Google TensorFlow是美国谷歌(Google)公司的一套用于机器学习的端到端开源平台。 Tensorflow 存在缓冲区错误漏洞,该漏洞源于TensorFlow的类型推断可能会导致堆读取越界,因为边界检查是在DCHECK中完成的(在生产过程中是没有操作的)。攻击者可利用该漏洞可以控制input idx变量,使ix大于node .args中的值的数量。修复将包含在TensorFlow 2.8.0中。这是唯一受影响的版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| tensorflow | tensorflow | = 2.8.0-rc0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-23561 | 8.8 HIGH | Out of bounds write in TFLite |
| CVE-2022-23594 | 8.8 HIGH | Out of bounds read in Tensorflow |
| CVE-2022-23587 | 8.8 HIGH | Integer overflow in Tensorflow |
| CVE-2022-23559 | 8.8 HIGH | Integer overflow in TFLite |
| CVE-2022-23560 | 8.8 HIGH | Read and Write outside of bounds in TFLite |
| CVE-2022-23574 | 8.8 HIGH | Out of bounds read and write in Tensorflow |
| CVE-2022-23566 | 8.8 HIGH | Out of bounds write in Tensorflow |
| CVE-2022-23558 | 7.6 HIGH | Integer overflow in TFLite array creation |
| CVE-2022-23562 | 7.6 HIGH | Integer overflow in Tensorflow |
| CVE-2022-23584 | 7.6 HIGH | Use after free in `DecodePng` in Tensorflow |
| CVE-2022-23573 | 7.6 HIGH | Uninitialized variable access in Tensorflow |
| CVE-2022-23591 | 7.5 HIGH | Stack overflow in Tensorflow |
| CVE-2022-23563 | 7.1 HIGH | Insecure temporary file in Tensorflow |
| CVE-2022-23575 | 6.5 MEDIUM | Integer overflow in Tensorflow |
| CVE-2022-23557 | 6.5 MEDIUM | Division by zero in TFLite |
| CVE-2022-23570 | 6.5 MEDIUM | Null-dereference in Tensorflow |
| CVE-2022-23564 | 6.5 MEDIUM | Reachable Assertion in Tensorflow |
| CVE-2022-23565 | 6.5 MEDIUM | `CHECK`-failures in Tensorflow |
| CVE-2022-23582 | 6.5 MEDIUM | `CHECK`-failures in `TensorByteSize` in Tensorflow |
| CVE-2022-23583 | 6.5 MEDIUM | `CHECK`-failures in binary ops in Tensorflow |
Showing top 20 of 36 CVEs. View all on vendor page → →
No comments yet