2861

Open SourceCoalition ESS < 30%MEDIUM2022-09-26

DEBIAN-CVE-2022-2861

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-3309

GoogleCoalition ESS < 30%CRITICAL2022-09-27

Use after free in assistant in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via specific UI gestures. (Chromium security severi...

CVEs:CVE-2022-3309

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-35938

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. The `GatherNd` function takes arguments that determine the sizes of inputs and outputs. If the inputs given are greater than or equal to the sizes of the outputs, an out-of-bounds memory read ...

CVEs:CVE-2022-35938

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

GHSA-ffjm-4qwc-7cmf

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to OOB write in `scatter_nd` in TF Lite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-ffjm-4qwc-7cmf

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to OOB write in `scatter_nd` in TF Lite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-pxrw-j2fv-hx3h

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to OOB read in `Gather_nd` in TF Lite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-pxrw-j2fv-hx3h

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to OOB read in `Gather_nd` in TF Lite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35937

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to OOB read in `Gather_nd` in TF Lite

CVEs:CVE-2022-35937

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35937

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to OOB read in `Gather_nd` in TF Lite

CVEs:CVE-2022-35937

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35937

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. The `GatherNd` function takes arguments that determine the sizes of inputs and outputs. If the inputs given are greater than or equal to the sizes of the outputs, an out-of-bounds memory read ...

CVEs:CVE-2022-35937

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-35939

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to OOB write in `scatter_nd` in TF Lite

CVEs:CVE-2022-35939

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35939

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. The `ScatterNd` function takes an input argument that determines the indices of of the output tensor. An input index greater than the output tensor or less than zero will either write content ...

CVEs:CVE-2022-35939

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-35939

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to OOB write in `scatter_nd` in TF Lite

CVEs:CVE-2022-35939

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-3316

GoogleCoalition ESS < 30%MEDIUM2022-09-27

Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass security feature via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2022-3316

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-3053

Open SourceCoalition ESS < 30%MEDIUM2022-09-26

DEBIAN-CVE-2022-3053

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-3310

GoogleCoalition ESS < 30%CRITICAL2022-09-27

Insufficient policy enforcement in custom tabs in Google Chrome on Android prior to 106.0.5249.62 allowed an attacker who convinced the user to install an application to bypass same origin policy via a crafted application. (Chromium security severity: ...

CVEs:CVE-2022-3310

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-3049

Open SourceCoalition ESS < 30%CRITICAL2022-09-26

DEBIAN-CVE-2022-3049

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-3057

Open SourceCoalition ESS < 30%MEDIUM2022-09-26

DEBIAN-CVE-2022-3057

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GHSA-vm7x-4qhj-rrcq

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `TensorListScatter` and `TensorListScatterV2`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-vm7x-4qhj-rrcq

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `TensorListScatter` and `TensorListScatterV2`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-97p7-w86h-vcf9

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` failure in `SobolSample` via missing validation

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-97p7-w86h-vcf9

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` failure in `SobolSample` via missing validation

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35935

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` failure in `SobolSample` via missing validation

CVEs:CVE-2022-35935

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35935

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` failure in `SobolSample` via missing validation

CVEs:CVE-2022-35935

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35935

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. The implementation of SobolSampleOp is vulnerable to a denial of service via CHECK-failure (assertion failure) caused by assuming `input(0)`, `input(1)`, and `input(2)` to be scalar. This issu...

CVEs:CVE-2022-35935

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-35991

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` fail in `TensorListScatter` and `TensorListScatterV2`

CVEs:CVE-2022-35991

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35991

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. When `TensorListScatter` and `TensorListScatterV2` receive an `element_shape` of a rank greater than one, they give a `CHECK` fail that can trigger a denial of service attack. We have patched ...

CVEs:CVE-2022-35991

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-35991

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `TensorListScatter` and `TensorListScatterV2`

CVEs:CVE-2022-35991

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

DEBIAN-CVE-2022-3042

Open SourceCoalition ESS < 30%CRITICAL2022-09-26

DEBIAN-CVE-2022-3042

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GHSA-wr9v-g9vf-c74v

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to segfault in `RaggedBincount`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

GHSA-wr9v-g9vf-c74v

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to segfault in `RaggedBincount`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
Upstream advisory

GHSA-397c-5g2j-qxpv

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to segfault in `SparseBincount`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-397c-5g2j-qxpv

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to segfault in `SparseBincount`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-v7vw-577f-vp8x

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to segfault in `QuantizedRelu` and `QuantizedRelu6`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-v7vw-577f-vp8x

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to segfault in `QuantizedRelu` and `QuantizedRelu6`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-vgvh-2pf4-jr2x

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to segfault in `QuantizeDownAndShrinkRange`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-vgvh-2pf4-jr2x

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to segfault in `QuantizeDownAndShrinkRange`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-689c-r7h2-fv9v

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to segfault in `QuantizedMatMul`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-689c-r7h2-fv9v

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to segfault in `QuantizedMatMul`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-g35r-369w-3fqp

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to segfault in `QuantizedInstanceNorm`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-g35r-369w-3fqp

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to segfault in `QuantizedInstanceNorm`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35986

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to segfault in `RaggedBincount`

CVEs:CVE-2022-35986

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

CVE-2022-35986

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to segfault in `RaggedBincount`

CVEs:CVE-2022-35986

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

CVE-2022-35986

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. If `RaggedBincount` is given an empty input tensor `splits`, it results in a segfault that can be used to trigger a denial of service attack. We have patched the issue in GitHub commit 7a4591f...

CVEs:CVE-2022-35986

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

GHSA-wqmc-pm8c-2jhc

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to segfault in `Requantize`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-wqmc-pm8c-2jhc

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to segfault in `Requantize`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35970

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to segfault in `QuantizedInstanceNorm`

CVEs:CVE-2022-35970

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35970

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to segfault in `QuantizedInstanceNorm`

CVEs:CVE-2022-35970

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35970

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. If `QuantizedInstanceNorm` is given `x_min` or `x_max` tensors of a nonzero rank, it results in a segfault that can be used to trigger a denial of service attack. We have patched the issue in ...

