Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

467 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.1)0.21%—Google Tensorflow14/5/202117/6/2026
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow in `tf.raw_ops.RaggedTensorToTensor`. This is because the…
ModificadaAlta (7.1)0.20%—Google Tensorflow14/5/202117/6/2026
TensorFlow is an end-to-end open source platform for machine learning. An attacker can access data outside of bounds of heap allocated array in `tf.raw_ops.UnicodeEncode`. This is because the…
ModificadaAlta (7.8)0.21%—Google Tensorflow14/5/202117/6/2026
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow in `tf.raw_ops.SparseSplit`. This is because the…
ModificadaMedia (5.5)0.19%—Google Tensorflow14/5/202117/6/2026
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service via a FPE runtime error in `tf.raw_ops.SparseMatMul`. The division by 0 occurs deep in Eigen code because the `b` tensor is empty. The fix will be included in TensorFlow 2.5.0. We will also cherrypick this…
ModificadaMedia (5.5)0.19%—Google Tensorflow14/5/202117/6/2026
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service via a FPE runtime error in `tf.raw_ops.Reverse`. This is because the…
ModificadaMedia (5.5)0.19%—Google Tensorflow14/5/202117/6/2026
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service via a FPE runtime error in `tf.raw_ops.FusedBatchNorm`. This is because the…
ModificadaAlta (7.1)0.20%—Google Tensorflow14/5/202117/6/2026
TensorFlow is an end-to-end open source platform for machine learning. An attacker can read data outside of bounds of heap allocated buffer in `tf.raw_ops.QuantizeAndDequantizeV3`. This is because the…
ModificadaMedia (5.5)0.19%—Google Tensorflow14/5/202117/6/2026
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service by controlling the values of `num_segments` tensor argument for `UnsortedSegmentJoin`. This is because the…
ModificadaMedia (5.5)0.22%—Google Tensorflow14/5/202117/6/2026
TensorFlow is an end-to-end open source platform for machine learning. The implementation of `MatrixTriangularSolve`(https://github.com/tensorflow/tensorflow/blob/8cae746d8449c7dda5298327353d68613f16e798/tensorflow/core/kernels/linalg/matrix_triangular_solve_op_impl.h#L160-L240) fails to terminate kernel execution if…
ModificadaMedia (5.5)0.19%—Google Tensorflow14/5/202117/6/2026
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a runtime division by zero error and denial of service in `tf.raw_ops.FractionalAvgPool`. This is because the…
ModificadaMedia (5.5)0.19%—Google Tensorflow14/5/202117/6/2026
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a runtime division by zero error and denial of service in `tf.raw_ops.QuantizedBatchNormWithGlobalNormalization`. This is because the…
ModificadaMedia (5.5)0.19%—Google Tensorflow14/5/202117/6/2026
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a runtime division by zero error and denial of service in `tf.raw_ops.QuantizedBatchNormWithGlobalNormalization`. This is because the…
ModificadaMedia (5.5)0.19%—Google Tensorflow14/5/202117/6/2026
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a segfault and denial of service via accessing data outside of bounds in `tf.raw_ops.QuantizedBatchNormWithGlobalNormalization`. This is because the…
ModificadaAlta (7.8)0.20%—Google Tensorflow14/5/202117/6/2026
TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger an integer division by zero undefined behavior in `tf.raw_ops.QuantizedBiasAdd`. This is because the implementation of the Eigen…
ModificadaMedia (5.5)0.19%—Google Tensorflow14/5/202117/6/2026
TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a denial of service via a `CHECK`-fail in converting sparse tensors to CSR Sparse matrices. This is because the…
ModificadaMedia (5.5)0.31%—Google Tensorflow14/5/202117/6/2026
TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a denial of service via a `CHECK`-fail in `tf.raw_ops.QuantizeAndDequantizeV4Grad`. This is because the implementation does not validate the rank of the `input_*` tensors. In turn, this results in the tensors being passes as…
ModificadaMedia (5.5)0.19%—Google Tensorflow14/5/202117/6/2026
TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a denial of service via a `CHECK`-fail in `tf.raw_ops.CTCGreedyDecoder`. This is because the…
ModificadaMedia (5.5)0.20%—Google Tensorflow14/5/202117/6/2026
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow by passing crafted inputs to `tf.raw_ops.StringNGrams`. This is because the…
ModificadaMedia (5.5)0.19%—Google Tensorflow14/5/202117/6/2026
TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a dereference of a null pointer in `tf.raw_ops.StringNGrams`. This is because the…
ModificadaAlta (7.8)0.21%—Google Tensorflow14/5/202117/6/2026
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow to occur in `Conv2DBackpropFilter`. This is because the…
ModificadaMedia (5.5)0.19%—Google Tensorflow14/5/202117/6/2026
TensorFlow is an end-to-end open source platform for machine learning. Calling `tf.raw_ops.ImmutableConst`(https://www.tensorflow.org/api_docs/python/tf/raw_ops/ImmutableConst) with a `dtype` of `tf.resource` or `tf.variant` results in a segfault in the implementation as code assumes that the tensor contents are pure…
ModificadaMedia (5.5)0.19%—Google Tensorflow14/5/202117/6/2026
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a division by zero to occur in `Conv2DBackpropFilter`. This is because the…
ModificadaAlta (7.8)0.21%—Google Tensorflow14/5/202117/6/2026
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow in `QuantizedResizeBilinear` by passing in invalid thresholds for the quantization. This is because the…
ModificadaAlta (7.8)0.21%—Google Tensorflow14/5/202117/6/2026
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow in `QuantizedReshape` by passing in invalid thresholds for the quantization. This is because the…
ModificadaAlta (7.8)0.21%—Google Tensorflow14/5/202117/6/2026
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow in `QuantizedMul` by passing in invalid thresholds for the quantization. This is because the…
Orbitaley — Vulnerabilidades