Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

tensorflow — Vulnerabilities & Security Advisories 404

All 404 CVE vulnerabilities found in tensorflow, with AI-generated Chinese analysis, references, and POCs.

This page documents known security weaknesses within the TensorFlow product ecosystem, focusing on vulnerability aggregation for the TensorFlow framework. It provides a centralized view of security issues affecting this widely used open-source machine learning library, helping stakeholders assess their exposure to common programming errors and configuration flaws. The content here compiles a comprehensive list of identified vulnerabilities, ranging from critical remote code execution risks to less severe information disclosure issues. The data covers historical records spanning from the initial public releases of the software through recent updates, ensuring that both legacy and current versions are accounted for. This extensive time range allows users to trace the evolution of security posture over the product's lifecycle. Visitors can utilize this resource to track vendor advisories associated with specific components of the TensorFlow stack. It enables security professionals to understand broader trends within a specific weakness class by analyzing multiple instances across different releases. Additionally, users can look up a product's vulnerability history to identify patterns in fixes and regressions, supporting more informed risk management decisions. By aggregating these findings, the page serves as a reference for developers and security auditors seeking to evaluate the integrity of their machine learning pipelines against known threats without needing to consult multiple disparate sources.

Vendor: tensorflow

CVE IDTitleCVSSSeverityPublished
CVE-2022-29205 Segfault due to missing support for quantized types in TensorFlow CWE-908 5.5 Medium2022-05-20
CVE-2022-29206 Missing validation results in undefined behavior in `SparseTensorDenseAdd` in TensorFlow CWE-20 5.5 Medium2022-05-20
CVE-2022-29207 Undefined behavior when users supply invalid resource handles in TensorFlow CWE-20 5.5 Medium2022-05-20
CVE-2022-29195 Missing validation causes denial of service in TensorFlow via `StagePeek` CWE-20 5.5 Medium2022-05-20
CVE-2022-29197 Missing validation causes denial of service in TensorFlow via `UnsortedSegmentJoin` CWE-20 5.5 Medium2022-05-20
CVE-2022-29196 Missing validation causes denial of service in TensorFlow via `Conv3DBackpropFilterV2` CWE-20 5.5 Medium2022-05-20
CVE-2022-29198 Missing validation causes denial of service in TensorFlow via `SparseTensorToCSRSparseMatrix` CWE-20 5.5 Medium2022-05-20
CVE-2022-29199 Missing validation causes denial of service in TensorFlow via `LoadAndRemapMatrix` CWE-20 5.5 Medium2022-05-20
CVE-2022-29200 Missing validation causes denial of service in TensorFlow via `LSTMBlockCell` CWE-20 5.5 Medium2022-05-20
CVE-2022-29193 Missing validation causes `TensorSummaryV2` in TensorFlow to crash CWE-20 5.5 Medium2022-05-20
CVE-2022-29194 Missing validation causes denial of service via `DeleteSessionTensor` in TensorFlow CWE-20 5.5 Medium2022-05-20
CVE-2022-29191 Missing validation causes denial of service via `GetSessionTensor` in TensorFlow CWE-20 5.5 Medium2022-05-20
CVE-2022-29192 Missing validation crashes `QuantizeAndDequantizeV4Grad` in TensorFlow CWE-20 5.5 Medium2022-05-20
CVE-2022-23561 Out of bounds write in TFLite CWE-787 8.8 High2022-02-04
CVE-2022-23557 Division by zero in TFLite CWE-369 6.5 Medium2022-02-04
CVE-2022-23558 Integer overflow in TFLite array creation CWE-190 7.6 High2022-02-04
CVE-2022-23570 Null-dereference in Tensorflow CWE-476 6.5 Medium2022-02-04
CVE-2022-23564 Reachable Assertion in Tensorflow CWE-617 6.5 Medium2022-02-04
CVE-2022-23565 `CHECK`-failures in Tensorflow CWE-617 6.5 Medium2022-02-04
CVE-2022-23562 Integer overflow in Tensorflow CWE-190 7.6 High2022-02-04
CVE-2022-23563 Insecure temporary file in Tensorflow CWE-367 7.1 High2022-02-04
CVE-2022-23559 Integer overflow in TFLite CWE-190 8.8 High2022-02-04
CVE-2022-23560 Read and Write outside of bounds in TFLite CWE-125 8.8 High2022-02-04
CVE-2022-23574 Out of bounds read and write in Tensorflow CWE-125 8.8 High2022-02-04
CVE-2022-23571 Reachable Assertion in Tensorflow CWE-617 6.5 Medium2022-02-04
CVE-2022-23566 Out of bounds write in Tensorflow CWE-787 8.8 High2022-02-04
CVE-2022-23577 Null-dereference in Tensorflow CWE-476 6.5 Medium2022-02-04
CVE-2022-23578 Memory leak in Tensorflow CWE-401 4.3 Medium2022-02-04
CVE-2022-23572 Crash when type cannot be specialized in Tensorflow CWE-754 6.5 Medium2022-02-04
CVE-2022-23573 Uninitialized variable access in Tensorflow CWE-908 7.6 High2022-02-04

All 404 known CVE vulnerabilities affecting tensorflow with full Chinese analysis, references, and POCs where available.