CVE-2022-41082
CVEs:CVE-2022-41082
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 23 are already weaponised in the wild.
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
CVEs:CVE-2022-41082
Microsoft Exchange Server Remote Code Execution Vulnerability
CVEs:CVE-2022-41082
Microsoft Exchange Server Remote Code Execution Vulnerability
CVEs:CVE-2022-41082
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| exchange_server | affected | microsoft | — | — |
CVEs:CVE-2022-41040
Microsoft Exchange Server Elevation of Privilege Vulnerability
CVEs:CVE-2022-41040
Microsoft Exchange Server Elevation of Privilege Vulnerability
CVEs:CVE-2022-41040
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| exchange_server | affected | microsoft | — | — |
CVEs:CVE-2022-3236
A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older.
CVEs:CVE-2022-3236
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| firewall | affected | sophos | — | — |
A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older.
CVEs:CVE-2022-3236
DEBIAN-CVE-2022-3038
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP3 | chromium | — |
| chromium | affected | openSUSE:Leap 15.3 | chromium | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP4 | chromium | — |
| chromium | affected | openSUSE:Leap 15.4 | chromium | — |
Updated chromium-browser-stable packages fix security vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium-browser-stable | affected | Mageia:8 | chromium-browser-stable | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
DEBIAN-CVE-2022-3075
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
CVEs:CVE-2022-3075
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-3075
Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
CVEs:CVE-2022-3075
The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a repo...
CVEs:CVE-2022-32917
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ipados | affected | apple | — | — |
| iphone_os | affected | apple | — | — |
| macos | affected | apple | — | — |
CVEs:CVE-2022-32917
The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..
CVEs:CVE-2022-32917
DEBIAN-CVE-2022-2856
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2022-40083
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-labstack-echo | affected | Debian:13 | golang-github-labstack-echo | — |
| golang-github-labstack-echo | affected | Debian:12 | golang-github-labstack-echo | — |
| golang-github-labstack-echo | affected | Debian:14 | golang-github-labstack-echo | — |
Important security update for SUSE Manager Client Tools
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ansible | affected | openSUSE:Leap 15.3 | ansible | — |
| ansible | affected | openSUSE:Leap 15.4 | ansible | — |
| ansible | affected | SUSE:Manager Proxy Module 4.3 | ansible | — |
| ansible | affected | SUSE:Manager Client Tools 15 | ansible | — |
| ansible | affected | SUSE:Manager Proxy Module 4.2 | ansible | — |
| dracut-saltboot | affected | SUSE:Manager Client Tools 15 | dracut-saltboot | — |
| dracut-saltboot | affected | openSUSE:Leap 15.4 | dracut-saltboot | — |
| dracut-saltboot | affected | openSUSE:Leap 15.3 | dracut-saltboot | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Linux Enterprise Server 15-LTSS | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Linux Enterprise High Performance Computing 15-LTSS | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Linux Enterprise High Performance Computing 15-ESPOS | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Linux Enterprise Server for SAP Applications 15 | golang-github-prometheus-node_exporter | — |
| golang-github-QubitProducts-exporter_exporter | affected | SUSE:Manager Proxy Module 4.2 | golang-github-QubitProducts-exporter_exporter | — |
| golang-github-QubitProducts-exporter_exporter | affected | SUSE:Manager Proxy Module 4.3 | golang-github-QubitProducts-exporter_exporter | — |
| golang-github-QubitProducts-exporter_exporter | affected | SUSE:Manager Server Module 4.2 | golang-github-QubitProducts-exporter_exporter | — |
| golang-github-QubitProducts-exporter_exporter | affected | SUSE:Manager Server Module 4.3 | golang-github-QubitProducts-exporter_exporter | — |
| golang-github-QubitProducts-exporter_exporter | affected | openSUSE:Leap 15.4 | golang-github-QubitProducts-exporter_exporter | — |
| golang-github-QubitProducts-exporter_exporter | affected | openSUSE:Leap 15.3 | golang-github-QubitProducts-exporter_exporter | — |
| golang-github-QubitProducts-exporter_exporter | affected | SUSE:Manager Client Tools 15 | golang-github-QubitProducts-exporter_exporter | — |
| mgr-daemon | affected | SUSE:Manager Client Tools 15 | mgr-daemon | — |
| mgr-virtualization | affected | SUSE:Manager Client Tools 15 | mgr-virtualization | — |
| prometheus-blackbox_exporter | affected | SUSE:Manager Proxy Module 4.2 | prometheus-blackbox_exporter | — |
| prometheus-blackbox_exporter | affected | SUSE:Manager Client Tools 15 | prometheus-blackbox_exporter | — |
| prometheus-blackbox_exporter | affected | openSUSE:Leap 15.4 | prometheus-blackbox_exporter | — |
| prometheus-blackbox_exporter | affected | SUSE:Manager Proxy Module 4.3 | prometheus-blackbox_exporter | — |
| python-hwdata | affected | SUSE:Manager Proxy Module 4.1 | python-hwdata | — |
| python-hwdata | affected | SUSE:Manager Client Tools 15 | python-hwdata | — |
| python-hwdata | affected | SUSE:Manager Proxy Module 4.2 | python-hwdata | — |
| python-hwdata | affected | SUSE:Manager Proxy Module 4.3 | python-hwdata | — |
| python-hwdata | affected | SUSE:Manager Server Module 4.1 | python-hwdata | — |
| python-hwdata | affected | SUSE:Manager Server Module 4.2 | python-hwdata | — |
| python-hwdata | affected | SUSE:Manager Server Module 4.3 | python-hwdata | — |
| python-hwdata | affected | openSUSE:Leap 15.3 | python-hwdata | — |
| python-hwdata | affected | openSUSE:Leap 15.4 | python-hwdata | — |
| spacecmd | affected | openSUSE:Leap 15.3 | spacecmd | — |
| spacecmd | affected | openSUSE:Leap 15.4 | spacecmd | — |
| spacecmd | affected | SUSE:Manager Client Tools 15 | spacecmd | — |
| spacewalk-client-tools | affected | SUSE:Manager Client Tools 15 | spacewalk-client-tools | — |
| uyuni-common-libs | affected | SUSE:Manager Client Tools 15 | uyuni-common-libs | — |
| uyuni-proxy-systemd-services | affected | SUSE:Manager Client Tools 15 | uyuni-proxy-systemd-services | — |
| wire | affected | openSUSE:Leap 15.4 | wire | — |
| zypp-plugin-spacewalk | affected | SUSE:Manager Client Tools 15 | zypp-plugin-spacewalk | — |
| zypp-plugin-spacewalk | affected | SUSE:Manager Proxy Module 4.1 | zypp-plugin-spacewalk | — |
| zypp-plugin-spacewalk | affected | SUSE:Manager Proxy Module 4.2 | zypp-plugin-spacewalk | — |
| zypp-plugin-spacewalk | affected | SUSE:Manager Proxy Module 4.3 | zypp-plugin-spacewalk | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
Updated google-gson packages fix security vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google-gson | affected | Mageia:8 | google-gson | — |
libgoogle-gson-java - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| libgoogle-gson-java | affected | Debian:10 | libgoogle-gson-java | — |
libgoogle-gson-java - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| libgoogle-gson-java | affected | Debian:11 | libgoogle-gson-java | — |
golang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | openEuler:20.03-LTS-SP1 | golang | — |
| golang | affected | openEuler:20.03-LTS-SP3 | golang | — |
| golang | affected | openEuler:22.03-LTS | golang | — |
Denial of service in net/http and golang.org/x/net/http2
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| dynamic-localpv-provisioner | affected | chainguard | dynamic-localpv-provisioner | — |
