ONNX是ONNX组织开源的一个机器学习互操作性的开放标准。 ONNX 1.21.x及之前版本存在缓冲区错误漏洞,该漏洞源于onnxruntime组件的onnx/defs/nn/old.cc文件中的convPoolShapeInference_opset19函数存在越界读取问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | onnx | 1.0 |
cpe:2.3:a:onnx:onnx:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-14629 | 4.3 MEDIUM | RT-Thread Parameter lwp_syscall.c sys_ioctl divide by zero |
| CVE-2026-14618 | 4.3 MEDIUM | Open5GS AMF nnrf-handler.c amf_nnrf_handle_nf_discover denial of service |
| CVE-2026-14685 | 3.3 LOW | HdrHistogram AbstractHistogram AbstractHistogram.java recordValueWithCount state issue |
| CVE-2026-14684 | 3.3 LOW | HdrHistogram AbstractHistogram.java memory allocation |
| CVE-2026-14683 | 3.3 LOW | HdrHistogram AbstractHistogram.java memory allocation |
No comments yet