CVEs:CVE-2022-35970

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-35973

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to segfault in `QuantizedMatMul`

CVEs:CVE-2022-35973

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35973

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to segfault in `QuantizedMatMul`

CVEs:CVE-2022-35973

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35973

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. If `QuantizedMatMul` is given nonscalar input for: `min_a`, `max_a`, `min_b`, or `max_b` It gives a segfault that can be used to trigger a denial of service attack. We have patched the issue i...

CVEs:CVE-2022-35973

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-35974

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to segfault in `QuantizeDownAndShrinkRange`

CVEs:CVE-2022-35974

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35974

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. If `QuantizeDownAndShrinkRange` is given nonscalar inputs for `input_min` or `input_max`, it results in a segfault that can be used to trigger a denial of service attack. We have patched the i...

CVEs:CVE-2022-35974

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-35974

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to segfault in `QuantizeDownAndShrinkRange`

CVEs:CVE-2022-35974

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35979

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. If `QuantizedRelu` or `QuantizedRelu6` are given nonscalar inputs for `min_features` or `max_features`, it results in a segfault that can be used to trigger a denial of service attack. We have...

CVEs:CVE-2022-35979

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-35979

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to segfault in `QuantizedRelu` and `QuantizedRelu6`

CVEs:CVE-2022-35979

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35979

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to segfault in `QuantizedRelu` and `QuantizedRelu6`

CVEs:CVE-2022-35979

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35982

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. If `SparseBincount` is given inputs for `indices`, `values`, and `dense_shape` that do not make a valid sparse tensor, it results in a segfault that can be used to trigger a denial of service ...

CVEs:CVE-2022-35982

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-35982

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to segfault in `SparseBincount`

CVEs:CVE-2022-35982

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35982

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to segfault in `SparseBincount`

CVEs:CVE-2022-35982

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-36017

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to segfault in `Requantize`

CVEs:CVE-2022-36017

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-36017

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. If `Requantize` is given `input_min`, `input_max`, `requested_output_min`, `requested_output_max` tensors of a nonzero rank, it results in a segfault that can be used to trigger a denial of se...

CVEs:CVE-2022-36017

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-36017

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to segfault in `Requantize`

CVEs:CVE-2022-36017

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-20386

Open SourceCoalition ESS < 30%CRITICAL2022-09-07

Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227328

CVEs:CVE-2022-20386

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20387

Open SourceCoalition ESS < 30%CRITICAL2022-09-07

Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227324

CVEs:CVE-2022-20387

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20388

Open SourceCoalition ESS < 30%CRITICAL2022-09-07

Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227323

CVEs:CVE-2022-20388

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20389

Open SourceCoalition ESS < 30%CRITICAL2022-09-07

Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257004

CVEs:CVE-2022-20389

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20390

Open SourceCoalition ESS < 30%CRITICAL2022-09-07

Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257002

CVEs:CVE-2022-20390

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20391

Open SourceCoalition ESS < 30%CRITICAL2022-09-07

Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257000

CVEs:CVE-2022-20391

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-238227323

GoogleCoalition ESS < 30%2022-09-01

ASB-A-238227323

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-238227324

GoogleCoalition ESS < 30%2022-09-01

ASB-A-238227324

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-238227328

GoogleCoalition ESS < 30%2022-09-01

ASB-A-238227328

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-238257000

GoogleCoalition ESS < 30%2022-09-01

ASB-A-238257000

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-238257002

GoogleCoalition ESS < 30%2022-09-01

ASB-A-238257002

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-238257004

GoogleCoalition ESS < 30%2022-09-01

ASB-A-238257004

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

GHSA-4pc4-m9mj-v2r9

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to segfault in `QuantizedBiasAdd`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-4pc4-m9mj-v2r9

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to segfault in `QuantizedBiasAdd`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-v6h3-348g-6h5x

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to segfault in `QuantizedAdd`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-v6h3-348g-6h5x

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to segfault in `QuantizedAdd`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-4w68-4x85-mjj9

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to segfault in `QuantizedAvgPool`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-4w68-4x85-mjj9

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to segfault in `QuantizedAvgPool`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-f7r5-q7cx-h668

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to segfault in `BlockLSTMGradV2`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-f7r5-q7cx-h668

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to segfault in `BlockLSTMGradV2`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35964

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to segfault in `BlockLSTMGradV2`

CVEs:CVE-2022-35964

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35964

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. The implementation of `BlockLSTMGradV2` does not fully validate its inputs. This results in a a segfault that can be used to trigger a denial of service attack. We have patched the issue in Gi...

CVEs:CVE-2022-35964

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-35964

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to segfault in `BlockLSTMGradV2`

CVEs:CVE-2022-35964

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35966

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to segfault in `QuantizedAvgPool`

CVEs:CVE-2022-35966

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35966

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. If `QuantizedAvgPool` is given `min_input` or `max_input` tensors of a nonzero rank, it results in a segfault that can be used to trigger a denial of service attack. We have patched the issue ...

CVEs:CVE-2022-35966

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-35966

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to segfault in `QuantizedAvgPool`

CVEs:CVE-2022-35966

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35967

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to segfault in `QuantizedAdd`

CVEs:CVE-2022-35967

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35967

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to segfault in `QuantizedAdd`

CVEs:CVE-2022-35967

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35967

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. If `QuantizedAdd` is given `min_input` or `max_input` tensors of a nonzero rank, it results in a segfault that can be used to trigger a denial of service attack. We have patched the issue in G...

CVEs:CVE-2022-35967

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-35972

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to segfault in `QuantizedBiasAdd`

CVEs:CVE-2022-35972

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35972

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to segfault in `QuantizedBiasAdd`

CVEs:CVE-2022-35972

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35972

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. If `QuantizedBiasAdd` is given `min_input`, `max_input`, `min_bias`, `max_bias` tensors of a nonzero rank, it results in a segfault that can be used to trigger a denial of service attack. We h...

CVEs:CVE-2022-35972

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

GHSA-9vqj-64pv-w55c

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `tf.linalg.matrix_rank`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-9vqj-64pv-w55c

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `tf.linalg.matrix_rank`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35998

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `EmptyTensorList`

CVEs:CVE-2022-35998

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

CVE-2022-35998

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. If `EmptyTensorList` receives an input `element_shape` with more than one dimension, it gives a `CHECK` fail that can be used to trigger a denial of service attack. We have patched the issue i...