| dynamic-localpv-provisioner | affected | wolfi | dynamic-localpv-provisioner | — |
| dynamic-localpv-provisioner-fips | affected | chainguard | dynamic-localpv-provisioner-fips | — |
| grpcurl | affected | wolfi | grpcurl | — |
| grpcurl | affected | chainguard | grpcurl | — |
| hey | affected | chainguard | hey | — |
| hey | affected | wolfi | hey | — |
| k3d | affected | wolfi | k3d | — |
| k3d | affected | chainguard | k3d | — |
| kubeflow | affected | chainguard | kubeflow | — |
| kubeflow | affected | wolfi | kubeflow | — |
| kubeflow-fips | affected | chainguard | kubeflow-fips | — |
| kubeflow-katib | affected | wolfi | kubeflow-katib | — |
| kubeflow-katib | affected | chainguard | kubeflow-katib | — |
| kube-state-metrics-2.6 | affected | chainguard | kube-state-metrics-2.6 | — |
| prometheus-postgres-exporter-0.10 | affected | chainguard | prometheus-postgres-exporter-0.10 | — |
| stdlib | affected | Go | stdlib | — |
| terraform-provider-sendgrid | affected | wolfi | terraform-provider-sendgrid | — |
| terraform-provider-sendgrid | affected | chainguard | terraform-provider-sendgrid | — |
| terraform-provider-sendgrid-fips | affected | chainguard | terraform-provider-sendgrid-fips | — |
| wireguard-go | affected | chainguard | wireguard-go | — |
| wireguard-go | affected | wolfi | wireguard-go | — |
| x/net | affected | golang.org | golang.org/x/net | — |
golang.org/x/net/http2 Denial of Service vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| x/net | affected | golang.org | golang.org/x/net | — |
| x/net/http2 | affected | golang.org | golang.org/x/net/http2 | — |
golang.org/x/net/http2 Denial of Service vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| dynamic-localpv-provisioner | affected | chainguard | dynamic-localpv-provisioner | — |
| dynamic-localpv-provisioner | affected | wolfi | dynamic-localpv-provisioner | — |
| dynamic-localpv-provisioner-fips | affected | chainguard | dynamic-localpv-provisioner-fips | — |
| grpcurl | affected | wolfi | grpcurl | — |
| grpcurl | affected | chainguard | grpcurl | — |
| hey | affected | wolfi | hey | — |
| hey | affected | chainguard | hey | — |
| k3d | affected | wolfi | k3d | — |
| k3d | affected | chainguard | k3d | — |
| kubeflow | affected | wolfi | kubeflow | — |
| kubeflow | affected | chainguard | kubeflow | — |
| kubeflow-fips | affected | chainguard | kubeflow-fips | — |
| kubeflow-katib | affected | wolfi | kubeflow-katib | — |
| kubeflow-katib | affected | chainguard | kubeflow-katib | — |
| kube-state-metrics-2.6 | affected | chainguard | kube-state-metrics-2.6 | — |
| prometheus-postgres-exporter-0.10 | affected | chainguard | prometheus-postgres-exporter-0.10 | — |
| terraform-provider-sendgrid | affected | wolfi | terraform-provider-sendgrid | — |
| terraform-provider-sendgrid | affected | chainguard | terraform-provider-sendgrid | — |
| terraform-provider-sendgrid-fips | affected | chainguard | terraform-provider-sendgrid-fips | — |
| wireguard-go | affected | wolfi | wireguard-go | — |
| wireguard-go | affected | chainguard | wireguard-go | — |
| x/net | affected | golang.org | golang.org/x/net | — |
| x/net | affected | golang.org | — | — |
| x/net/http2 | affected | golang.org | golang.org/x/net/http2 | — |
CVE-2022-27664 affecting package golang for versions less than 1.18.8-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2022-27664 affecting package golang for versions less than 1.21.6-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2022-27664 affecting package golang for versions less than 1.18.8-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:3 | golang | — |
CVE-2022-27664 affecting package golang 1.25.7-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:3 | golang | — |
DEBIAN-CVE-2022-27664
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-1.15 | affected | Debian:11 | golang-1.15 | — |
| golang-1.19 | affected | Debian:12 | golang-1.19 | — |
| golang-golang-x-net | affected | Debian:11 | golang-golang-x-net | — |
| golang-golang-x-net | affected | Debian:12 | golang-golang-x-net | — |
| golang-golang-x-net | affected | Debian:13 | golang-golang-x-net | — |
| golang-golang-x-net | affected | Debian:14 | golang-golang-x-net | — |
golang.org/x/net/http2 Denial of Service vulnerability
CVEs:CVE-2022-27664
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| x/net | affected | golang.org | golang.org/x/net | — |
| x/net/http2 | affected | golang.org | golang.org/x/net/http2 | — |
In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error.
CVEs:CVE-2022-27664
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| fedora | affected | fedoraproject | — | — |
| go | affected | golang | — | — |
Fix CVE(s): CVE-2021-28861
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| idle-python3.5 | affected | TuxCare:Ubuntu:16.04 | idle-python3.5 | — |
| libpython3.5 | affected | TuxCare:Ubuntu:16.04 | libpython3.5 | — |
| libpython3.5-dev | affected | TuxCare:Ubuntu:16.04 | libpython3.5-dev | — |
| libpython3.5-minimal | affected | TuxCare:Ubuntu:16.04 | libpython3.5-minimal | — |
| libpython3.5-stdlib | affected | TuxCare:Ubuntu:16.04 | libpython3.5-stdlib | — |
| libpython3.5-testsuite | affected | TuxCare:Ubuntu:16.04 | libpython3.5-testsuite | — |
| python3.5 | affected | TuxCare:Ubuntu:16.04 | python3.5 | — |
| python3.5-dev | affected | TuxCare:Ubuntu:16.04 | python3.5-dev | — |
| python3.5-doc | affected | TuxCare:Ubuntu:16.04 | python3.5-doc | — |
| python3.5-examples | affected | TuxCare:Ubuntu:16.04 | python3.5-examples | — |
| python3.5-minimal | affected | TuxCare:Ubuntu:16.04 | python3.5-minimal | — |
| python3.5-venv | affected | TuxCare:Ubuntu:16.04 | python3.5-venv | — |
A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This could lead to the client performing unexpected actions as well as forwarding the client's API server credentials to t...
CVEs:CVE-2022-3172
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| apiserver | affected | kubernetes | — | — |
DEBIAN-CVE-2022-3199
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | openSUSE:Leap 15.4 | chromium | — |
| chromium | affected | SUSE:Package Hub 15 SP3 | chromium | — |
| chromium | affected | SUSE:Package Hub 15 SP4 | chromium | — |
| chromium | affected | openSUSE:Leap 15.3 | chromium | — |
Use after free in Frames in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2022-3199
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-3199
protobuf-cpp and protobuf-python have potential Denial of Service issue
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf | affected | PyPI | protobuf | — |
protobuf-cpp and protobuf-python have potential Denial of Service issue
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf | affected | PyPI | protobuf | — |
| protobuf | affected | PyPI | protobuf | — |
CVE-2022-1941 affecting package protobuf for versions less than 3.17.3-3
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf | affected | Azure Linux:2 | protobuf | — |
CVE-2022-1941 affecting package protobuf for versions less than 25.3-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf | affected | Azure Linux:3 | protobuf | — |
CVE-2022-1941 affecting package tensorflow for versions less than 2.16.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:3 | tensorflow | — |
DEBIAN-CVE-2022-1941
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf | affected | Debian:11 | protobuf | — |
| protobuf | affected | Debian:12 | protobuf | — |
| protobuf | affected | Debian:13 | protobuf | — |
| protobuf | affected | Debian:14 | protobuf | — |
A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 3.21.5 for protobuf-cpp, and versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 4....
