Google TensorFlow是美国谷歌(Google)公司的一套用于机器学习的端到端开源平台。 TensorFlow 2.6.0 之前版本、2.5.1之前版本、2.4.3之前版本和2.3.4之前版本存在代码问题漏洞,该漏洞源于通过向“tf.rawu ops.CompressElement”传递无效输入,可以触发TensorFlow中的空指针解引用
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| tensorflow | tensorflow | >= 2.5.0, < 2.5.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-37678 | 9.3 CRITICAL | Arbitrary code execution due to YAML deserialization |
| CVE-2021-37639 | 8.4 HIGH | Null pointer dereference and heap OOB read in TensorFlow |
| CVE-2021-37689 | 7.8 HIGH | Null pointer dereference in TensorFlow Lite MLIR optimizations |
| CVE-2021-37665 | 7.8 HIGH | Incomplete validation in MKL requantization in TensorFlow |
| CVE-2021-37663 | 7.8 HIGH | Incomplete validation in `QuantizeV2` in TensorFlow |
| CVE-2021-37681 | 7.8 HIGH | Null pointer exception in TensorFlow Lite |
| CVE-2021-37667 | 7.8 HIGH | Reference binding to nullptr in unicode encoding in TensorFlow |
| CVE-2021-37688 | 7.8 HIGH | Null pointer dereference in TensorFlow Lite |
| CVE-2021-37676 | 7.8 HIGH | Reference binding to nullptr in shape inference in TensorFlow |
| CVE-2021-37671 | 7.8 HIGH | Reference binding to nullptr in map operations in TensorFlow |
| CVE-2021-37666 | 7.8 HIGH | Reference binding to nullptr in `RaggedTensorToVariant` in TensorFlow |
| CVE-2021-37648 | 7.8 HIGH | Incorrect validation of `SaveV2` inputs in TensorFlow |
| CVE-2021-37652 | 7.8 HIGH | Use after free in boosted trees creation in TensorFlow |
| CVE-2021-37650 | 7.8 HIGH | Segfault and heap buffer overflow in `{Experimental,}DatasetToTFRecord` in TensorFlow |
| CVE-2021-37643 | 7.7 HIGH | Null pointer dereference in `MatrixDiagPartOp` in TensorFlow |
| CVE-2021-37647 | 7.7 HIGH | Null pointer dereference in `SparseTensorSliceDataset` in TensorFlow |
| CVE-2021-37638 | 7.7 HIGH | Null pointer dereference in `RaggedTensorToTensor` in TensorFlow |
| CVE-2021-37649 | 7.7 HIGH | Null pointer dereference in `UncompressElement` in TensorFlow |
| CVE-2021-37664 | 7.3 HIGH | Heap OOB in boosted trees in TensorFlow |
| CVE-2021-37635 | 7.3 HIGH | Heap out of bounds access in sparse reduction operations in TensorFlow |
Showing top 20 of 58 CVEs. View all on vendor page → →
No comments yet