Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
437 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.17% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of SVDF in TFLite is [vulnerable to a null pointer error](https://github.com/tensorflow/tensorflow/blob/460e000de3a83278fb00b61a16d161b1964f15f4/tensorflow/lite/kernels/svdf.cc#L300-L313). The… | |
| Modificada | Media (5.5) | 0.15% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of fully connected layers in TFLite is [vulnerable to a division by zero… | |
| Modificada | Alta (7.8) | 0.17% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause undefined behavior via binding a reference to null pointer in `tf.raw_ops.SparseFillEmptyRows`. The shape inference… | |
| Modificada | Media (5.5) | 0.16% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions most implementations of convolution operators in TensorFlow are affected by a division by 0 vulnerability where an attacker can trigger a denial of service via a crash. The shape inference… | |
| Modificada | Alta (7.8) | 0.17% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause undefined behavior via binding a reference to null pointer in `tf.raw_ops.Map*` and `tf.raw_ops.OrderedMap*` operations. The… | |
| Modificada | Alta (7.8) | 0.17% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause undefined behavior via binding a reference to null pointer in `tf.raw_ops.UnicodeEncode`. The… | |
| Modificada | Alta (7.8) | 0.17% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause undefined behavior via binding a reference to null pointer in `tf.raw_ops.RaggedTensorToVariant`. The… | |
| Modificada | Alta (7.8) | 0.17% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation for `tf.raw_ops.BoostedTreesCreateEnsemble` can result in a use after free error if an attacker supplies specially crafted arguments. The… | |
| Modificada | Alta (7.8) | 0.19% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions the code for `tf.raw_ops.SaveV2` does not properly validate the inputs and an attacker can trigger a null pointer dereference. The… | |
| Modificada | Alta (7.1) | 0.17% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can read from outside of bounds of heap allocated data by sending specially crafted illegal arguments to `BoostedTreesSparseCalculateBestFeatureSplit`. The… | |
| Modificada | Alta (7.8) | 0.19% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can generate undefined behavior via a reference binding to nullptr in `BoostedTreesCalculateBestGainsPerFeature` and similar attack can occur in `BoostedTreesCalculateBestFeatureSplitV2`. The… | |
| Modificada | Media (5.5) | 0.15% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause a denial of service in `boosted_trees_create_quantile_stream_resource` by using negative arguments. The… | |
| Modificada | Alta (7.8) | 0.18% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause undefined behavior via binding a reference to null pointer in all binary cwise operations that don't require broadcasting (e.g., gradients of binary cwise operations). The… | |
| Modificada | Alta (7.8) | 0.17% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause undefined behavior via binding a reference to null pointer in all operations of type `tf.raw_ops.MatrixSetDiagV*`. The… | |
| Modificada | Alta (7.8) | 0.17% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause undefined behavior via binding a reference to null pointer in all operations of type `tf.raw_ops.MatrixDiagV*`. The… | |
| Modificada | Alta (7.8) | 0.17% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause undefined behavior via binding a reference to null pointer in `tf.raw_ops.RaggedTensorToSparse`. The… | |
| Modificada | Alta (7.3) | 0.17% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can trigger a read from outside of bounds of heap allocated data by sending invalid arguments to `tf.raw_ops.ResourceScatterUpdate`. The… | |
| Modificada | Alta (7.1) | 0.17% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can trigger a crash via a `CHECK`-fail in debug builds of TensorFlow using `tf.raw_ops.ResourceGather` or a read from outside the bounds of heap allocated data in the same API in a release build. The… | |
| Modificada | Alta (7.8) | 0.17% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation for `tf.raw_ops.FractionalAvgPoolGrad` can be tricked into accessing data outside of bounds of heap allocated buffers. The… | |
| Modificada | Alta (7.8) | 0.18% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation for `tf.raw_ops.ExperimentalDatasetToTFRecord` and `tf.raw_ops.DatasetToTFRecord` can trigger heap buffer overflow and segmentation fault. The… | |
| Modificada | Media (5.5) | 0.15% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of `tf.raw_ops.StringNGrams` is vulnerable to an integer overflow issue caused by converting a signed integer value to an unsigned one and then allocating memory based on this value. The… | |
| Modificada | Media (5.5) | 0.15% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of `tf.raw_ops.QuantizeAndDequantizeV4Grad` is vulnerable to an integer overflow issue caused by converting a signed integer value to an unsigned one and then allocating memory based on this value. The… | |
| Modificada | Media (5.5) | 0.15% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions providing a negative element to `num_elements` list argument of `tf.raw_ops.TensorListReserve` causes the runtime to abort the process due to reallocating a `std::vector` to have a negative number of elements. The… | |
| Modificada | Alta (7.1) | 0.17% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions if the arguments to `tf.raw_ops.RaggedGather` don't determine a valid ragged tensor code can trigger a read from outside of bounds of heap allocated buffers. The… | |
| Modificada | Alta (7.1) | 0.17% | — | Google Tensorflow | 12/8/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of sparse reduction operations in TensorFlow can trigger accesses outside of bounds of heap allocated data. The… |