Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
467 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.25% | — | Google Tensorflow | 5/11/2021 | 17/6/2026 | TensorFlow is an open source platform for machine learning. In affeced versions during execution, `EinsumHelper::ParseEquation()` is supposed to set the flags in `input_has_ellipsis` vector and `*output_has_ellipsis` boolean to indicate whether there is ellipsis in the corresponding inputs and output. However, the… | |
| Modificada | Media (5.5) | 0.24% | — | Google Tensorflow | 5/11/2021 | 17/6/2026 | TensorFlow is an open source platform for machine learning. In affected versions if `tf.summary.create_file_writer` is called with non-scalar arguments code crashes due to a `CHECK`-fail. The fix will be included in TensorFlow 2.7.0. We will also cherrypick this commit on TensorFlow 2.6.1, TensorFlow 2.5.2, and… | |
| Modificada | Media (5.5) | 0.24% | — | Google Tensorflow | 5/11/2021 | 17/6/2026 | TensorFlow is an open source platform for machine learning. In affected versions if `tf.image.resize` is called with a large input argument then the TensorFlow process will crash due to a `CHECK`-failure caused by an overflow. The number of elements in the output tensor is too much for the `int64_t` type and the… | |
| Modificada | Media (5.5) | 0.24% | — | Google Tensorflow | 5/11/2021 | 17/6/2026 | TensorFlow is an open source platform for machine learning. In affected versions if `tf.tile` is called with a large input argument then the TensorFlow process will crash due to a `CHECK`-failure caused by an overflow. The number of elements in the output tensor is too much for the `int64_t` type and the overflow is… | |
| Modificada | Media (5.5) | 0.32% | — | Google Tensorflow | 5/11/2021 | 17/6/2026 | TensorFlow is an open source platform for machine learning. In affected versions TensorFlow allows tensor to have a large number of dimensions and each dimension can be as large as desired. However, the total number of elements in a tensor must fit within an `int64_t`. If an overflow occurs, `MultiplyWithoutOverflow`… | |
| Modificada | Media (5.5) | 0.24% | — | Google Tensorflow | 5/11/2021 | 17/6/2026 | TensorFlow is an open source platform for machine learning. In affected versions the Keras pooling layers can trigger a segfault if the size of the pool is 0 or if a dimension is negative. This is due to the TensorFlow's implementation of pooling operations where the values in the sliding window are not checked to be… | |
| Modificada | Media (5.5) | 0.21% | — | Google Tensorflow | 5/11/2021 | 17/6/2026 | TensorFlow is an open source platform for machine learning. In affected versions the implementation of `tf.math.segment_*` operations results in a `CHECK`-fail related abort (and denial of service) if a segment id in `segment_ids` is large. This is similar to CVE-2021-29584 (and similar other reported vulnerabilities… | |
| Modificada | Media (6.6) | 0.16% | — | Google Tensorflow | 13/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions when running shape functions, some functions (such as `MutableHashTableShape`) produce extra output information in the form of a `ShapeAndType` struct. The shapes embedded in this struct are owned by an inference context that… | |
| Modificada | Media (5.5) | 0.17% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions under certain conditions, Go code can trigger a segfault in string deallocation. For string tensors, `C.TF_TString_Dealloc` is called during garbage collection within a finalizer function. However, tensor structure isn't… | |
| Modificada | Media (5.5) | 0.15% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can craft a TFLite model that would trigger a division by zero error in LSH… | |
| Modificada | Media (5.5) | 0.19% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions TFLite's [`GatherNd` implementation](https://github.com/tensorflow/tensorflow/blob/149562d49faa709ea80df1d99fc41d005b81082a/tensorflow/lite/kernels/gather_nd.cc#L124) does not support negative indices but there are no checks… | |
| Modificada | Media (5.5) | 0.17% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions TFLite's [`expand_dims.cc`](https://github.com/tensorflow/tensorflow/blob/149562d49faa709ea80df1d99fc41d005b81082a/tensorflow/lite/kernels/expand_dims.cc#L36-L50) contains a vulnerability which allows reading one element… | |
| Modificada | Media (5.5) | 0.14% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementations of pooling in TFLite are vulnerable to division by 0 errors as there are no checks for divisors not being 0. We have patched the issue in GitHub commit… | |
| Modificada | Media (5.5) | 0.15% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of division in TFLite is [vulnerable to a division by 0 error](https://github.com/tensorflow/tensorflow/blob/460e000de3a83278fb00b61a16d161b1964f15f4/tensorflow/lite/kernels/div.cc). There is no check that… | |
| Modificada | Alta (7.1) | 0.18% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions all TFLite operations that use quantization can be made to use unitialized values. [For… | |
| Modificada | Alta (7.8) | 0.18% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions it is possible to nest a `tf.map_fn` within another `tf.map_fn` call. However, if the input tensor is a `RaggedTensor` and there is no function signature provided, code assumes the output is a fully specified tensor and fills… | |
| Modificada | Alta (8.8) | 0.45% | 💥 PoC | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions TensorFlow and Keras can be tricked to perform arbitrary code execution when deserializing a Keras model from YAML format. The… | |
| Modificada | Media (5.5) | 0.15% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions the shape inference code for `tf.raw_ops.Dequantize` has a vulnerability that could trigger a denial of service via a segfault if an attacker provides invalid arguments. The shape inference… | |
| Modificada | Media (5.5) | 0.18% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can trigger a denial of service via a segmentation fault in `tf.raw_ops.MaxPoolGrad` caused by missing validation. The… | |
| Modificada | Media (5.5) | 0.15% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can trigger a denial of service via a `CHECK`-fail in `tf.raw_ops.MapStage`. The… | |
| Modificada | Media (5.5) | 0.17% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can read from outside of bounds of heap allocated data by sending specially crafted illegal arguments to `tf.raw_ops.SdcaOptimizerV2`. The… | |
| Modificada | Media (5.5) | 0.17% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can read from outside of bounds of heap allocated data by sending specially crafted illegal arguments to `tf.raw_ops.UpperBound`. The… | |
| Modificada | Media (5.5) | 0.18% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause denial of service in applications serving models using `tf.raw_ops.NonMaxSuppressionV5` by triggering a division by 0. The… | |
| Modificada | Media (5.5) | 0.15% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause denial of service in applications serving models using `tf.raw_ops.UnravelIndex` by triggering a division by 0. The… | |
| Modificada | Alta (7.8) | 0.18% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions due to incomplete validation in MKL implementation of requantization, an attacker can trigger undefined behavior via binding a reference to a null pointer or can access data outside the bounds of heap allocated arrays. The… |