CVEs:CVE-2022-35998

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-35998

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` fail in `EmptyTensorList`

CVEs:CVE-2022-35998

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

GHSA-qhw4-wwr7-gjc5

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `EmptyTensorList`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
Upstream advisory

GHSA-qhw4-wwr7-gjc5

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `EmptyTensorList`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

GHSA-mv8m-8x97-937q

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `tf.random.gamma`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-mv8m-8x97-937q

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `tf.random.gamma`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-p7hr-f446-x6qf

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `tf.sparse.cross`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-p7hr-f446-x6qf

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `tf.sparse.cross`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35988

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` fail in `tf.linalg.matrix_rank`

CVEs:CVE-2022-35988

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35988

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `tf.linalg.matrix_rank`

CVEs:CVE-2022-35988

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35988

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. When `tf.linalg.matrix_rank` receives an empty input `a`, the GPU kernel gives a `CHECK` fail that can be used to trigger a denial of service attack. We have patched the issue in GitHub commit...

CVEs:CVE-2022-35988

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-35997

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. If `tf.sparse.cross` receives an input `separator` that is not a scalar, it gives a `CHECK` fail that can be used to trigger a denial of service attack. We have patched the issue in GitHub com...

CVEs:CVE-2022-35997

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-35997

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `tf.sparse.cross`

CVEs:CVE-2022-35997

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35997

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` fail in `tf.sparse.cross`

CVEs:CVE-2022-35997

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-36004

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. When `tf.random.gamma` receives large input shape and rates, it gives a `CHECK` fail that can trigger a denial of service attack. We have patched the issue in GitHub commit 552bfced6ce4809db5f...

CVEs:CVE-2022-36004

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-36004

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `tf.random.gamma`

CVEs:CVE-2022-36004

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-36004

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` fail in `tf.random.gamma`

CVEs:CVE-2022-36004

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-3318

GoogleCoalition ESS < 30%CRITICAL2022-09-27

Use after free in ChromeOS Notifications in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker who convinced a user to reboot Chrome OS to potentially exploit heap corruption via UI interaction. (Chromium security severity: Low)

CVEs:CVE-2022-3318

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-m6vp-8q9j-whx4

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `Save` and `SaveSlices`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-m6vp-8q9j-whx4

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `Save` and `SaveSlices`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-p2xf-8hgm-hpw5

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `ParameterizedTruncatedNormal`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-p2xf-8hgm-hpw5

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `ParameterizedTruncatedNormal`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-9942-r22v-78cp

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `LRNGrad`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-9942-r22v-78cp

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `LRNGrad`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-j43h-pgmg-5hjq

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `MaxPool`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-j43h-pgmg-5hjq

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `MaxPool`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-vxv8-r8q2-63xw

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `FractionalMaxPoolGrad`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-vxv8-r8q2-63xw

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `FractionalMaxPoolGrad`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-2475-53vw-vp25

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `AvgPoolGrad`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-2475-53vw-vp25

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `AvgPoolGrad`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-9v8w-xmr4-wgxp

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `TensorListFromTensor`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-9v8w-xmr4-wgxp

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `TensorListFromTensor`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-wq6q-6m32-9rv9

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `SetSize`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-wq6q-6m32-9rv9

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `SetSize`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-84jm-4cf3-9jfm

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` failures in `FractionalAvgPoolGrad`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-84jm-4cf3-9jfm

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` failures in `FractionalAvgPoolGrad`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-fhfc-2q7x-929f

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `CollectiveGather`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-fhfc-2q7x-929f

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `CollectiveGather`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-q5jv-m6qw-5g37

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to floating point exception in `Conv2D`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-q5jv-m6qw-5g37

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to floating point exception in `Conv2D`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-fqxc-pvf8-2w9v

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to null dereference on MLIR on empty function attributes

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-fqxc-pvf8-2w9v

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to null dereference on MLIR on empty function attributes

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-jqm7-m5q7-3hm5

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `DrawBoundingBoxes`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-jqm7-m5q7-3hm5

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `DrawBoundingBoxes`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-mh3m-62v7-68xg

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `Unbatch`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-mh3m-62v7-68xg

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `Unbatch`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-fv43-93gv-vm8f

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to null dereference on MLIR on empty function attributes

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-fv43-93gv-vm8f

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to null dereference on MLIR on empty function attributes

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-cv2p-32v3-vhwq

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `RandomPoissonV2`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-cv2p-32v3-vhwq

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `RandomPoissonV2`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-r26c-679w-mrjm

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVarsGradient`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-r26c-679w-mrjm

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVarsGradient`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-g9h5-vr8m-x2h4

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `AudioSummaryV2`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-g9h5-vr8m-x2h4

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `AudioSummaryV2`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-w62h-8xjm-fv49

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `DenseBincount`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-w62h-8xjm-fv49

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `DenseBincount`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-9cr2-8pwr-fhfq

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `QuantizeAndDequantizeV3`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-9cr2-8pwr-fhfq

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `QuantizeAndDequantizeV3`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-9j4v-pp28-mxv7

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVarsPerChannel`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-9j4v-pp28-mxv7

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVarsPerChannel`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-f4w6-h4f5-wx45

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` failure in tf.reshape via overflows

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-f4w6-h4f5-wx45

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` failure in tf.reshape via overflows

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-37jf-mjv6-xfqw

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `Conv2DBackpropInput`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-37jf-mjv6-xfqw

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `Conv2DBackpropInput`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35934

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` failure in tf.reshape via overflows

CVEs:CVE-2022-35934

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35934

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. The implementation of tf.reshape op in TensorFlow is vulnerable to a denial of service via CHECK-failure (assertion failure) caused by overflowing the number of elements in a tensor. This issu...

CVEs:CVE-2022-35934

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-35934

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` failure in tf.reshape via overflows

CVEs:CVE-2022-35934

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35963

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` failures in `FractionalAvgPoolGrad`

CVEs:CVE-2022-35963

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35963

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` failures in `FractionalAvgPoolGrad`

CVEs:CVE-2022-35963

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35963

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. The implementation of `FractionalAvgPoolGrad` does not fully validate the input `orig_input_tensor_shape`. This results in an overflow that results in a `CHECK` failure which can be used to tr...

