Google TensorFlow是美国谷歌(Google)公司的一套用于机器学习的端到端开源平台。 Google TensorFlow 2.9.0之前版本、2.8.1之前版本、2.7.2之前版本和2.6.4之前版本存在代码问题漏洞,该漏洞源于tf.raw_ops.SparseTensorDenseAdd对于输入的参数存在不完全验证。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| tensorflow | tensorflow | < 2.6.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-29216 | 7.8 HIGH | Code injection in `saved_model_cli` in TensorFlow |
| CVE-2022-29208 | 7.1 HIGH | Segfault and Out-of-bounds Write write due to incomplete validation in TensorFlow |
| CVE-2022-29205 | 5.5 MEDIUM | Segfault due to missing support for quantized types in TensorFlow |
| CVE-2022-29213 | 5.5 MEDIUM | Incomplete validation in signal ops leads to crashes in TensorFlow |
| CVE-2022-29210 | 5.5 MEDIUM | Heap buffer overflow due to incorrect hash function in TensorFlow |
| CVE-2022-29209 | 5.5 MEDIUM | Type confusion leading to `CHECK`-failure based denial of service in TensorFlow |
| CVE-2022-29211 | 5.5 MEDIUM | Segfault in TensorFlow if `tf.histogram_fixed_width` is called with NaN values |
| CVE-2022-29212 | 5.5 MEDIUM | Core dump when loading TFLite models with quantization in TensorFlow |
| CVE-2022-29201 | 5.5 MEDIUM | Missing validation in `QuantizedConv2D` results in undefined behavior in TensorFlow |
| CVE-2022-29202 | 5.5 MEDIUM | Denial of service in TensorFlow due to lack of validation in `tf.ragged.constant` |
| CVE-2022-29203 | 5.5 MEDIUM | Integer overflow in `SpaceToBatchND` in TensorFlow |
| CVE-2022-29204 | 5.5 MEDIUM | Missing validation causes denial of service in TensorFlow via `Conv3DBackpropFilterV2` |
| CVE-2022-29192 | 5.5 MEDIUM | Missing validation crashes `QuantizeAndDequantizeV4Grad` in TensorFlow |
| CVE-2022-29207 | 5.5 MEDIUM | Undefined behavior when users supply invalid resource handles in TensorFlow |
| CVE-2022-29195 | 5.5 MEDIUM | Missing validation causes denial of service in TensorFlow via `StagePeek` |
| CVE-2022-29197 | 5.5 MEDIUM | Missing validation causes denial of service in TensorFlow via `UnsortedSegmentJoin` |
| CVE-2022-29196 | 5.5 MEDIUM | Missing validation causes denial of service in TensorFlow via `Conv3DBackpropFilterV2` |
| CVE-2022-29198 | 5.5 MEDIUM | Missing validation causes denial of service in TensorFlow via `SparseTensorToCSRSparseMatr |
| CVE-2022-29199 | 5.5 MEDIUM | Missing validation causes denial of service in TensorFlow via `LoadAndRemapMatrix` |
| CVE-2022-29200 | 5.5 MEDIUM | Missing validation causes denial of service in TensorFlow via `LSTMBlockCell` |
Showing top 20 of 24 CVEs. View all on vendor page → →
No comments yet