Google TensorFlow是美国谷歌(Google)公司的一套用于机器学习的端到端开源平台。 Google TensorFlow 中存在输入验证错误漏洞,该漏洞源于产品在 tf.raw_ops.MapStage 的 CHECK 实现不当,攻击者可通过该漏洞导致拒绝服务。以下产品及版本收到影响:TensorFlow 2.5.1、TensorFlow 2.4.3 和 TensorFlow 2.3.4。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| tensorflow | tensorflow | >= 2.5.0, < 2.5.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-37678 | 9.3 CRITICAL | Arbitrary code execution due to YAML deserialization |
| CVE-2021-37639 | 8.4 HIGH | Null pointer dereference and heap OOB read in TensorFlow |
| CVE-2021-37689 | 7.8 HIGH | Null pointer dereference in TensorFlow Lite MLIR optimizations |
| CVE-2021-37665 | 7.8 HIGH | Incomplete validation in MKL requantization in TensorFlow |
| CVE-2021-37663 | 7.8 HIGH | Incomplete validation in `QuantizeV2` in TensorFlow |
| CVE-2021-37681 | 7.8 HIGH | Null pointer exception in TensorFlow Lite |
| CVE-2021-37648 | 7.8 HIGH | Incorrect validation of `SaveV2` inputs in TensorFlow |
| CVE-2021-37688 | 7.8 HIGH | Null pointer dereference in TensorFlow Lite |
| CVE-2021-37676 | 7.8 HIGH | Reference binding to nullptr in shape inference in TensorFlow |
| CVE-2021-37671 | 7.8 HIGH | Reference binding to nullptr in map operations in TensorFlow |
| CVE-2021-37666 | 7.8 HIGH | Reference binding to nullptr in `RaggedTensorToVariant` in TensorFlow |
| CVE-2021-37667 | 7.8 HIGH | Reference binding to nullptr in unicode encoding in TensorFlow |
| CVE-2021-37652 | 7.8 HIGH | Use after free in boosted trees creation in TensorFlow |
| CVE-2021-37650 | 7.8 HIGH | Segfault and heap buffer overflow in `{Experimental,}DatasetToTFRecord` in TensorFlow |
| CVE-2021-37643 | 7.7 HIGH | Null pointer dereference in `MatrixDiagPartOp` in TensorFlow |
| CVE-2021-37637 | 7.7 HIGH | Null pointer dereference in `CompressElement` in TensorFlow |
| CVE-2021-37649 | 7.7 HIGH | Null pointer dereference in `UncompressElement` in TensorFlow |
| CVE-2021-37647 | 7.7 HIGH | Null pointer dereference in `SparseTensorSliceDataset` in TensorFlow |
| CVE-2021-37638 | 7.7 HIGH | Null pointer dereference in `RaggedTensorToTensor` in TensorFlow |
| CVE-2021-37659 | 7.3 HIGH | Out of bounds read via null pointer dereference in TensorFlow |
Showing top 20 of 58 CVEs. View all on vendor page → →
No comments yet