CVEs:CVE-2022-35963

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-35968

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. The implementation of `AvgPoolGrad` does not fully validate the input `orig_input_shape`. This results in a `CHECK` failure which can be used to trigger a denial of service attack. We have pat...

CVEs:CVE-2022-35968

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-35968

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `AvgPoolGrad`

CVEs:CVE-2022-35968

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35968

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` fail in `AvgPoolGrad`

CVEs:CVE-2022-35968

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35981

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `FractionalMaxPoolGrad`

CVEs:CVE-2022-35981

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35981

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` fail in `FractionalMaxPoolGrad`

CVEs:CVE-2022-35981

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35981

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. `FractionalMaxPoolGrad` validates its inputs with `CHECK` failures instead of with returning errors. If it gets incorrectly sized inputs, the `CHECK` failure can be used to trigger a denial of...

CVEs:CVE-2022-35981

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-35983

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. If `Save` or `SaveSlices` is run over tensors of an unsupported `dtype`, it results in a `CHECK` fail that can be used to trigger a denial of service attack. We have patched the issue in GitHu...

CVEs:CVE-2022-35983

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-35983

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` fail in `Save` and `SaveSlices`

CVEs:CVE-2022-35983

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35983

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `Save` and `SaveSlices`

CVEs:CVE-2022-35983

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35984

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `ParameterizedTruncatedNormal`

CVEs:CVE-2022-35984

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35984

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. `ParameterizedTruncatedNormal` assumes `shape` is of type `int32`. A valid `shape` of type `int64` results in a mismatched type `CHECK` fail that can be used to trigger a denial of service att...

CVEs:CVE-2022-35984

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-35984

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` fail in `ParameterizedTruncatedNormal`

CVEs:CVE-2022-35984

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35985

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` fail in `LRNGrad`

CVEs:CVE-2022-35985

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35985

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `LRNGrad`

CVEs:CVE-2022-35985

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35985

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. If `LRNGrad` is given an `output_image` input tensor that is not 4-D, it results in a `CHECK` fail that can be used to trigger a denial of service attack. We have patched the issue in GitHub c...

CVEs:CVE-2022-35985

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-35987

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. `DenseBincount` assumes its input tensor `weights` to either have the same shape as its input tensor `input` or to be length-0. A different `weights` shape will trigger a `CHECK` fail that can...

CVEs:CVE-2022-35987

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-35987

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `DenseBincount`

CVEs:CVE-2022-35987

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35987

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` fail in `DenseBincount`

CVEs:CVE-2022-35987

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35989

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `MaxPool`

CVEs:CVE-2022-35989

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35989

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` fail in `MaxPool`

CVEs:CVE-2022-35989

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35989

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. When `MaxPool` receives a window size input array `ksize` with dimensions greater than its input tensor `input`, the GPU kernel gives a `CHECK` fail that can be used to trigger a denial of ser...

CVEs:CVE-2022-35989

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-35992

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `TensorListFromTensor`

CVEs:CVE-2022-35992

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35992

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` fail in `TensorListFromTensor`

CVEs:CVE-2022-35992

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35992

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. When `TensorListFromTensor` receives an `element_shape` of a rank greater than one, it gives a `CHECK` fail that can trigger a denial of service attack. We have patched the issue in GitHub com...

CVEs:CVE-2022-35992

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-35993

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` fail in `SetSize`

CVEs:CVE-2022-35993

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35993

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `SetSize`

CVEs:CVE-2022-35993

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35993

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. When `SetSize` receives an input `set_shape` that is not a 1D tensor, it gives a `CHECK` fails that can be used to trigger a denial of service attack. We have patched the issue in GitHub commi...

CVEs:CVE-2022-35993

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-35994

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `CollectiveGather`

CVEs:CVE-2022-35994

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35994

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. When `CollectiveGather` receives an scalar input `input`, it gives a `CHECK` fails that can be used to trigger a denial of service attack. We have patched the issue in GitHub commit c1f491817d...

CVEs:CVE-2022-35994

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-35994

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` fail in `CollectiveGather`

CVEs:CVE-2022-35994

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35995

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` fail in `AudioSummaryV2`

CVEs:CVE-2022-35995

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35995

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. When `AudioSummaryV2` receives an input `sample_rate` with more than one element, it gives a `CHECK` fails that can be used to trigger a denial of service attack. We have patched the issue in ...

CVEs:CVE-2022-35995

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-35995

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `AudioSummaryV2`

CVEs:CVE-2022-35995

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35996

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to floating point exception in `Conv2D`

CVEs:CVE-2022-35996

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35996

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to floating point exception in `Conv2D`

CVEs:CVE-2022-35996

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35996

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. If `Conv2D` is given empty `input` and the `filter` and `padding` sizes are valid, the output is all-zeros. This causes division-by-zero floating point exceptions that can be used to trigger a...

CVEs:CVE-2022-35996

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-35999

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` fail in `Conv2DBackpropInput`

CVEs:CVE-2022-35999

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35999

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `Conv2DBackpropInput`

CVEs:CVE-2022-35999

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35999

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. When `Conv2DBackpropInput` receives empty `out_backprop` inputs (e.g. `[3, 1, 0, 1]`), the current CPU/GPU kernels `CHECK` fail (one with dnnl, the other with cudnn). This can be used to trigg...

CVEs:CVE-2022-35999

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-36000

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to null dereference on MLIR on empty function attributes

CVEs:CVE-2022-36000

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-36000

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. When `mlir::tfg::ConvertGenericFunctionToFunctionDef` is given empty function attributes, it gives a null dereference. We have patched the issue in GitHub commit aed36912609fc07229b4d0a7b44f3f...

CVEs:CVE-2022-36000

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-36000

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to null dereference on MLIR on empty function attributes

CVEs:CVE-2022-36000

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-36001

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. When `DrawBoundingBoxes` receives an input `boxes` that is not of dtype `float`, it gives a `CHECK` fail that can trigger a denial of service attack. We have patched the issue in GitHub commit...