CVEs:CVE-2022-1941
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
| protobuf-cpp | affected | — | — | |
| protobuf-python | affected | — | — |
protobuf-cpp and protobuf-python have potential Denial of Service issue
CVEs:CVE-2022-1941
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf | affected | PyPI | protobuf | — |
protobuf-cpp and protobuf-python have potential Denial of Service issue
CVEs:CVE-2022-1941
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf | affected | PyPI | protobuf | — |
Panic on malformed packets in golang.org/x/crypto/ssh
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| dex-k8s-authenticator | affected | chainguard | dex-k8s-authenticator | — |
| dynamic-localpv-provisioner | affected | chainguard | dynamic-localpv-provisioner | — |
| dynamic-localpv-provisioner | affected | wolfi | dynamic-localpv-provisioner | — |
| dynamic-localpv-provisioner-fips | affected | chainguard | dynamic-localpv-provisioner-fips | — |
| k3d | affected | chainguard | k3d | — |
| k3d | affected | wolfi | k3d | — |
| kubeflow | affected | wolfi | kubeflow | — |
| kubeflow | affected | chainguard | kubeflow | — |
| kubeflow-fips | affected | chainguard | kubeflow-fips | — |
| prometheus-postgres-exporter-0.10 | affected | chainguard | prometheus-postgres-exporter-0.10 | — |
| terraform-provider-sendgrid | affected | chainguard | terraform-provider-sendgrid | — |
| terraform-provider-sendgrid | affected | wolfi | terraform-provider-sendgrid | — |
| terraform-provider-sendgrid-fips | affected | chainguard | terraform-provider-sendgrid-fips | — |
| x/crypto | affected | golang.org | golang.org/x/crypto | — |
x/crypto/ssh vulnerable to panic via malformed packets
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| dex-k8s-authenticator | affected | chainguard | dex-k8s-authenticator | — |
| dynamic-localpv-provisioner | affected | wolfi | dynamic-localpv-provisioner | — |
| dynamic-localpv-provisioner | affected | chainguard | dynamic-localpv-provisioner | — |
| dynamic-localpv-provisioner-fips | affected | chainguard | dynamic-localpv-provisioner-fips | — |
| k3d | affected | chainguard | k3d | — |
| k3d | affected | wolfi | k3d | — |
| kubeflow | affected | wolfi | kubeflow | — |
| kubeflow | affected | chainguard | kubeflow | — |
| kubeflow-fips | affected | chainguard | kubeflow-fips | — |
| prometheus-postgres-exporter-0.10 | affected | chainguard | prometheus-postgres-exporter-0.10 | — |
| terraform-provider-sendgrid | affected | chainguard | terraform-provider-sendgrid | — |
| terraform-provider-sendgrid | affected | wolfi | terraform-provider-sendgrid | — |
| terraform-provider-sendgrid-fips | affected | chainguard | terraform-provider-sendgrid-fips | — |
| x/crypto | affected | golang.org | golang.org/x/crypto | — |
x/crypto/ssh vulnerable to panic via malformed packets
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| x/crypto | affected | golang.org | golang.org/x/crypto | — |
DEBIAN-CVE-2021-43565
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-go.crypto | affected | Debian:11 | golang-go.crypto | — |
| golang-go.crypto | affected | Debian:12 | golang-go.crypto | — |
| golang-go.crypto | affected | Debian:13 | golang-go.crypto | — |
| golang-go.crypto | affected | Debian:14 | golang-go.crypto | — |
ASB-A-231494876
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 106.0.5249.62 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2022-3317
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-3317
PUB-A-228694483
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
ASB-A-216408350
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
Windows workloads can run as ContainerAdministrator even when those workloads set the runAsNonRoot option to true.
CVEs:CVE-2021-25749
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | kubernetes | — | — |
CVEs:CVE-2021-25749
CVEs:CVE-2022-20566
In l2cap_chan_put of l2cap_core, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Andro...
CVEs:CVE-2022-20566
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
DEBIAN-CVE-2019-5797
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Use after free in Browser Creation in Google Chrome prior to 104.0.5112.101 allowed a remote attacker who had convinced a user to engage in a specific UI interaction to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-2998
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-2998
DEBIAN-CVE-2022-2998
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Use after free in Passwords in Google Chrome prior to 105.0.5195.125 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2022-3842
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-3842
DEBIAN-CVE-2022-2852
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2022-32190
DEBIAN-CVE-2022-32190
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-1.19 | affected | Debian:12 | golang-1.19 | — |
JoinPath and URL.JoinPath do not remove ../ path elements appended to a relative path. For example, JoinPath("https://go.dev", "../go") returns the URL "https://go.dev/../go", despite the JoinPath documentation stating that ../ path elements are remove...
CVEs:CVE-2022-32190
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| go | affected | golang | — | — |
Failure to strip relative path components in net/url
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubeflow-katib | affected | chainguard | kubeflow-katib | — |
| kubeflow-katib | affected | wolfi | kubeflow-katib | — |
| stdlib | affected | Go | stdlib | — |
DEBIAN-CVE-2022-2853
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
com.google.cloud.tools:jib-core vulnerable to Remote Code Execution (RCE)
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.google.cloud.tools:jib-core | affected | Maven | com.google.cloud.tools:jib-core | — |
com.google.cloud.tools:jib-core vulnerable to Remote Code Execution (RCE)
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.google.cloud.tools:jib-core | affected | Maven | com.google.cloud.tools:jib-core | — |
com.google.cloud.tools:jib-core vulnerable to Remote Code Execution (RCE)
CVEs:CVE-2022-25914
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.google.cloud.tools:jib-core | affected | Maven | com.google.cloud.tools:jib-core | — |
The package com.google.cloud.tools:jib-core before 0.22.0 are vulnerable to Remote Code Execution (RCE) via the isDockerInstalled function, due to attempting to execute input.
CVEs:CVE-2022-25914
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| jib | affected | jib_project | — | — |
DEBIAN-CVE-2022-3195
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Out of bounds write in Storage in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2022-3195
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-3195
DEBIAN-CVE-2022-3045
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2022-3056
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2022-2238
A vulnerability was found in the search-api container in Red Hat Advanced Cluster Management for Kubernetes when a query in the search filter gets parsed by the backend. This flaw allows an attacker to craft specific strings containing special characte...
CVEs:CVE-2022-2238
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| advanced_cluster_management_for_kubernetes | affected | redhat | — | — |
DEBIAN-CVE-2022-3196
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
CVEs:CVE-2022-3196
Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)
CVEs:CVE-2022-3196
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
DEBIAN-CVE-2022-3197
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)
CVEs:CVE-2022-3197
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-3197
DEBIAN-CVE-2022-3044
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2022-2860
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2022-3041
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2022-3040
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2022-38012
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVEs:CVE-2022-38012
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
DEBIAN-CVE-2022-2858
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2022-2855
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
matrix-android-sdk2 vulnerable to Olm/Megolm protocol confusion
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.matrix.android:matrix-android-sdk2 | affected | Maven | org.matrix.android:matrix-android-sdk2 | — |
matrix-android-sdk2 vulnerable to Olm/Megolm protocol confusion
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.matrix.android:matrix-android-sdk2 | affected | Maven | org.matrix.android:matrix-android-sdk2 | — |
matrix-android-sdk2 vulnerable to Olm/Megolm protocol confusion
CVEs:CVE-2022-39248
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.matrix.android:matrix-android-sdk2 | affected | Maven | org.matrix.android:matrix-android-sdk2 | — |
matrix-android-sdk2 is the Matrix SDK for Android. Prior to version 1.5.1, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shiel...
CVEs:CVE-2022-39248
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| software_development_kit | affected | matrix | — | — |
DEBIAN-CVE-2022-2859
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2022-3046
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2022-3039
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2022-3052
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
TensorFlow segfault TFLite converter on per-channel quantized transposed convolutions
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow segfault TFLite converter on per-channel quantized transposed convolutions
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow segfault TFLite converter on per-channel quantized transposed convolutions
CVEs:CVE-2022-36027
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. When converting transposed convolutions using per-channel weight quantization the converter segfaults and crashes the Python process. We have patched the issue in GitHub commit aa0b852a4588cea...
CVEs:CVE-2022-36027
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow segfault TFLite converter on per-channel quantized transposed convolutions
CVEs:CVE-2022-36027
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
DEBIAN-CVE-2022-3050
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Insufficient data validation in File System API in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass File System restrictions via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2022-3443
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-3443
CVEs:CVE-2022-3444
Insufficient data validation in File System API in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass File System restrictions via a crafted HTML page and malicious file. (Chromium security severity: Low)
CVEs:CVE-2022-3444
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Insufficient policy enforcement in developer tools in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2022-3308
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-3308
CVEs:CVE-2022-26447
In BT firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06784478; Iss...
CVEs:CVE-2022-26447
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| yocto | affected | yoctoproject | — | — |
ASB-A-237956326
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
DEBIAN-CVE-2022-3200
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Heap buffer overflow in Internals in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2022-3200
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-3200
CVEs:CVE-2022-3304
Use after free in CSS in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2022-3304
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
TensorFlow vulnerable to `CHECK` failure in `AvgPoolOp`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` failure in `AvgPoolOp`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` failure in `AvgPoolOp`
CVEs:CVE-2022-35941
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` failure in `AvgPoolOp`
CVEs:CVE-2022-35941
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. The `AvgPoolOp` function takes an argument `ksize` that must be positive but is not checked. A negative `ksize` can trigger a `CHECK` failure and crash the program. We have patched the issue i...
CVEs:CVE-2022-35941
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to null-dereference in `mlir::tfg::TFOp::nameAttr`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to null-dereference in `mlir::tfg::TFOp::nameAttr`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to null-dereference in `mlir::tfg::TFOp::nameAttr`
CVEs:CVE-2022-36014
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. When `mlir::tfg::TFOp::nameAttr` receives null type list attributes, it crashes. We have patched the issue in GitHub commits 3a754740d5414e362512ee981eefba41561a63a6 and a0f0b9a21c927093045709...
