Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
437 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.19% | — | Google Tensorflow | 14/5/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. Due to lack of validation in `tf.raw_ops.CTCBeamSearchDecoder`, an attacker can trigger denial of service via segmentation faults. The… | |
| Modificada | Media (5.5) | 0.19% | — | Google Tensorflow | 14/5/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.FractionalMaxPoolGrad` triggers an undefined behavior if one of the input tensors is empty. The code is also vulnerable to a denial of service attack as a `CHECK` condition becomes false and aborts the process. The… | |
| Modificada | Alta (7.8) | 0.21% | — | Google Tensorflow | 14/5/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.MaxPoolGrad` is vulnerable to a heap buffer overflow. The implementation(https://github.com/tensorflow/tensorflow/blob/ab1e644b48c82cb71493f4362b4dd38f4577a1cf/tensorflow/core/kernels/maxpooling_op.cc#L194-L203)… | |
| Modificada | Alta (7.8) | 0.21% | — | Google Tensorflow | 14/5/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.FractionalAvgPoolGrad` is vulnerable to a heap buffer overflow. The… | |
| Modificada | Alta (7.8) | 0.21% | — | Google Tensorflow | 14/5/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.AvgPool3DGrad` is vulnerable to a heap buffer overflow. The implementation(https://github.com/tensorflow/tensorflow/blob/d80ffba9702dc19d1fac74fc4b766b3fa1ee976b/tensorflow/core/kernels/pooling_ops_3d.cc#L376-L450)… | |
| Modificada | Alta (7.8) | 0.21% | — | Google Tensorflow | 14/5/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.MaxPool3DGradGrad` is vulnerable to a heap buffer overflow. The… | |
| Modificada | Media (5.5) | 0.20% | — | Google Tensorflow | 14/5/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.ReverseSequence` allows for stack overflow and/or `CHECK`-fail based denial of service. The… | |
| Modificada | Alta (7.8) | 0.20% | — | Google Tensorflow | 14/5/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.MaxPool3DGradGrad` exhibits undefined behavior by dereferencing null pointers backing attacker-supplied empty tensors. The… | |
| Modificada | Media (5.5) | 0.19% | — | Google Tensorflow | 14/5/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.MaxPoolGradWithArgmax` is vulnerable to a division by 0. The… | |
| Modificada | Media (5.5) | 0.19% | — | Google Tensorflow | 14/5/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.SdcaOptimizer` triggers undefined behavior due to dereferencing a null pointer. The… | |
| Modificada | Alta (7.8) | 0.24% | — | Google Tensorflow | 14/5/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.MaxPoolGradWithArgmax` can cause reads outside of bounds of heap allocated data if attacker supplies specially crafted inputs. The… | |
| Modificada | Alta (7.1) | 0.15% | — | Google Tensorflow | 14/5/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.MaxPoolGradWithArgmax` can cause reads outside of bounds of heap allocated data if attacker supplies specially crafted inputs. The… | |
| Modificada | Alta (7.1) | 0.20% | — | Google Tensorflow | 14/5/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.MaxPoolGradWithArgmax` can cause reads outside of bounds of heap allocated data if attacker supplies specially crafted inputs. The… | |
| Modificada | Alta (7.8) | 0.20% | — | Google Tensorflow | 14/5/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger undefined behavior by binding to null pointer in `tf.raw_ops.ParameterizedTruncatedNormal`. This is because the… | |
| Modificada | Media (5.5) | 0.19% | — | Google Tensorflow | 14/5/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. Due to lack of validation in `tf.raw_ops.SparseDenseCwiseMul`, an attacker can trigger denial of service via `CHECK`-fails or accesses to outside the bounds of heap allocated data. Since the… | |
| Modificada | Alta (7.8) | 0.20% | — | Google Tensorflow | 14/5/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. An attacker can write outside the bounds of heap allocated arrays by passing invalid arguments to `tf.raw_ops.Dilation2DBackpropInput`. This is because the… | |
| Modificada | Media (5.5) | 0.19% | — | Google Tensorflow | 14/5/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a null pointer dereference in the implementation of `tf.raw_ops.SparseFillEmptyRows`. This is because of missing… | |
| Modificada | Media (5.5) | 0.19% | — | Google Tensorflow | 14/5/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a null pointer dereference in the implementation of `tf.raw_ops.EditDistance`. This is because the… | |
| Modificada | Media (5.5) | 0.19% | — | Google Tensorflow | 14/5/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service by exploiting a `CHECK`-failure coming from the implementation of `tf.raw_ops.RFFT`. Eigen code operating on an empty matrix can trigger on an assertion and will cause program termination. The fix will be… | |
| Modificada | Media (5.5) | 0.19% | — | Google Tensorflow | 14/5/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service by exploiting a `CHECK`-failure coming from the implementation of `tf.raw_ops.IRFFT`. The fix will be included in TensorFlow 2.5.0. We will also cherrypick this commit on TensorFlow 2.4.2, TensorFlow 2.3.3,… | |
| Modificada | Media (5.5) | 0.19% | — | Google Tensorflow | 14/5/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service by exploiting a `CHECK`-failure coming from `tf.raw_ops.LoadAndRemapMatrix`. This is because the… | |
| Modificada | Alta (7.1) | 0.21% | — | Google Tensorflow | 14/5/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow in `tf.raw_ops.RaggedTensorToTensor`. This is because the… | |
| Modificada | Alta (7.1) | 0.20% | — | Google Tensorflow | 14/5/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. An attacker can access data outside of bounds of heap allocated array in `tf.raw_ops.UnicodeEncode`. This is because the… | |
| Modificada | Alta (7.8) | 0.21% | — | Google Tensorflow | 14/5/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow in `tf.raw_ops.SparseSplit`. This is because the… | |
| Modificada | Media (5.5) | 0.19% | — | Google Tensorflow | 14/5/2021 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service via a FPE runtime error in `tf.raw_ops.SparseMatMul`. The division by 0 occurs deep in Eigen code because the `b` tensor is empty. The fix will be included in TensorFlow 2.5.0. We will also cherrypick this… |