CVEs:CVE-2022-36001

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-36001

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` fail in `DrawBoundingBoxes`

CVEs:CVE-2022-36001

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-36001

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `DrawBoundingBoxes`

CVEs:CVE-2022-36001

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-36002

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` fail in `Unbatch`

CVEs:CVE-2022-36002

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-36002

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. When `Unbatch` receives a nonscalar input `id`, it gives a `CHECK` fail that can trigger a denial of service attack. We have patched the issue in GitHub commit 4419d10d576adefa36b0e0a9425d2569...

CVEs:CVE-2022-36002

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-36002

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `Unbatch`

CVEs:CVE-2022-36002

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-36003

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` fail in `RandomPoissonV2`

CVEs:CVE-2022-36003

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-36003

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. When `RandomPoissonV2` receives large input shape and rates, it gives a `CHECK` fail that can trigger a denial of service attack. We have patched the issue in GitHub commit 552bfced6ce4809db5f...

CVEs:CVE-2022-36003

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-36003

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `RandomPoissonV2`

CVEs:CVE-2022-36003

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-36005

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVarsGradient`

CVEs:CVE-2022-36005

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-36005

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVarsGradient`

CVEs:CVE-2022-36005

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-36005

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. When `tf.quantization.fake_quant_with_min_max_vars_gradient` receives input `min` or `max` that is nonscalar, it gives a `CHECK` fail that can trigger a denial of service attack. We have patch...

CVEs:CVE-2022-36005

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-36011

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to null dereference on MLIR on empty function attributes

CVEs:CVE-2022-36011

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-36011

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. When `mlir::tfg::ConvertGenericFunctionToFunctionDef` is given empty function attributes, it gives a null dereference. We have patched the issue in GitHub commit 1cf45b831eeb0cab8655c9c7c5d06e...

CVEs:CVE-2022-36011

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-36011

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to null dereference on MLIR on empty function attributes

CVEs:CVE-2022-36011

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-36019

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVarsPerChannel`

CVEs:CVE-2022-36019

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-36019

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVarsPerChannel`

CVEs:CVE-2022-36019

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-36019

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. If `FakeQuantWithMinMaxVarsPerChannel` is given `min` or `max` tensors of a rank other than one, it results in a `CHECK` fail that can be used to trigger a denial of service attack. We have pa...

CVEs:CVE-2022-36019

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-36026

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `QuantizeAndDequantizeV3`

CVEs:CVE-2022-36026

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-36026

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. If `QuantizeAndDequantizeV3` is given a nonscalar `num_bits` input tensor, it results in a `CHECK` fail that can be used to trigger a denial of service attack. We have patched the issue in Git...

CVEs:CVE-2022-36026

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-36026

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` fail in `QuantizeAndDequantizeV3`

CVEs:CVE-2022-36026

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-3314

GoogleCoalition ESS < 30%CRITICAL2022-09-27

Use after free in logging in Google Chrome prior to 106.0.5249.62 allowed a remote attacker who had compromised a WebUI process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2022-3314

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-3047

Open SourceCoalition ESS < 30%CRITICAL2022-09-26

DEBIAN-CVE-2022-3047

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GHSA-9fpg-838v-wpv7

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVars`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-9fpg-838v-wpv7

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVars`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-q2c3-jpmc-gfjx

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `Conv2DBackpropInput`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-q2c3-jpmc-gfjx

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `Conv2DBackpropInput`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-h7ff-cfc9-wmmh

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVarsPerChannelGradient`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-h7ff-cfc9-wmmh

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVarsPerChannelGradient`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-qxpx-j395-pw36

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to segfault in `LowerBound` and `UpperBound`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-qxpx-j395-pw36

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to segfault in `LowerBound` and `UpperBound`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-wxjj-cgcx-r3vq

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` failures in `AvgPool3DGrad`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-wxjj-cgcx-r3vq

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` failures in `AvgPool3DGrad`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-m6cv-4fmf-66xf

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `RaggedTensorToVariant`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-m6cv-4fmf-66xf

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `RaggedTensorToVariant`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35959

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. The implementation of `AvgPool3DGradOp` does not fully validate the input `orig_input_shape`. This results in an overflow that results in a `CHECK` failure which can be used to trigger a denia...

CVEs:CVE-2022-35959

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-35959

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` failures in `AvgPool3DGrad`

CVEs:CVE-2022-35959

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35959

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` failures in `AvgPool3DGrad`

CVEs:CVE-2022-35959

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35965

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. If `LowerBound` or `UpperBound` is given an empty`sorted_inputs` input, it results in a `nullptr` dereference, leading to a segfault that can be used to trigger a denial of service attack. We ...

CVEs:CVE-2022-35965

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-35965

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to segfault in `LowerBound` and `UpperBound`

CVEs:CVE-2022-35965

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35965

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to segfault in `LowerBound` and `UpperBound`

CVEs:CVE-2022-35965

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35969

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `Conv2DBackpropInput`

CVEs:CVE-2022-35969

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35969

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. The implementation of `Conv2DBackpropInput` requires `input_sizes` to be 4-dimensional. Otherwise, it gives a `CHECK` failure which can be used to trigger a denial of service attack. We have p...

CVEs:CVE-2022-35969

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-35969

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` fail in `Conv2DBackpropInput`

CVEs:CVE-2022-35969

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35971

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. If `FakeQuantWithMinMaxVars` is given `min` or `max` tensors of a nonzero rank, it results in a `CHECK` fail that can be used to trigger a denial of service attack. We have patched the issue i...

CVEs:CVE-2022-35971

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-35971

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVars`

CVEs:CVE-2022-35971

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35971

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVars`

CVEs:CVE-2022-35971

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35990

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVarsPerChannelGradient`

CVEs:CVE-2022-35990

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35990

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVarsPerChannelGradient`

CVEs:CVE-2022-35990

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-35990

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. When `tf.quantization.fake_quant_with_min_max_vars_per_channel_gradient` receives input `min` or `max` of rank other than 1, it gives a `CHECK` fail that can trigger a denial of service attack...