CVEs:CVE-2022-36014
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to null-dereference in `mlir::tfg::TFOp::nameAttr`
CVEs:CVE-2022-36014
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` failures in `UnbatchGradOp`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` failures in `UnbatchGradOp`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` failures in `UnbatchGradOp`
CVEs:CVE-2022-35952
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. The `UnbatchGradOp` function takes an argument `id` that is assumed to be a scalar. A nonscalar `id` can trigger a `CHECK` failure and crash the program. It also requires its argument `batch_i...
CVEs:CVE-2022-35952
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to `CHECK` failures in `UnbatchGradOp`
CVEs:CVE-2022-35952
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
matrix-android-sdk2 vulnerable to impersonation via forwarded Megolm sessions
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.matrix.android:matrix-android-sdk2 | affected | Maven | org.matrix.android:matrix-android-sdk2 | — |
matrix-android-sdk2 vulnerable to impersonation via forwarded Megolm sessions
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.matrix.android:matrix-android-sdk2 | affected | Maven | org.matrix.android:matrix-android-sdk2 | — |
matrix-android-sdk2 is the Matrix SDK for Android. Prior to version 1.5.1, an attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some pl...
CVEs:CVE-2022-39246
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| software_development_kit | affected | matrix | — | — |
matrix-android-sdk2 vulnerable to impersonation via forwarded Megolm sessions
CVEs:CVE-2022-39246
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.matrix.android:matrix-android-sdk2 | affected | Maven | org.matrix.android:matrix-android-sdk2 | — |
TensorFlow vulnerable to Int overflow in `RaggedRangeOp`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to Int overflow in `RaggedRangeOp`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` failure in `TensorListReserve` via missing validation
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` failure in `TensorListReserve` via missing validation
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to null-dereference in `mlir::tfg::GraphDefImporter::ConvertNodeDef`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to null-dereference in `mlir::tfg::GraphDefImporter::ConvertNodeDef`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK`-fail in `tensorflow::full_type::SubstituteFromAttrs`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK`-fail in `tensorflow::full_type::SubstituteFromAttrs`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to integer overflow in math ops
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to integer overflow in math ops
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to assertion fail on MLIR empty edge names
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to assertion fail on MLIR empty edge names
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to Int overflow in `RaggedRangeOp`
CVEs:CVE-2022-35940
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to Int overflow in `RaggedRangeOp`
CVEs:CVE-2022-35940
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. The `RaggedRangOp` function takes an argument `limits` that is eventually used to construct a `TensorShape` as an `int64`. If `limits` is a very large float, it can overflow when converted to ...
CVEs:CVE-2022-35940
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow is an open source platform for machine learning. In `core/kernels/list_kernels.cc's TensorListReserve`, `num_elements` is assumed to be a tensor of size 1. When a `num_elements` of more than 1 element is provided, then `tf.raw_ops.TensorList...
CVEs:CVE-2022-35960
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to `CHECK` failure in `TensorListReserve` via missing validation
CVEs:CVE-2022-35960
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` failure in `TensorListReserve` via missing validation
CVEs:CVE-2022-35960
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. When `mlir::tfg::ConvertGenericFunctionToFunctionDef` is given empty function attributes, it crashes. We have patched the issue in GitHub commit ad069af92392efee1418c48ff561fd3070a03d7b. The f...
CVEs:CVE-2022-36012
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to assertion fail on MLIR empty edge names
CVEs:CVE-2022-36012
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to assertion fail on MLIR empty edge names
CVEs:CVE-2022-36012
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to null-dereference in `mlir::tfg::GraphDefImporter::ConvertNodeDef`
CVEs:CVE-2022-36013
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to null-dereference in `mlir::tfg::GraphDefImporter::ConvertNodeDef`
CVEs:CVE-2022-36013
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. When `mlir::tfg::GraphDefImporter::ConvertNodeDef` tries to convert NodeDefs without an op name, it crashes. We have patched the issue in GitHub commit a0f0b9a21c9270930457095092f558fbad4c03e5...
CVEs:CVE-2022-36013
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to integer overflow in math ops
CVEs:CVE-2022-36015
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. When `RangeSize` receives values that do not fit into an `int64_t`, it crashes. We have patched the issue in GitHub commit 37e64539cd29fcfb814c4451152a60f5d107b0f0. The fix will be included in...
CVEs:CVE-2022-36015
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to integer overflow in math ops
CVEs:CVE-2022-36015
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK`-fail in `tensorflow::full_type::SubstituteFromAttrs`
CVEs:CVE-2022-36016
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK`-fail in `tensorflow::full_type::SubstituteFromAttrs`
CVEs:CVE-2022-36016
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. When `tensorflow::full_type::SubstituteFromAttrs` receives a `FullTypeDef& t` that is not exactly three args, it triggers a `CHECK`-fail instead of returning a status. We have patched the issu...
CVEs:CVE-2022-36016
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
DEBIAN-CVE-2022-3043
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2022-3055
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2022-3051
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2022-2854
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2022-3307
Use after free in media in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2022-3307
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2022-2857
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Incorrect security UI in full screen in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2022-3313
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-3313
DEBIAN-CVE-2022-3058
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Use after free in survey in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2022-3306
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-3306
DEBIAN-CVE-2022-3201
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2022-3054
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2022-3201
Insufficient validation of untrusted input in DevTools in Google Chrome on Chrome OS prior to 105.0.5195.125 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted HTML page. (Chromium ...
CVEs:CVE-2022-3201
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
DEBIAN-CVE-2022-3198
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)
CVEs:CVE-2022-3198
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-3198
CVEs:CVE-2022-3311
Use after free in import in Google Chrome prior to 106.0.5249.62 allowed a remote attacker who had compromised a WebUI process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2022-3311
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Type confusion in Blink in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2022-3315
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-3315
Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 108.0.5359.71 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2022-4187
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-4187
Use after free in survey in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2022-3305
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-3305
DEBIAN-CVE-2022-2861
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2022-3309
Use after free in assistant in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via specific UI gestures. (Chromium security severi...
CVEs:CVE-2022-3309
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
TensorFlow is an open source platform for machine learning. The `GatherNd` function takes arguments that determine the sizes of inputs and outputs. If the inputs given are greater than or equal to the sizes of the outputs, an out-of-bounds memory read ...
CVEs:CVE-2022-35938
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to OOB write in `scatter_nd` in TF Lite
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to OOB write in `scatter_nd` in TF Lite
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to OOB read in `Gather_nd` in TF Lite
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to OOB read in `Gather_nd` in TF Lite
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to OOB read in `Gather_nd` in TF Lite
CVEs:CVE-2022-35937
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to OOB read in `Gather_nd` in TF Lite
CVEs:CVE-2022-35937
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. The `GatherNd` function takes arguments that determine the sizes of inputs and outputs. If the inputs given are greater than or equal to the sizes of the outputs, an out-of-bounds memory read ...
CVEs:CVE-2022-35937
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to OOB write in `scatter_nd` in TF Lite
CVEs:CVE-2022-35939
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. The `ScatterNd` function takes an input argument that determines the indices of of the output tensor. An input index greater than the output tensor or less than zero will either write content ...
CVEs:CVE-2022-35939
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to OOB write in `scatter_nd` in TF Lite
CVEs:CVE-2022-35939
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CVEs:CVE-2022-3316
Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass security feature via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2022-3316
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2022-3053
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Insufficient policy enforcement in custom tabs in Google Chrome on Android prior to 106.0.5249.62 allowed an attacker who convinced the user to install an application to bypass same origin policy via a crafted application. (Chromium security severity: ...
CVEs:CVE-2022-3310
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-3310
DEBIAN-CVE-2022-3049
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2022-3057
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
TensorFlow vulnerable to `CHECK` fail in `TensorListScatter` and `TensorListScatterV2`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `TensorListScatter` and `TensorListScatterV2`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` failure in `SobolSample` via missing validation
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` failure in `SobolSample` via missing validation
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` failure in `SobolSample` via missing validation
CVEs:CVE-2022-35935
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` failure in `SobolSample` via missing validation
CVEs:CVE-2022-35935
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. The implementation of SobolSampleOp is vulnerable to a denial of service via CHECK-failure (assertion failure) caused by assuming `input(0)`, `input(1)`, and `input(2)` to be scalar. This issu...
