CVE-2024-0521Critical· 9.3▾ MidnightCode Injection in paddlepaddle
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 51.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.5%
The vulnerability arises from the way the url parameter is incorporated into the command string without proper validation or sanitization. If the url is constructed from untrusted sources, an attacker could potentially inject malicious commands.
paddlepaddle < 2.6.0Upgrade to a patched release:
paddlepaddle 2.6.0Connected by shared product, vendor, weakness, or advisory.
CVE-2023-38674Medium· 4.7PaddlePaddle floating point exception in paddle.nanmedian
CVE-2023-38676Medium· 4.7PaddlePaddle segfault in paddle.dot
CVE-2023-52308Medium· 4.7PaddlePaddle floating point exception in paddle.amin
CVE-2023-52305Medium· 4.7PaddlePaddle floating point exception in paddle.topk
CVE-2023-38670Medium· 4.7Null pointer dereference in PaddlePaddle
CVE-2023-52306Medium· 4.7PaddlePaddle floating point exception in paddle.lerp