CVEs:CVE-2022-35990

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-36018

Open SourceCoalition ESS < 30%MEDIUM2022-09-16

TensorFlow vulnerable to `CHECK` fail in `RaggedTensorToVariant`

CVEs:CVE-2022-36018

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-36018

Open SourceCoalition ESS < 30%HIGH2022-09-16

TensorFlow vulnerable to `CHECK` fail in `RaggedTensorToVariant`

CVEs:CVE-2022-36018

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-36018

Open SourceCoalition ESS < 30%CRITICAL2022-09-16

TensorFlow is an open source platform for machine learning. If `RaggedTensorToVariant` is given a `rt_nested_splits` list that contains tensors of ranks other than one, it results in a `CHECK` fail that can be used to trigger a denial of service attack...

CVEs:CVE-2022-36018

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

DEBIAN-CVE-2022-3071

Open SourceCoalition ESS < 30%CRITICAL2022-09-26

DEBIAN-CVE-2022-3071

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-20385

Open SourceCoalition ESS < 30%CRITICAL2022-09-07

a function called 'nla_parse', do not check the len of para, it will check nla_type (which can be controlled by userspace) with 'maxtype' (in this case, it is GSCAN_MAX), then it access polciy array 'policy[type]', which OOB access happens.Product: And...

CVEs:CVE-2022-20385

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-238379819

GoogleCoalition ESS < 30%2022-09-01

ASB-A-238379819

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-2995

GoogleCoalition ESS < 30%HIGH2022-09-19

CRI-O incorrect handling of supplementary groups may lead to sensitive information disclosure

CVEs:CVE-2022-2995

Affected products

ProductStatusVendorPackageEcosystem
cri-o/cri-o affected github.com github.com/cri-o/cri-o
Upstream advisory

CVE-2022-2995

GoogleCoalition ESS < 30%HIGH2022-09-19

Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to ...

CVEs:CVE-2022-2995

Affected products

ProductStatusVendorPackageEcosystem
cri-o affected kubernetes
Upstream advisory

CVE-2021-0942

Open SourceCoalition ESS < 30%CRITICAL2022-09-07

The path in this case is a little bit convoluted. The end result is that via an ioctl an untrusted app can control the ui32PageIndex offset in the expression:sPA.uiAddr = page_to_phys(psOSPageArrayData->pagearray[ui32PageIndex]);With the current PoC th...

CVEs:CVE-2021-0942

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-238904312

GoogleCoalition ESS < 30%HIGH2022-09-01

ASB-A-238904312

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

DEBIAN-CVE-2022-3048

Open SourceCoalition ESS < 30%MEDIUM2022-09-26

DEBIAN-CVE-2022-3048

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:11 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-2990

Open SourceCoalition ESS < 30%HIGH2022-09-13

DEBIAN-CVE-2022-2990

Affected products

ProductStatusVendorPackageEcosystem
golang-github-containers-buildah affected Debian:11 golang-github-containers-buildah
golang-github-containers-buildah affected Debian:12 golang-github-containers-buildah
golang-github-containers-buildah affected Debian:13 golang-github-containers-buildah
golang-github-containers-buildah affected Debian:14 golang-github-containers-buildah
Upstream advisory

CVE-2022-3312

GoogleCoalition ESS < 30%MEDIUM2022-09-27

Insufficient validation of untrusted input in VPN in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a local attacker to bypass managed device restrictions via physical access to the device. (Chromium security severity: Medium)

CVEs:CVE-2022-3312

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-36853

Open SourceCoalition ESS < 30%HIGH2022-09-09

Intent redirection in Photo Editor prior to SMR Sep-2022 Release 1 allows attacker to get sensitive information.

CVEs:CVE-2022-36853

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26469

Open SourceCoalition ESS < 30%HIGH2022-09-06

In MtkEmail, there is a possible escalation of privilege due to fragment injection. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07216598...

CVEs:CVE-2022-26469

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26468

Open SourceCoalition ESS < 30%HIGH2022-09-06

In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User int...

CVEs:CVE-2022-26468

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-36857

Open SourceCoalition ESS < 30%LOW2022-09-09

Improper Authorization vulnerability in Photo Editor prior to SMR Sep-2022 Release 1 allows physical attackers to read internal application data.

CVEs:CVE-2022-36857

Affected products

ProductStatusVendorPackageEcosystem
android affected google
photo_editor affected samsung
Upstream advisory

ASB-A-228101796

GoogleCoalition ESS < 30%2022-09-01

ASB-A-228101796

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2022-26456

Open SourceCoalition ESS < 30%MEDIUM2022-09-06

In vow, there is a possible information disclosure due to a symbolic link following. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06545473; Issue...

CVEs:CVE-2022-26456

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-223210037

GoogleCoalition ESS < 30%2022-09-01

ASB-A-223210037

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

ASB-A-235102897

GoogleCoalition ESS < 30%2022-09-01

ASB-A-235102897

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2022-20395

Open SourceCoalition ESS < 30%HIGH2022-09-07

In checkAccess of MediaProvider.java, there is a possible file deletion due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Prod...

CVEs:CVE-2022-20395

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20231

Open SourceCoalition ESS < 30%HIGH2022-09-07

In smc_intc_request_fiq of arm_gic.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Pr...

CVEs:CVE-2022-20231

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20364

Open SourceCoalition ESS < 30%HIGH2022-09-07

In sysmmu_unmap of TBD, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: And...

CVEs:CVE-2022-20364

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26458

Open SourceCoalition ESS < 30%HIGH2022-09-06

In vow, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07032678; Issue ID: ...

CVEs:CVE-2022-26458

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-36850

Open SourceCoalition ESS < 30%CRITICAL2022-09-09

Path traversal vulnerability in CallBGProvider prior to SMR Sep-2022 Release 1 allows attacker to overwrite arbitrary file with phone uid.

CVEs:CVE-2022-36850

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20392

Open SourceCoalition ESS < 30%HIGH2022-09-07

In declareDuplicatePermission of ParsedPermissionUtils.java, there is a possible way to obtain a dangerous permission without user consent due to improper input validation. This could lead to local escalation of privilege during app installation or upg...

CVEs:CVE-2022-20392

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26448

Open SourceCoalition ESS < 30%HIGH2022-09-06

In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07063849; Issue I...

CVEs:CVE-2022-26448

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26449

Open SourceCoalition ESS < 30%HIGH2022-09-06

In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07177810; Issue I...

CVEs:CVE-2022-26449

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26453

Open SourceCoalition ESS < 30%HIGH2022-09-06

In teei, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06664675; Issue ID: ALPS066...