CVEs:CVE-2022-35935
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to `CHECK` fail in `TensorListScatter` and `TensorListScatterV2`
CVEs:CVE-2022-35991
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. When `TensorListScatter` and `TensorListScatterV2` receive an `element_shape` of a rank greater than one, they give a `CHECK` fail that can trigger a denial of service attack. We have patched ...
CVEs:CVE-2022-35991
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to `CHECK` fail in `TensorListScatter` and `TensorListScatterV2`
CVEs:CVE-2022-35991
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
DEBIAN-CVE-2022-3042
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
TensorFlow vulnerable to segfault in `RaggedBincount`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
TensorFlow vulnerable to segfault in `RaggedBincount`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
TensorFlow vulnerable to segfault in `SparseBincount`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to segfault in `SparseBincount`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to segfault in `QuantizedRelu` and `QuantizedRelu6`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to segfault in `QuantizedRelu` and `QuantizedRelu6`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to segfault in `QuantizeDownAndShrinkRange`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to segfault in `QuantizeDownAndShrinkRange`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to segfault in `QuantizedMatMul`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to segfault in `QuantizedMatMul`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to segfault in `QuantizedInstanceNorm`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to segfault in `QuantizedInstanceNorm`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to segfault in `RaggedBincount`
CVEs:CVE-2022-35986
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
TensorFlow vulnerable to segfault in `RaggedBincount`
CVEs:CVE-2022-35986
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
TensorFlow is an open source platform for machine learning. If `RaggedBincount` is given an empty input tensor `splits`, it results in a segfault that can be used to trigger a denial of service attack. We have patched the issue in GitHub commit 7a4591f...
CVEs:CVE-2022-35986
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to segfault in `Requantize`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to segfault in `Requantize`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to segfault in `QuantizedInstanceNorm`
CVEs:CVE-2022-35970
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to segfault in `QuantizedInstanceNorm`
CVEs:CVE-2022-35970
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. If `QuantizedInstanceNorm` is given `x_min` or `x_max` tensors of a nonzero rank, it results in a segfault that can be used to trigger a denial of service attack. We have patched the issue in ...
CVEs:CVE-2022-35970
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to segfault in `QuantizedMatMul`
CVEs:CVE-2022-35973
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to segfault in `QuantizedMatMul`
CVEs:CVE-2022-35973
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. If `QuantizedMatMul` is given nonscalar input for: `min_a`, `max_a`, `min_b`, or `max_b` It gives a segfault that can be used to trigger a denial of service attack. We have patched the issue i...
CVEs:CVE-2022-35973
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to segfault in `QuantizeDownAndShrinkRange`
CVEs:CVE-2022-35974
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. If `QuantizeDownAndShrinkRange` is given nonscalar inputs for `input_min` or `input_max`, it results in a segfault that can be used to trigger a denial of service attack. We have patched the i...
CVEs:CVE-2022-35974
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to segfault in `QuantizeDownAndShrinkRange`
CVEs:CVE-2022-35974
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. If `QuantizedRelu` or `QuantizedRelu6` are given nonscalar inputs for `min_features` or `max_features`, it results in a segfault that can be used to trigger a denial of service attack. We have...
CVEs:CVE-2022-35979
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to segfault in `QuantizedRelu` and `QuantizedRelu6`
CVEs:CVE-2022-35979
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to segfault in `QuantizedRelu` and `QuantizedRelu6`
CVEs:CVE-2022-35979
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. If `SparseBincount` is given inputs for `indices`, `values`, and `dense_shape` that do not make a valid sparse tensor, it results in a segfault that can be used to trigger a denial of service ...
CVEs:CVE-2022-35982
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to segfault in `SparseBincount`
CVEs:CVE-2022-35982
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to segfault in `SparseBincount`
CVEs:CVE-2022-35982
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to segfault in `Requantize`
CVEs:CVE-2022-36017
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. If `Requantize` is given `input_min`, `input_max`, `requested_output_min`, `requested_output_max` tensors of a nonzero rank, it results in a segfault that can be used to trigger a denial of se...
CVEs:CVE-2022-36017
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to segfault in `Requantize`
CVEs:CVE-2022-36017
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227328
CVEs:CVE-2022-20386
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20386
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227324
CVEs:CVE-2022-20387
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20387
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227323
CVEs:CVE-2022-20388
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20388
CVEs:CVE-2022-20389
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257004
CVEs:CVE-2022-20389
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257002
CVEs:CVE-2022-20390
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20390
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257000
CVEs:CVE-2022-20391
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20391
ASB-A-238227323
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-238227324
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-238227328
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-238257000
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-238257002
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-238257004
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
TensorFlow vulnerable to segfault in `QuantizedBiasAdd`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to segfault in `QuantizedBiasAdd`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to segfault in `QuantizedAdd`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to segfault in `QuantizedAdd`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to segfault in `QuantizedAvgPool`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to segfault in `QuantizedAvgPool`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to segfault in `BlockLSTMGradV2`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to segfault in `BlockLSTMGradV2`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to segfault in `BlockLSTMGradV2`
CVEs:CVE-2022-35964
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. The implementation of `BlockLSTMGradV2` does not fully validate its inputs. This results in a a segfault that can be used to trigger a denial of service attack. We have patched the issue in Gi...
CVEs:CVE-2022-35964
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to segfault in `BlockLSTMGradV2`
CVEs:CVE-2022-35964
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to segfault in `QuantizedAvgPool`
CVEs:CVE-2022-35966
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. If `QuantizedAvgPool` is given `min_input` or `max_input` tensors of a nonzero rank, it results in a segfault that can be used to trigger a denial of service attack. We have patched the issue ...
CVEs:CVE-2022-35966
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to segfault in `QuantizedAvgPool`
CVEs:CVE-2022-35966
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to segfault in `QuantizedAdd`
CVEs:CVE-2022-35967
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to segfault in `QuantizedAdd`
CVEs:CVE-2022-35967
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. If `QuantizedAdd` is given `min_input` or `max_input` tensors of a nonzero rank, it results in a segfault that can be used to trigger a denial of service attack. We have patched the issue in G...
CVEs:CVE-2022-35967
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to segfault in `QuantizedBiasAdd`
CVEs:CVE-2022-35972
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to segfault in `QuantizedBiasAdd`
CVEs:CVE-2022-35972
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. If `QuantizedBiasAdd` is given `min_input`, `max_input`, `min_bias`, `max_bias` tensors of a nonzero rank, it results in a segfault that can be used to trigger a denial of service attack. We h...
CVEs:CVE-2022-35972
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to `CHECK` fail in `tf.linalg.matrix_rank`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `tf.linalg.matrix_rank`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `EmptyTensorList`
CVEs:CVE-2022-35998
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
TensorFlow is an open source platform for machine learning. If `EmptyTensorList` receives an input `element_shape` with more than one dimension, it gives a `CHECK` fail that can be used to trigger a denial of service attack. We have patched the issue i...
CVEs:CVE-2022-35998
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to `CHECK` fail in `EmptyTensorList`
CVEs:CVE-2022-35998
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
TensorFlow vulnerable to `CHECK` fail in `EmptyTensorList`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
TensorFlow vulnerable to `CHECK` fail in `EmptyTensorList`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
TensorFlow vulnerable to `CHECK` fail in `tf.random.gamma`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `tf.random.gamma`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `tf.sparse.cross`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `tf.sparse.cross`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `tf.linalg.matrix_rank`
CVEs:CVE-2022-35988
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `tf.linalg.matrix_rank`
CVEs:CVE-2022-35988
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. When `tf.linalg.matrix_rank` receives an empty input `a`, the GPU kernel gives a `CHECK` fail that can be used to trigger a denial of service attack. We have patched the issue in GitHub commit...
CVEs:CVE-2022-35988
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow is an open source platform for machine learning. If `tf.sparse.cross` receives an input `separator` that is not a scalar, it gives a `CHECK` fail that can be used to trigger a denial of service attack. We have patched the issue in GitHub com...
CVEs:CVE-2022-35997
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to `CHECK` fail in `tf.sparse.cross`
CVEs:CVE-2022-35997
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `tf.sparse.cross`
CVEs:CVE-2022-35997
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. When `tf.random.gamma` receives large input shape and rates, it gives a `CHECK` fail that can trigger a denial of service attack. We have patched the issue in GitHub commit 552bfced6ce4809db5f...
