Google Tensorflow: vulnerabilidades y CVE
Google Tensorflow tiene 433 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 18 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE433
Últimos 12 meses2
Críticas18
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-2492 | Alta (7.8) | 0.26% | — | 20 feb 2026 | TensorFlow HDF5 Library Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of TensorFlow. An attacker… |
| CVE-2025-12058 | Media (5.9) | 0.25% | — | 29 oct 2025 | The Keras.Model.load_model method, including when executed with the intended security mitigation safe_mode=True, is vulnerable to arbitrary local file loading and Server-Side Request Forgery (SSRF). This vulnerability… |
| CVE-2025-55559 | Alta (7.5) | 0.21% | — | 25 sept 2025 | An issue was discovered TensorFlow v2.18.0. A Denial of Service (DoS) occurs when padding is set to 'valid' in tf.keras.layers.Conv2D. |
| CVE-2025-55556 | Media (6.5) | 0.17% | — | 25 sept 2025 | TensorFlow v2.18.0 was discovered to output random results when compiling Embedding, leading to unexpected behavior in the application. |
| CVE-2023-33976 | Alta (7.5) | 0.43% | — | 30 jul 2024 | TensorFlow is an end-to-end open source platform for machine learning. `array_ops.upper_bound` causes a segfault when not given a rank 2 tensor. The fix will be included in TensorFlow 2.13 and will also cherrypick this… |
| CVE-2023-25661 | Media (6.5) | 0.44% | — | 27 mar 2023 | TensorFlow is an Open Source Machine Learning Framework. In versions prior to 2.11.1 a malicious invalid input crashes a tensorflow model (Check Failed) and can be used to trigger a denial of service attack. A proof of… |
| CVE-2023-27579 | Alta (7.5) | 0.39% | — | 25 mar 2023 | TensorFlow is an end-to-end open source platform for machine learning. Constructing a tflite model with a paramater `filter_input_channel` of less than 1 gives a FPE. This issue has been patched in version 2.12.… |
| CVE-2023-25801 | Alta (7.8) | 0.15% | — | 25 mar 2023 | TensorFlow is an open source machine learning platform. Prior to versions 2.12.0 and 2.11.1, `nn_ops.fractional_avg_pool_v2` and `nn_ops.fractional_max_pool_v2` require the first and fourth elements of their parameter… |
| CVE-2023-25676 | Alta (7.5) | 0.39% | — | 25 mar 2023 | TensorFlow is an open source machine learning platform. When running versions prior to 2.12.0 and 2.11.1 with XLA, `tf.raw_ops.ParallelConcat` segfaults with a nullptr dereference when given a parameter `shape` with… |
| CVE-2023-25675 | Alta (7.5) | 0.39% | — | 25 mar 2023 | TensorFlow is an open source machine learning platform. When running versions prior to 2.12.0 and 2.11.1 with XLA, `tf.raw_ops.Bincount` segfaults when given a parameter `weights` that is neither the same shape as… |
| CVE-2023-25674 | Alta (7.5) | 0.39% | — | 25 mar 2023 | TensorFlow is an open source machine learning platform. Versions prior to 2.12.0 and 2.11.1 have a null pointer error in RandomShuffle with XLA enabled. A fix is included in TensorFlow 2.12.0 and 2.11.1. |
| CVE-2023-25673 | Alta (7.5) | 0.39% | — | 25 mar 2023 | TensorFlow is an open source platform for machine learning. Versions prior to 2.12.0 and 2.11.1 have a Floating Point Exception in TensorListSplit with XLA. A fix is included in TensorFlow version 2.12.0 and version… |
| CVE-2023-25672 | Alta (7.5) | 0.36% | — | 25 mar 2023 | TensorFlow is an open source platform for machine learning. The function `tf.raw_ops.LookupTableImportV2` cannot handle scalars in the `values` parameter and gives an NPE. A fix is included in TensorFlow version 2.12.0… |
| CVE-2023-25671 | Alta (7.5) | 0.52% | — | 25 mar 2023 | TensorFlow is an open source platform for machine learning. There is out-of-bounds access due to mismatched integer type sizes. A fix is included in TensorFlow version 2.12.0 and version 2.11.1. |