CVEs:CVE-2022-26453

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26454

Open SourceCoalition ESS < 30%HIGH2022-09-06

In teei, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06664701; Issue ID: ALPS...

CVEs:CVE-2022-26454

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26455

Open SourceCoalition ESS < 30%HIGH2022-09-06

In gz, there is a possible memory corruption due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07177858; Issue ID: A...

CVEs:CVE-2022-26455

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-36858

Open SourceCoalition ESS < 30%HIGH2022-09-09

A heap-based overflow vulnerability in GetCorrectDbLanguageTypeEsPKc() function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.

CVEs:CVE-2022-36858

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-36860

Open SourceCoalition ESS < 30%HIGH2022-09-09

A heap-based overflow vulnerability in LoadEnvironment function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.

CVEs:CVE-2022-36860

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-36862

Open SourceCoalition ESS < 30%HIGH2022-09-09

A heap-based overflow vulnerability in HWR::EngineCJK::Impl::Construct() in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.

CVEs:CVE-2022-36862

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-36863

Open SourceCoalition ESS < 30%HIGH2022-09-09

A heap-based overflow vulnerability in GetCorrectDbLanguageTypeEsPKc function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.

CVEs:CVE-2022-36863

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-36843

Open SourceCoalition ESS < 30%HIGH2022-09-09

A heap-based overflow vulnerability in MHW_RECOG_LIB_INFO function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.

CVEs:CVE-2022-36843

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-36844

Open SourceCoalition ESS < 30%HIGH2022-09-09

A heap-based overflow vulnerability in HWR::EngJudgeModel::Construct() in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.

CVEs:CVE-2022-36844

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-36845

Open SourceCoalition ESS < 30%HIGH2022-09-09

A heap-based overflow vulnerability in MHW_RECOG_LIB_INFO function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.

CVEs:CVE-2022-36845

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-36846

Open SourceCoalition ESS < 30%HIGH2022-09-09

A heap-based overflow vulnerability in ConstructDictionary function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.

CVEs:CVE-2022-36846

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-36852

Open SourceCoalition ESS < 30%LOW2022-09-09

Improper Authorization vulnerability in Video Editor prior to SMR Sep-2022 Release 1 allows local attacker to access internal application data.

CVEs:CVE-2022-36852

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-36855

Open SourceCoalition ESS < 30%CRITICAL2022-09-09

A use after free vulnerability in iva_ctl driver prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.

CVEs:CVE-2022-36855

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-36841

Open SourceCoalition ESS < 30%HIGH2022-09-09

A heap-based overflow vulnerability in PrepareRecogLibrary_Part function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.

CVEs:CVE-2022-36841

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-36842

Open SourceCoalition ESS < 30%HIGH2022-09-09

A heap-based overflow vulnerability in prepareRecogLibrary function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.

CVEs:CVE-2022-36842

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0871

Open SourceCoalition ESS < 30%HIGH2022-09-07

In PVRSRVBridgePMRPDumpSymbolicAddr of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow out-of-bounds heap access. This could lead to local escalation of privilege with no additional execution ...

CVEs:CVE-2021-0871

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0943

Open SourceCoalition ESS < 30%HIGH2022-09-07

In MMU_MapPages of TBD, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: ...

CVEs:CVE-2021-0943

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26460

Open SourceCoalition ESS < 30%HIGH2022-09-06

In vow, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07032590; Issue I...

CVEs:CVE-2022-26460

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26461

Open SourceCoalition ESS < 30%MEDIUM2022-09-06

In vow, there is a possible undefined behavior due to an API misuse. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07032604; Issue ID: ALPS07032604.

CVEs:CVE-2022-26461

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26465

Open SourceCoalition ESS < 30%HIGH2022-09-06

In audio ipi, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06558799; I...

CVEs:CVE-2022-26465

Affected products

ProductStatusVendorPackageEcosystem
android affected google
yocto affected yoctoproject
Upstream advisory

CVE-2022-26466

Open SourceCoalition ESS < 30%HIGH2022-09-06

In audio ipi, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06558777; Issue I...

CVEs:CVE-2022-26466

Affected products

ProductStatusVendorPackageEcosystem
android affected google
yocto affected yoctoproject
Upstream advisory

CVE-2022-26467

Open SourceCoalition ESS < 30%HIGH2022-09-06

In rpmb, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07167738; Issue ...

CVEs:CVE-2022-26467

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26470

Open SourceCoalition ESS < 30%HIGH2022-09-06

In aie, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07116037; Issue I...

CVEs:CVE-2022-26470

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26457

Open SourceCoalition ESS < 30%HIGH2022-09-06

In vow, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07138490; Issue ID: ...

CVEs:CVE-2022-26457

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26464

Open SourceCoalition ESS < 30%HIGH2022-09-06

In vow, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07032699; Issue I...

CVEs:CVE-2022-26464

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-238916921

GoogleCoalition ESS < 30%HIGH2022-09-01

ASB-A-238916921

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-238921253

GoogleCoalition ESS < 30%HIGH2022-09-01

ASB-A-238921253

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20393

Open SourceCoalition ESS < 30%HIGH2022-09-07

In extract3GPPGlobalDescriptions of TextDescriptions.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure from the media server with no additional execution privileges needed. User inte...

CVEs:CVE-2022-20393

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26459

Open SourceCoalition ESS < 30%HIGH2022-09-06

In vow, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07032634; Issue ID: ALPS0...

CVEs:CVE-2022-26459

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26462

Open SourceCoalition ESS < 30%MEDIUM2022-09-06

In vow, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07032660; Issue ID:...

CVEs:CVE-2022-26462

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26463

Open SourceCoalition ESS < 30%MEDIUM2022-09-06

In vow, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07032686; Issue ID:...

CVEs:CVE-2022-26463

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39119

Open SourceCoalition ESS < 30%HIGH2022-09-09

In network service, there is a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

CVEs:CVE-2022-39119

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-36854

Open SourceCoalition ESS < 30%MEDIUM2022-09-09

Out of bound read in libapexjni.media.samsung.so prior to SMR Sep-2022 Release 1 allows attacker access unauthorized information.