CVEs:CVE-2022-36004
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to `CHECK` fail in `tf.random.gamma`
CVEs:CVE-2022-36004
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `tf.random.gamma`
CVEs:CVE-2022-36004
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Use after free in ChromeOS Notifications in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker who convinced a user to reboot Chrome OS to potentially exploit heap corruption via UI interaction. (Chromium security severity: Low)
CVEs:CVE-2022-3318
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-3318
TensorFlow vulnerable to `CHECK` fail in `Save` and `SaveSlices`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `Save` and `SaveSlices`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `ParameterizedTruncatedNormal`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `ParameterizedTruncatedNormal`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `LRNGrad`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `LRNGrad`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `MaxPool`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `MaxPool`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `FractionalMaxPoolGrad`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `FractionalMaxPoolGrad`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `AvgPoolGrad`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `AvgPoolGrad`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `TensorListFromTensor`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `TensorListFromTensor`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `SetSize`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `SetSize`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` failures in `FractionalAvgPoolGrad`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` failures in `FractionalAvgPoolGrad`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `CollectiveGather`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `CollectiveGather`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to floating point exception in `Conv2D`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to floating point exception in `Conv2D`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to null dereference on MLIR on empty function attributes
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to null dereference on MLIR on empty function attributes
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `DrawBoundingBoxes`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `DrawBoundingBoxes`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `Unbatch`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `Unbatch`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to null dereference on MLIR on empty function attributes
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to null dereference on MLIR on empty function attributes
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `RandomPoissonV2`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `RandomPoissonV2`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVarsGradient`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVarsGradient`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `AudioSummaryV2`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `AudioSummaryV2`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `DenseBincount`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `DenseBincount`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `QuantizeAndDequantizeV3`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `QuantizeAndDequantizeV3`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVarsPerChannel`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVarsPerChannel`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` failure in tf.reshape via overflows
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` failure in tf.reshape via overflows
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `Conv2DBackpropInput`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `Conv2DBackpropInput`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` failure in tf.reshape via overflows
CVEs:CVE-2022-35934
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. The implementation of tf.reshape op in TensorFlow is vulnerable to a denial of service via CHECK-failure (assertion failure) caused by overflowing the number of elements in a tensor. This issu...
CVEs:CVE-2022-35934
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to `CHECK` failure in tf.reshape via overflows
CVEs:CVE-2022-35934
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` failures in `FractionalAvgPoolGrad`
CVEs:CVE-2022-35963
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` failures in `FractionalAvgPoolGrad`
CVEs:CVE-2022-35963
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. The implementation of `FractionalAvgPoolGrad` does not fully validate the input `orig_input_tensor_shape`. This results in an overflow that results in a `CHECK` failure which can be used to tr...
CVEs:CVE-2022-35963
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow is an open source platform for machine learning. The implementation of `AvgPoolGrad` does not fully validate the input `orig_input_shape`. This results in a `CHECK` failure which can be used to trigger a denial of service attack. We have pat...
CVEs:CVE-2022-35968
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to `CHECK` fail in `AvgPoolGrad`
CVEs:CVE-2022-35968
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `AvgPoolGrad`
CVEs:CVE-2022-35968
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `FractionalMaxPoolGrad`
CVEs:CVE-2022-35981
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `FractionalMaxPoolGrad`
CVEs:CVE-2022-35981
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. `FractionalMaxPoolGrad` validates its inputs with `CHECK` failures instead of with returning errors. If it gets incorrectly sized inputs, the `CHECK` failure can be used to trigger a denial of...
CVEs:CVE-2022-35981
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow is an open source platform for machine learning. If `Save` or `SaveSlices` is run over tensors of an unsupported `dtype`, it results in a `CHECK` fail that can be used to trigger a denial of service attack. We have patched the issue in GitHu...
CVEs:CVE-2022-35983
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to `CHECK` fail in `Save` and `SaveSlices`
CVEs:CVE-2022-35983
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `Save` and `SaveSlices`
CVEs:CVE-2022-35983
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `ParameterizedTruncatedNormal`
CVEs:CVE-2022-35984
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. `ParameterizedTruncatedNormal` assumes `shape` is of type `int32`. A valid `shape` of type `int64` results in a mismatched type `CHECK` fail that can be used to trigger a denial of service att...
CVEs:CVE-2022-35984
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to `CHECK` fail in `ParameterizedTruncatedNormal`
CVEs:CVE-2022-35984
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `LRNGrad`
CVEs:CVE-2022-35985
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `LRNGrad`
CVEs:CVE-2022-35985
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. If `LRNGrad` is given an `output_image` input tensor that is not 4-D, it results in a `CHECK` fail that can be used to trigger a denial of service attack. We have patched the issue in GitHub c...
CVEs:CVE-2022-35985
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow is an open source platform for machine learning. `DenseBincount` assumes its input tensor `weights` to either have the same shape as its input tensor `input` or to be length-0. A different `weights` shape will trigger a `CHECK` fail that can...
CVEs:CVE-2022-35987
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to `CHECK` fail in `DenseBincount`
CVEs:CVE-2022-35987
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `DenseBincount`
CVEs:CVE-2022-35987
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `MaxPool`
CVEs:CVE-2022-35989
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `MaxPool`
CVEs:CVE-2022-35989
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. When `MaxPool` receives a window size input array `ksize` with dimensions greater than its input tensor `input`, the GPU kernel gives a `CHECK` fail that can be used to trigger a denial of ser...
CVEs:CVE-2022-35989
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to `CHECK` fail in `TensorListFromTensor`
CVEs:CVE-2022-35992
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `TensorListFromTensor`
CVEs:CVE-2022-35992
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. When `TensorListFromTensor` receives an `element_shape` of a rank greater than one, it gives a `CHECK` fail that can trigger a denial of service attack. We have patched the issue in GitHub com...
CVEs:CVE-2022-35992
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to `CHECK` fail in `SetSize`
CVEs:CVE-2022-35993
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `SetSize`
CVEs:CVE-2022-35993
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. When `SetSize` receives an input `set_shape` that is not a 1D tensor, it gives a `CHECK` fails that can be used to trigger a denial of service attack. We have patched the issue in GitHub commi...
CVEs:CVE-2022-35993
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to `CHECK` fail in `CollectiveGather`
CVEs:CVE-2022-35994
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. When `CollectiveGather` receives an scalar input `input`, it gives a `CHECK` fails that can be used to trigger a denial of service attack. We have patched the issue in GitHub commit c1f491817d...
CVEs:CVE-2022-35994
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to `CHECK` fail in `CollectiveGather`
CVEs:CVE-2022-35994
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `AudioSummaryV2`
CVEs:CVE-2022-35995
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. When `AudioSummaryV2` receives an input `sample_rate` with more than one element, it gives a `CHECK` fails that can be used to trigger a denial of service attack. We have patched the issue in ...
CVEs:CVE-2022-35995
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to `CHECK` fail in `AudioSummaryV2`
CVEs:CVE-2022-35995
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to floating point exception in `Conv2D`
CVEs:CVE-2022-35996
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to floating point exception in `Conv2D`
CVEs:CVE-2022-35996
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. If `Conv2D` is given empty `input` and the `filter` and `padding` sizes are valid, the output is all-zeros. This causes division-by-zero floating point exceptions that can be used to trigger a...
CVEs:CVE-2022-35996
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to `CHECK` fail in `Conv2DBackpropInput`
CVEs:CVE-2022-35999
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `Conv2DBackpropInput`
CVEs:CVE-2022-35999
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. When `Conv2DBackpropInput` receives empty `out_backprop` inputs (e.g. `[3, 1, 0, 1]`), the current CPU/GPU kernels `CHECK` fail (one with dnnl, the other with cudnn). This can be used to trigg...
CVEs:CVE-2022-35999
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to null dereference on MLIR on empty function attributes
CVEs:CVE-2022-36000
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. When `mlir::tfg::ConvertGenericFunctionToFunctionDef` is given empty function attributes, it gives a null dereference. We have patched the issue in GitHub commit aed36912609fc07229b4d0a7b44f3f...
CVEs:CVE-2022-36000
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to null dereference on MLIR on empty function attributes
CVEs:CVE-2022-36000
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. When `DrawBoundingBoxes` receives an input `boxes` that is not of dtype `float`, it gives a `CHECK` fail that can trigger a denial of service attack. We have patched the issue in GitHub commit...
