Google TensorFlow是美国谷歌(Google)公司的一套用于机器学习的端到端开源平台。 Google TensorFlow 2.12.0 版本之前的 2.12 版本和 2.11.1 版本之前的 2.11 版本存在安全漏洞,该漏洞源于当使用 XLA 运行 2.12.0 和 2.11.1 之前的版本时,如果给定的参数 weights 与参数 arr 的形状既不相同,也不是长度为 0 的张量,则 会出现段错误。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| tensorflow | tensorflow | < 2.11.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-25668 | 9.8 CRITICAL | TensorFlow vulnerable to heap out-of-buffer read in the QuantizeAndDequantize operation |
| CVE-2023-25801 | 8.0 HIGH | TensorFlow has double free in Fractional(Max/Avg)Pool |
| CVE-2023-27579 | 7.5 HIGH | TensorFlow has Floating Point Exception in TFLite in conv kernel |
| CVE-2023-25660 | 7.5 HIGH | TensorFlow vulnerable to seg fault in `tf.raw_ops.Print` |
| CVE-2023-25676 | 7.5 HIGH | TensorFlow has null dereference on ParallelConcat with XLA |
| CVE-2023-25674 | 7.5 HIGH | TensorFlow has Null Pointer Error in RandomShuffle with XLA enable |
| CVE-2023-25673 | 7.5 HIGH | TensorFlow has Floating Point Exception in TensorListSplit with XLA |
| CVE-2023-25672 | 7.5 HIGH | TensorFlow has Null Pointer Error in LookupTableImportV2 |
| CVE-2023-25671 | 7.5 HIGH | TensorFlow has segmentation fault in tfg-translate |
| CVE-2023-25670 | 7.5 HIGH | TensorFlow has Null Pointer Error in QuantizedMatMulWithBiasAndDequantize |
| CVE-2023-25669 | 7.5 HIGH | TensorFlow has Floating Point Exception in AvgPoolGrad with XLA |
| CVE-2023-25665 | 7.5 HIGH | TensorFlow has Null Pointer Error in SparseSparseMaximum |
| CVE-2023-25666 | 7.5 HIGH | TensorFlow has Floating Point Exception in AudioSpectrogram |
| CVE-2023-25664 | 7.5 HIGH | TensorFlow vulnerable to Heap Buffer Overflow in AvgPoolGrad |
| CVE-2023-25663 | 7.5 HIGH | TensorFlow has Null Pointer Error in TensorArrayConcatV2 |
| CVE-2023-25662 | 7.5 HIGH | TensorFlow vulnerable to integer overflow in EditDistance |
| CVE-2023-25658 | 7.5 HIGH | TensorFlow vulnerable to Out-of-Bounds Read in GRUBlockCellGrad |
| CVE-2023-25659 | 7.5 HIGH | TensorFlow vulnerable to Out-of-Bounds Read in DynamicStitch |
| CVE-2023-25667 | 6.5 MEDIUM | TensorFlow vulnerable to segfault when opening multiframe gif |
No comments yet