Google TensorFlow是美国谷歌(Google)公司的一套用于机器学习的端到端开源平台。 Google TensorFlow 中存在输入验证错误漏洞,该漏洞源于产品 requantization 的 MKL 实现未对空指针做有效验证,攻击者可通过解引用空指针访问堆分配数组之外的数据。以下产品及版本收到影响:TensorFlow 2.5.1、TensorFlow 2.4.3 和 TensorFlow 2.3.4。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| tensorflow | tensorflow | >= 2.5.0, < 2.5.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-37678 | 9.3 CRITICAL | Arbitrary code execution due to YAML deserialization |
| CVE-2021-37639 | 8.4 HIGH | Null pointer dereference and heap OOB read in TensorFlow |
| CVE-2021-37689 | 7.8 HIGH | Null pointer dereference in TensorFlow Lite MLIR optimizations |
| CVE-2021-37663 | 7.8 HIGH | Incomplete validation in `QuantizeV2` in TensorFlow |
| CVE-2021-37681 | 7.8 HIGH | Null pointer exception in TensorFlow Lite |
| CVE-2021-37648 | 7.8 HIGH | Incorrect validation of `SaveV2` inputs in TensorFlow |
| CVE-2021-37688 | 7.8 HIGH | Null pointer dereference in TensorFlow Lite |
| CVE-2021-37676 | 7.8 HIGH | Reference binding to nullptr in shape inference in TensorFlow |
| CVE-2021-37671 | 7.8 HIGH | Reference binding to nullptr in map operations in TensorFlow |
| CVE-2021-37666 | 7.8 HIGH | Reference binding to nullptr in `RaggedTensorToVariant` in TensorFlow |
| CVE-2021-37667 | 7.8 HIGH | Reference binding to nullptr in unicode encoding in TensorFlow |
| CVE-2021-37652 | 7.8 HIGH | Use after free in boosted trees creation in TensorFlow |
| CVE-2021-37650 | 7.8 HIGH | Segfault and heap buffer overflow in `{Experimental,}DatasetToTFRecord` in TensorFlow |
| CVE-2021-37637 | 7.7 HIGH | Null pointer dereference in `CompressElement` in TensorFlow |
| CVE-2021-37643 | 7.7 HIGH | Null pointer dereference in `MatrixDiagPartOp` in TensorFlow |
| CVE-2021-37647 | 7.7 HIGH | Null pointer dereference in `SparseTensorSliceDataset` in TensorFlow |
| CVE-2021-37638 | 7.7 HIGH | Null pointer dereference in `RaggedTensorToTensor` in TensorFlow |
| CVE-2021-37649 | 7.7 HIGH | Null pointer dereference in `UncompressElement` in TensorFlow |
| CVE-2021-37659 | 7.3 HIGH | Out of bounds read via null pointer dereference in TensorFlow |
| CVE-2021-37664 | 7.3 HIGH | Heap OOB in boosted trees in TensorFlow |
Showing top 20 of 58 CVEs. View all on vendor page → →
No comments yet