| CVE-2023-25670 | Alta (7.5) | 0.39% | — | 25 mar 2023 | TensorFlow is an open source platform for machine learning. Versions prior to 2.12.0 and 2.11.1 have a null point error in QuantizedMatMulWithBiasAndDequantize with MKL enabled. A fix is included in TensorFlow version… |
| CVE-2023-25669 | Alta (7.5) | 0.39% | — | 25 mar 2023 | TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, if the stride and window size are not positive for `tf.raw_ops.AvgPoolGrad`, it can give a floating point exception. A fix… |
| CVE-2023-25668 | Crítica (9.8) | 0.84% | — | 25 mar 2023 | TensorFlow is an open source platform for machine learning. Attackers using Tensorflow prior to 2.12.0 or 2.11.1 can access heap memory which is not in the control of user, leading to a crash or remote code execution.… |
| CVE-2023-25667 | Alta (7.5) | 0.31% | — | 25 mar 2023 | TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, integer overflow occurs when `2^31 <= num_frames * height * width * channels < 2^32`, for example Full HD screencast of at… |
| CVE-2023-25666 | Alta (7.5) | 0.39% | — | 25 mar 2023 | TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, there is a floating point exception in AudioSpectrogram. A fix is included in TensorFlow version 2.12.0 and version 2.11.1. |
| CVE-2023-25665 | Alta (7.5) | 0.44% | — | 25 mar 2023 | TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, when `SparseSparseMaximum` is given invalid sparse tensors as inputs, it can give a null pointer error. A fix is included… |
| CVE-2023-25664 | Crítica (9.8) | 0.41% | — | 25 mar 2023 | TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, there is a heap buffer overflow in TAvgPoolGrad. A fix is included in TensorFlow 2.12.0 and 2.11.1. |
| CVE-2023-25663 | Alta (7.5) | 0.39% | — | 25 mar 2023 | TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, when `ctx->step_containter()` is a null ptr, the Lookup function will be executed with a null pointer. A fix is included… |
| CVE-2023-25662 | Alta (7.5) | 0.39% | — | 25 mar 2023 | TensorFlow is an open source platform for machine learning. Versions prior to 2.12.0 and 2.11.1 are vulnerable to integer overflow in EditDistance. A fix is included in TensorFlow version 2.12.0 and version 2.11.1. |
| CVE-2023-25660 | Alta (7.5) | 0.39% | — | 25 mar 2023 | TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, when the parameter `summarize` of `tf.raw_ops.Print` is zero, the new method `SummarizeArray<bool>` will reference to a… |
| CVE-2023-25659 | Alta (7.5) | 0.39% | — | 25 mar 2023 | TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, if the parameter `indices` for `DynamicStitch` does not match the shape of the parameter `data`, it can trigger an stack… |
| CVE-2023-25658 | Alta (7.5) | 0.39% | — | 25 mar 2023 | TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, an out of bounds read is in GRUBlockCellGrad. A fix is included in TensorFlow 2.12.0 and 2.11.1. |
| CVE-2022-41910 | Crítica (9.1) | 0.42% | — | 6 dic 2022 | TensorFlow is an open source platform for machine learning. The function MakeGrapplerFunctionItem takes arguments that determine the sizes of inputs and outputs. If the inputs given are greater than or equal to the… |
| CVE-2022-41902 | Crítica (9.1) | 0.47% | — | 6 dic 2022 | TensorFlow is an open source platform for machine learning. The function MakeGrapplerFunctionItem takes arguments that determine the sizes of inputs and outputs. If the inputs given are greater than or equal to the… |
| CVE-2022-41911 | Alta (7.5) | 0.43% | — | 18 nov 2022 | TensorFlow is an open source platform for machine learning. When printing a tensor, we get it's data as a `const char*` array (since that's the underlying storage) and then we typecast it to the element type. However,… |
| CVE-2022-41909 | Alta (7.5) | 0.53% | — | 18 nov 2022 | TensorFlow is an open source platform for machine learning. An input `encoded` that is not a valid `CompositeTensorVariant` tensor will trigger a segfault in `tf.raw_ops.CompositeTensorVariantToComponents`. We have… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.