CVEs:CVE-2022-36001
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to `CHECK` fail in `DrawBoundingBoxes`
CVEs:CVE-2022-36001
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `DrawBoundingBoxes`
CVEs:CVE-2022-36001
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `Unbatch`
CVEs:CVE-2022-36002
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. When `Unbatch` receives a nonscalar input `id`, it gives a `CHECK` fail that can trigger a denial of service attack. We have patched the issue in GitHub commit 4419d10d576adefa36b0e0a9425d2569...
CVEs:CVE-2022-36002
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to `CHECK` fail in `Unbatch`
CVEs:CVE-2022-36002
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `RandomPoissonV2`
CVEs:CVE-2022-36003
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. When `RandomPoissonV2` receives large input shape and rates, it gives a `CHECK` fail that can trigger a denial of service attack. We have patched the issue in GitHub commit 552bfced6ce4809db5f...
CVEs:CVE-2022-36003
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to `CHECK` fail in `RandomPoissonV2`
CVEs:CVE-2022-36003
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVarsGradient`
CVEs:CVE-2022-36005
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVarsGradient`
CVEs:CVE-2022-36005
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. When `tf.quantization.fake_quant_with_min_max_vars_gradient` receives input `min` or `max` that is nonscalar, it gives a `CHECK` fail that can trigger a denial of service attack. We have patch...
CVEs:CVE-2022-36005
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to null dereference on MLIR on empty function attributes
CVEs:CVE-2022-36011
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. When `mlir::tfg::ConvertGenericFunctionToFunctionDef` is given empty function attributes, it gives a null dereference. We have patched the issue in GitHub commit 1cf45b831eeb0cab8655c9c7c5d06e...
CVEs:CVE-2022-36011
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to null dereference on MLIR on empty function attributes
CVEs:CVE-2022-36011
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVarsPerChannel`
CVEs:CVE-2022-36019
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVarsPerChannel`
CVEs:CVE-2022-36019
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. If `FakeQuantWithMinMaxVarsPerChannel` is given `min` or `max` tensors of a rank other than one, it results in a `CHECK` fail that can be used to trigger a denial of service attack. We have pa...
CVEs:CVE-2022-36019
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to `CHECK` fail in `QuantizeAndDequantizeV3`
CVEs:CVE-2022-36026
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. If `QuantizeAndDequantizeV3` is given a nonscalar `num_bits` input tensor, it results in a `CHECK` fail that can be used to trigger a denial of service attack. We have patched the issue in Git...
CVEs:CVE-2022-36026
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to `CHECK` fail in `QuantizeAndDequantizeV3`
CVEs:CVE-2022-36026
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CVEs:CVE-2022-3314
Use after free in logging in Google Chrome prior to 106.0.5249.62 allowed a remote attacker who had compromised a WebUI process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2022-3314
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2022-3047
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVars`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVars`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `Conv2DBackpropInput`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `Conv2DBackpropInput`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVarsPerChannelGradient`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVarsPerChannelGradient`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to segfault in `LowerBound` and `UpperBound`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to segfault in `LowerBound` and `UpperBound`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` failures in `AvgPool3DGrad`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` failures in `AvgPool3DGrad`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `RaggedTensorToVariant`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `RaggedTensorToVariant`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. The implementation of `AvgPool3DGradOp` does not fully validate the input `orig_input_shape`. This results in an overflow that results in a `CHECK` failure which can be used to trigger a denia...
CVEs:CVE-2022-35959
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to `CHECK` failures in `AvgPool3DGrad`
CVEs:CVE-2022-35959
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` failures in `AvgPool3DGrad`
CVEs:CVE-2022-35959
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. If `LowerBound` or `UpperBound` is given an empty`sorted_inputs` input, it results in a `nullptr` dereference, leading to a segfault that can be used to trigger a denial of service attack. We ...
CVEs:CVE-2022-35965
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to segfault in `LowerBound` and `UpperBound`
CVEs:CVE-2022-35965
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to segfault in `LowerBound` and `UpperBound`
CVEs:CVE-2022-35965
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `Conv2DBackpropInput`
CVEs:CVE-2022-35969
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. The implementation of `Conv2DBackpropInput` requires `input_sizes` to be 4-dimensional. Otherwise, it gives a `CHECK` failure which can be used to trigger a denial of service attack. We have p...
CVEs:CVE-2022-35969
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to `CHECK` fail in `Conv2DBackpropInput`
CVEs:CVE-2022-35969
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. If `FakeQuantWithMinMaxVars` is given `min` or `max` tensors of a nonzero rank, it results in a `CHECK` fail that can be used to trigger a denial of service attack. We have patched the issue i...
CVEs:CVE-2022-35971
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVars`
CVEs:CVE-2022-35971
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVars`
CVEs:CVE-2022-35971
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVarsPerChannelGradient`
CVEs:CVE-2022-35990
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVarsPerChannelGradient`
CVEs:CVE-2022-35990
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. When `tf.quantization.fake_quant_with_min_max_vars_per_channel_gradient` receives input `min` or `max` of rank other than 1, it gives a `CHECK` fail that can trigger a denial of service attack...
CVEs:CVE-2022-35990
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to `CHECK` fail in `RaggedTensorToVariant`
CVEs:CVE-2022-36018
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to `CHECK` fail in `RaggedTensorToVariant`
CVEs:CVE-2022-36018
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. If `RaggedTensorToVariant` is given a `rt_nested_splits` list that contains tensors of ranks other than one, it results in a `CHECK` fail that can be used to trigger a denial of service attack...
CVEs:CVE-2022-36018
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
DEBIAN-CVE-2022-3071
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
a function called 'nla_parse', do not check the len of para, it will check nla_type (which can be controlled by userspace) with 'maxtype' (in this case, it is GSCAN_MAX), then it access polciy array 'policy[type]', which OOB access happens.Product: And...
CVEs:CVE-2022-20385
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20385
ASB-A-238379819
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CRI-O incorrect handling of supplementary groups may lead to sensitive information disclosure
CVEs:CVE-2022-2995
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| cri-o/cri-o | affected | github.com | github.com/cri-o/cri-o | — |
Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to ...
CVEs:CVE-2022-2995
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| cri-o | affected | kubernetes | — | — |
CVEs:CVE-2021-0942
The path in this case is a little bit convoluted. The end result is that via an ioctl an untrusted app can control the ui32PageIndex offset in the expression:sPA.uiAddr = page_to_phys(psOSPageArrayData->pagearray[ui32PageIndex]);With the current PoC th...
CVEs:CVE-2021-0942
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-238904312
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
DEBIAN-CVE-2022-3048
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2022-2990
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-containers-buildah | affected | Debian:11 | golang-github-containers-buildah | — |
| golang-github-containers-buildah | affected | Debian:12 | golang-github-containers-buildah | — |
| golang-github-containers-buildah | affected | Debian:13 | golang-github-containers-buildah | — |
| golang-github-containers-buildah | affected | Debian:14 | golang-github-containers-buildah | — |
Insufficient validation of untrusted input in VPN in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a local attacker to bypass managed device restrictions via physical access to the device. (Chromium security severity: Medium)
CVEs:CVE-2022-3312
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-3312
Intent redirection in Photo Editor prior to SMR Sep-2022 Release 1 allows attacker to get sensitive information.
CVEs:CVE-2022-36853
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-36853
CVEs:CVE-2022-26469
In MtkEmail, there is a possible escalation of privilege due to fragment injection. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07216598...
CVEs:CVE-2022-26469
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User int...
CVEs:CVE-2022-26468
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-26468
CVEs:CVE-2022-36857
Improper Authorization vulnerability in Photo Editor prior to SMR Sep-2022 Release 1 allows physical attackers to read internal application data.
CVEs:CVE-2022-36857
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| photo_editor | affected | samsung | — | — |
ASB-A-228101796
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
CVEs:CVE-2022-26456
In vow, there is a possible information disclosure due to a symbolic link following. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06545473; Issue...
CVEs:CVE-2022-26456
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-223210037
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
ASB-A-235102897
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
CVEs:CVE-2022-20395
In checkAccess of MediaProvider.java, there is a possible file deletion due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Prod...
CVEs:CVE-2022-20395
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20231
In smc_intc_request_fiq of arm_gic.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Pr...
CVEs:CVE-2022-20231
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20364
In sysmmu_unmap of TBD, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: And...
CVEs:CVE-2022-20364
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In vow, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07032678; Issue ID: ...