CVEs:CVE-2022-36854

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20398

Open SourceCoalition ESS < 30%HIGH2022-09-07

In addOrUpdateNetwork of WifiServiceImpl.java, there is a possible way for a guest user to configure Wi-Fi due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not need...

CVEs:CVE-2022-20398

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20399

Open SourceCoalition ESS < 30%MEDIUM2022-09-07

In the SEPolicy configuration of system apps, there is a possible access to the 'ip' utility due to an insecure default value. This could lead to local information disclosure of network data with no additional execution privileges needed. User interact...

CVEs:CVE-2022-20399

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-219808546

GoogleCoalition ESS < 30%MEDIUM2022-09-01

ASB-A-219808546

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-36847

Open SourceCoalition ESS < 30%CRITICAL2022-09-09

Use after free vulnerability in mtp_send_signal function of MTP driver prior to SMR Sep-2022 Release 1 allows attackers to perform malicious actions.

CVEs:CVE-2022-36847

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-36849

Open SourceCoalition ESS < 30%CRITICAL2022-09-09

Use after free vulnerability in sdp_mm_set_process_sensitive function of sdpmm driver prior to SMR Sep-2022 Release 1 allows attackers to perform malicious actions.

CVEs:CVE-2022-36849

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-36861

Open SourceCoalition ESS < 30%MEDIUM2022-09-09

Custom permission misuse vulnerability in SystemUI prior to SMR Sep-2022 Release 1 allows attacker to use some protected functions with SystemUI privilege.

CVEs:CVE-2022-36861

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-36856

Open SourceCoalition ESS < 30%MEDIUM2022-09-09

Improper access control vulnerability in Telecom application prior to SMR Sep-2022 Release 1 allows attacker to start emergency calls via undefined permission.

CVEs:CVE-2022-36856

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26451

Open SourceCoalition ESS < 30%HIGH2022-09-06

In ged, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07202966; Issue ID: ALPS07202966.

CVEs:CVE-2022-26451

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20396

Open SourceCoalition ESS < 30%MEDIUM2022-09-07

In SettingsActivity.java, there is a possible way to make a device discoverable over Bluetooth, without permission or user interaction, due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privilege...

CVEs:CVE-2022-20396

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-36848

Open SourceCoalition ESS < 30%MEDIUM2022-09-09

Improper Authorization vulnerability in setDualDARPolicyCmd prior to SMR Sep-2022 Release 1 allows local attackers to cause local permanent denial of service.

CVEs:CVE-2022-36848

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26450

Open SourceCoalition ESS < 30%HIGH2022-09-06

In apusys, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07177801; Issue ID: ALPS0717...

CVEs:CVE-2022-26450

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0697

Open SourceCoalition ESS < 30%HIGH2022-09-07

In PVRSRVRGXSubmitTransferKM of rgxtransfer.c, there is a possible user after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation...

CVEs:CVE-2021-0697

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-238918403

GoogleCoalition ESS < 30%NONE2022-09-01

ASB-A-238918403

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

OSV-2022-1001

Open SourceAll remainingHIGH2022-09-30

Heap-buffer-overflow in SkRect::setBoundsCheck

Affected products

ProductStatusVendorPackageEcosystem
skia affected OSS-Fuzz skia
Upstream advisory

OSV-2022-996

Open SourceAll remainingHIGH2022-09-29

Use-of-uninitialized-value in GrTriangulator::sanitizeContours

Affected products

ProductStatusVendorPackageEcosystem
skia affected OSS-Fuzz skia
Upstream advisory

OSV-2022-989

Open SourceAll remainingHIGH2022-09-29

Use-of-uninitialized-value in SkPathStroker::CheckCubicLinear

Affected products

ProductStatusVendorPackageEcosystem
skia affected OSS-Fuzz skia
Upstream advisory

OSV-2022-986

Open SourceAll remainingHIGH2022-09-29

Heap-buffer-overflow in SkEdgeClipper::ClipPath

Affected products

ProductStatusVendorPackageEcosystem
skia affected OSS-Fuzz skia
Upstream advisory

OSV-2022-983

Open SourceAll remainingHIGH2022-09-29

Heap-buffer-overflow in SkPathPriv::IsRectContour

Affected products

ProductStatusVendorPackageEcosystem
skia affected OSS-Fuzz skia
Upstream advisory

OSV-2022-981

Open SourceAll remainingHIGH2022-09-29

Heap-buffer-overflow in SkPath::Iter::next

Affected products

ProductStatusVendorPackageEcosystem
skia affected OSS-Fuzz skia
Upstream advisory

OSV-2022-978

Open SourceAll remainingHIGH2022-09-29

Heap-buffer-overflow in SkPath::Iter::next

Affected products

ProductStatusVendorPackageEcosystem
skia affected OSS-Fuzz skia
Upstream advisory

OSV-2022-976

Open SourceAll remainingHIGH2022-09-29

Heap-buffer-overflow in SkPath::Iter::next

Affected products

ProductStatusVendorPackageEcosystem
skia affected OSS-Fuzz skia
Upstream advisory

OSV-2022-972

Open SourceAll remainingHIGH2022-09-28

Use-of-uninitialized-value in SkFindQuadMaxCurvature

Affected products

ProductStatusVendorPackageEcosystem
skia affected OSS-Fuzz skia
Upstream advisory

OSV-2022-970

Open SourceAll remainingHIGH2022-09-28

Heap-buffer-overflow in SkPath::reverseAddPath

Affected products

ProductStatusVendorPackageEcosystem
skia affected OSS-Fuzz skia
Upstream advisory

OSV-2022-969

Open SourceAll remainingHIGH2022-09-28

Heap-buffer-overflow in SkPath::Iter::next

Affected products

ProductStatusVendorPackageEcosystem
skia affected OSS-Fuzz skia
Upstream advisory

OSV-2022-968

Open SourceAll remainingHIGH2022-09-28

Heap-buffer-overflow in SkMatrix::Persp_pts

Affected products

ProductStatusVendorPackageEcosystem
skia affected OSS-Fuzz skia
Upstream advisory

GO-2022-0965

Open SourceAll remaining2022-09-02

Unbounded recursion in JSON parsing in k8s.io/apimachinery

Affected products

ProductStatusVendorPackageEcosystem
apimachinery affected k8s.io k8s.io/apimachinery
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.