Google TensorFlow是美国谷歌(Google)公司的一套用于机器学习的端到端开源平台。 Google TensorFlow存在数字错误漏洞,该漏洞源于在受影响的版本中,“tf.raw_ops.QuantizeAndDequantizeV4Grad”的实现容易受到整数溢出问题的攻击,这是由于将有符号整数值转换为无符号整数值,然后根据该值分配内存而导致的。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| tensorflow | tensorflow | >= 2.5.0, < 2.5.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-37678 | 9.3 CRITICAL | Arbitrary code execution due to YAML deserialization |
| CVE-2021-37639 | 8.4 HIGH | Null pointer dereference and heap OOB read in TensorFlow |
| CVE-2021-37689 | 7.8 HIGH | Null pointer dereference in TensorFlow Lite MLIR optimizations |
| CVE-2021-37665 | 7.8 HIGH | Incomplete validation in MKL requantization in TensorFlow |
| CVE-2021-37663 | 7.8 HIGH | Incomplete validation in `QuantizeV2` in TensorFlow |
| CVE-2021-37681 | 7.8 HIGH | Null pointer exception in TensorFlow Lite |
| CVE-2021-37667 | 7.8 HIGH | Reference binding to nullptr in unicode encoding in TensorFlow |
| CVE-2021-37688 | 7.8 HIGH | Null pointer dereference in TensorFlow Lite |
| CVE-2021-37676 | 7.8 HIGH | Reference binding to nullptr in shape inference in TensorFlow |
| CVE-2021-37671 | 7.8 HIGH | Reference binding to nullptr in map operations in TensorFlow |
| CVE-2021-37666 | 7.8 HIGH | Reference binding to nullptr in `RaggedTensorToVariant` in TensorFlow |
| CVE-2021-37648 | 7.8 HIGH | Incorrect validation of `SaveV2` inputs in TensorFlow |
| CVE-2021-37652 | 7.8 HIGH | Use after free in boosted trees creation in TensorFlow |
| CVE-2021-37650 | 7.8 HIGH | Segfault and heap buffer overflow in `{Experimental,}DatasetToTFRecord` in TensorFlow |
| CVE-2021-37643 | 7.7 HIGH | Null pointer dereference in `MatrixDiagPartOp` in TensorFlow |
| CVE-2021-37637 | 7.7 HIGH | Null pointer dereference in `CompressElement` in TensorFlow |
| CVE-2021-37649 | 7.7 HIGH | Null pointer dereference in `UncompressElement` in TensorFlow |
| CVE-2021-37647 | 7.7 HIGH | Null pointer dereference in `SparseTensorSliceDataset` in TensorFlow |
| CVE-2021-37638 | 7.7 HIGH | Null pointer dereference in `RaggedTensorToTensor` in TensorFlow |
| CVE-2021-37659 | 7.3 HIGH | Out of bounds read via null pointer dereference in TensorFlow |
Showing top 20 of 58 CVEs. View all on vendor page → →
No comments yet