CVEs:CVE-2022-26458
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-26458
Path traversal vulnerability in CallBGProvider prior to SMR Sep-2022 Release 1 allows attacker to overwrite arbitrary file with phone uid.
CVEs:CVE-2022-36850
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-36850
CVEs:CVE-2022-20392
In declareDuplicatePermission of ParsedPermissionUtils.java, there is a possible way to obtain a dangerous permission without user consent due to improper input validation. This could lead to local escalation of privilege during app installation or upg...
CVEs:CVE-2022-20392
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07063849; Issue I...
CVEs:CVE-2022-26448
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-26448
In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07177810; Issue I...
CVEs:CVE-2022-26449
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-26449
CVEs:CVE-2022-26453
In teei, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06664675; Issue ID: ALPS066...
CVEs:CVE-2022-26453
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-26454
In teei, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06664701; Issue ID: ALPS...
CVEs:CVE-2022-26454
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-26455
In gz, there is a possible memory corruption due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07177858; Issue ID: A...
CVEs:CVE-2022-26455
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
A heap-based overflow vulnerability in GetCorrectDbLanguageTypeEsPKc() function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
CVEs:CVE-2022-36858
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-36858
CVEs:CVE-2022-36860
A heap-based overflow vulnerability in LoadEnvironment function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
CVEs:CVE-2022-36860
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-36862
A heap-based overflow vulnerability in HWR::EngineCJK::Impl::Construct() in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
CVEs:CVE-2022-36862
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-36863
A heap-based overflow vulnerability in GetCorrectDbLanguageTypeEsPKc function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
CVEs:CVE-2022-36863
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
A heap-based overflow vulnerability in MHW_RECOG_LIB_INFO function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
CVEs:CVE-2022-36843
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-36843
CVEs:CVE-2022-36844
A heap-based overflow vulnerability in HWR::EngJudgeModel::Construct() in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
CVEs:CVE-2022-36844
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
A heap-based overflow vulnerability in MHW_RECOG_LIB_INFO function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
CVEs:CVE-2022-36845
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-36845
CVEs:CVE-2022-36846
A heap-based overflow vulnerability in ConstructDictionary function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
CVEs:CVE-2022-36846
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-36852
Improper Authorization vulnerability in Video Editor prior to SMR Sep-2022 Release 1 allows local attacker to access internal application data.
CVEs:CVE-2022-36852
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-36855
A use after free vulnerability in iva_ctl driver prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
CVEs:CVE-2022-36855
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
A heap-based overflow vulnerability in PrepareRecogLibrary_Part function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
CVEs:CVE-2022-36841
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-36841
CVEs:CVE-2022-36842
A heap-based overflow vulnerability in prepareRecogLibrary function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
CVEs:CVE-2022-36842
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0871
In PVRSRVBridgePMRPDumpSymbolicAddr of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow out-of-bounds heap access. This could lead to local escalation of privilege with no additional execution ...
CVEs:CVE-2021-0871
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In MMU_MapPages of TBD, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: ...
CVEs:CVE-2021-0943
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0943
CVEs:CVE-2022-26460
In vow, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07032590; Issue I...
CVEs:CVE-2022-26460
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In vow, there is a possible undefined behavior due to an API misuse. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07032604; Issue ID: ALPS07032604.
CVEs:CVE-2022-26461
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-26461
CVEs:CVE-2022-26465
In audio ipi, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06558799; I...
CVEs:CVE-2022-26465
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| yocto | affected | yoctoproject | — | — |
In audio ipi, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06558777; Issue I...
CVEs:CVE-2022-26466
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| yocto | affected | yoctoproject | — | — |
CVEs:CVE-2022-26466
CVEs:CVE-2022-26467
In rpmb, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07167738; Issue ...
CVEs:CVE-2022-26467
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-26470
In aie, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07116037; Issue I...
CVEs:CVE-2022-26470
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-26457
In vow, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07138490; Issue ID: ...
CVEs:CVE-2022-26457
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In vow, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07032699; Issue I...
CVEs:CVE-2022-26464
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-26464
ASB-A-238916921
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-238921253
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In extract3GPPGlobalDescriptions of TextDescriptions.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure from the media server with no additional execution privileges needed. User inte...
CVEs:CVE-2022-20393
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20393
CVEs:CVE-2022-26459
In vow, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07032634; Issue ID: ALPS0...
CVEs:CVE-2022-26459
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-26462
In vow, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07032660; Issue ID:...
CVEs:CVE-2022-26462
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-26463
In vow, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07032686; Issue ID:...
CVEs:CVE-2022-26463
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In network service, there is a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVEs:CVE-2022-39119
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-39119
Out of bound read in libapexjni.media.samsung.so prior to SMR Sep-2022 Release 1 allows attacker access unauthorized information.
CVEs:CVE-2022-36854
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-36854
In addOrUpdateNetwork of WifiServiceImpl.java, there is a possible way for a guest user to configure Wi-Fi due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not need...
CVEs:CVE-2022-20398
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20398
In the SEPolicy configuration of system apps, there is a possible access to the 'ip' utility due to an insecure default value. This could lead to local information disclosure of network data with no additional execution privileges needed. User interact...
CVEs:CVE-2022-20399
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20399
ASB-A-219808546
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
Use after free vulnerability in mtp_send_signal function of MTP driver prior to SMR Sep-2022 Release 1 allows attackers to perform malicious actions.
CVEs:CVE-2022-36847
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-36847
CVEs:CVE-2022-36849
Use after free vulnerability in sdp_mm_set_process_sensitive function of sdpmm driver prior to SMR Sep-2022 Release 1 allows attackers to perform malicious actions.
CVEs:CVE-2022-36849
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-36861
Custom permission misuse vulnerability in SystemUI prior to SMR Sep-2022 Release 1 allows attacker to use some protected functions with SystemUI privilege.
CVEs:CVE-2022-36861
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Improper access control vulnerability in Telecom application prior to SMR Sep-2022 Release 1 allows attacker to start emergency calls via undefined permission.
CVEs:CVE-2022-36856
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-36856
In ged, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07202966; Issue ID: ALPS07202966.
CVEs:CVE-2022-26451
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-26451
CVEs:CVE-2022-20396
In SettingsActivity.java, there is a possible way to make a device discoverable over Bluetooth, without permission or user interaction, due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privilege...
CVEs:CVE-2022-20396
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Improper Authorization vulnerability in setDualDARPolicyCmd prior to SMR Sep-2022 Release 1 allows local attackers to cause local permanent denial of service.
CVEs:CVE-2022-36848
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-36848
In apusys, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07177801; Issue ID: ALPS0717...
CVEs:CVE-2022-26450
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-26450
CVEs:CVE-2021-0697
In PVRSRVRGXSubmitTransferKM of rgxtransfer.c, there is a possible user after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation...
CVEs:CVE-2021-0697
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-238918403
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
Heap-buffer-overflow in SkRect::setBoundsCheck
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| skia | affected | OSS-Fuzz | skia | — |
Use-of-uninitialized-value in GrTriangulator::sanitizeContours
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| skia | affected | OSS-Fuzz | skia | — |
Use-of-uninitialized-value in SkPathStroker::CheckCubicLinear
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| skia | affected | OSS-Fuzz | skia | — |
Heap-buffer-overflow in SkEdgeClipper::ClipPath
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| skia | affected | OSS-Fuzz | skia | — |
Heap-buffer-overflow in SkPathPriv::IsRectContour
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| skia | affected | OSS-Fuzz | skia | — |
Heap-buffer-overflow in SkPath::Iter::next
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| skia | affected | OSS-Fuzz | skia | — |
Heap-buffer-overflow in SkPath::Iter::next
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| skia | affected | OSS-Fuzz | skia | — |
Heap-buffer-overflow in SkPath::Iter::next
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| skia | affected | OSS-Fuzz | skia | — |
Use-of-uninitialized-value in SkFindQuadMaxCurvature
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| skia | affected | OSS-Fuzz | skia | — |
Heap-buffer-overflow in SkPath::reverseAddPath
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| skia | affected | OSS-Fuzz | skia | — |
Heap-buffer-overflow in SkPath::Iter::next
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| skia | affected | OSS-Fuzz | skia | — |
Heap-buffer-overflow in SkMatrix::Persp_pts
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| skia | affected | OSS-Fuzz | skia | — |
Unbounded recursion in JSON parsing in k8s.io/apimachinery
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| apimachinery | affected | k8s.io | k8s.io/apimachinery | — |
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.