tensorflow-cpu vulnerabilities
CVEs whose affected-version data names the tensorflow-cpu package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
416 CVEsRSS
CVE-2022-35985Medium· 5.9TensorFlow vulnerable to `CHECK` fail in `LRNGrad`
TensorFlow vulnerable to `CHECK` fail in `LRNGrad`
CVE-2022-35935Medium· 5.9TensorFlow vulnerable to `CHECK` failure in `SobolSample` via missing validation
TensorFlow vulnerable to `CHECK` failure in `SobolSample` via missing validation
CVE-2022-35963Medium· 5.9TensorFlow vulnerable to `CHECK` failures in `FractionalAvgPoolGrad`
TensorFlow vulnerable to `CHECK` failures in `FractionalAvgPoolGrad`
CVE-2022-36013Medium· 5.9TensorFlow vulnerable to null-dereference in `mlir::tfg::GraphDefImporter::ConvertNodeDef`
TensorFlow vulnerable to null-dereference in `mlir::tfg::GraphDefImporter::ConvertNodeDef`
CVE-2022-36014Medium· 5.9TensorFlow vulnerable to null-dereference in `mlir::tfg::TFOp::nameAttr`
TensorFlow vulnerable to null-dereference in `mlir::tfg::TFOp::nameAttr`
CVE-2022-36027Medium· 5.9TensorFlow segfault TFLite converter on per-channel quantized transposed convolutions
TensorFlow segfault TFLite converter on per-channel quantized transposed convolutions
CVE-2022-35973Medium· 5.9TensorFlow vulnerable to segfault in `QuantizedMatMul`
TensorFlow vulnerable to segfault in `QuantizedMatMul`
CVE-2022-35966Medium· 5.9TensorFlow vulnerable to segfault in `QuantizedAvgPool`
TensorFlow vulnerable to segfault in `QuantizedAvgPool`
CVE-2022-35972Medium· 5.9TensorFlow vulnerable to segfault in `QuantizedBiasAdd`
TensorFlow vulnerable to segfault in `QuantizedBiasAdd`
CVE-2022-35982Medium· 5.9TensorFlow vulnerable to segfault in `SparseBincount`
TensorFlow vulnerable to segfault in `SparseBincount`
CVE-2022-35999Medium· 5.9TensorFlow vulnerable to `CHECK` fail in `Conv2DBackpropInput`
TensorFlow vulnerable to `CHECK` fail in `Conv2DBackpropInput`
CVE-2022-35968Medium· 5.9TensorFlow vulnerable to `CHECK` fail in `AvgPoolGrad`
TensorFlow vulnerable to `CHECK` fail in `AvgPoolGrad`
CVE-2022-29211Medium· 5.5Segfault if `tf.histogram_fixed_width` is called with NaN values in TensorFlow
Segfault if `tf.histogram_fixed_width` is called with NaN values in TensorFlow
CVE-2022-29206Medium· 5.5Missing validation results in undefined behavior in `SparseTensorDenseAdd
Missing validation results in undefined behavior in `SparseTensorDenseAdd
CVE-2022-29201Medium· 5.5Missing validation results in undefined behavior in `QuantizedConv2D`
Missing validation results in undefined behavior in `QuantizedConv2D`
CVE-2022-29199Medium· 5.5Missing validation causes denial of service via `LoadAndRemapMatrix`
Missing validation causes denial of service via `LoadAndRemapMatrix`
CVE-2022-29198Medium· 5.5Missing validation causes denial of service via `SparseTensorToCSRSparseMatrix`
Missing validation causes denial of service via `SparseTensorToCSRSparseMatrix`
CVE-2022-29203Medium· 5.5Integer overflow in `SpaceToBatchND`
Integer overflow in `SpaceToBatchND`
CVE-2022-29204Medium· 5.5Missing validation causes denial of service via `Conv3DBackpropFilterV2`
Missing validation causes denial of service via `Conv3DBackpropFilterV2`
CVE-2022-29197Medium· 5.5Missing validation causes denial of service via `UnsortedSegmentJoin`
Missing validation causes denial of service via `UnsortedSegmentJoin`
CVE-2022-29210Medium· 5.5Heap buffer overflow due to incorrect hash function in TensorFlow
Heap buffer overflow due to incorrect hash function in TensorFlow
CVE-2022-29194Medium· 5.5Missing validation causes denial of service via `DeleteSessionTensor`
Missing validation causes denial of service via `DeleteSessionTensor`
CVE-2022-29195Medium· 5.5Missing validation causes denial of service via `StagePeek`
Missing validation causes denial of service via `StagePeek`
CVE-2022-29192Medium· 5.5Missing validation crashes `QuantizeAndDequantizeV4Grad`
Missing validation crashes `QuantizeAndDequantizeV4Grad`
CVE-2022-29191Medium· 5.5Missing validation causes denial of service via `GetSessionTensor`
Missing validation causes denial of service via `GetSessionTensor`
CVE-2022-29209Medium· 5.5Type confusion leading to `CHECK`-failure based denial of service in TensorFlow
Type confusion leading to `CHECK`-failure based denial of service in TensorFlow
CVE-2022-29202Medium· 5.5Denial of service in `tf.ragged.constant` due to lack of validation
Denial of service in `tf.ragged.constant` due to lack of validation
CVE-2022-29212Medium· 5.5Core dump when loading TFLite models with quantization in TensorFlow
Core dump when loading TFLite models with quantization in TensorFlow
CVE-2022-29216High· 7.8Code injection in `saved_model_cli` in TensorFlow
Code injection in `saved_model_cli` in TensorFlow
CVE-2022-29207Medium· 5.5Undefined behavior when users supply invalid resource handles
Undefined behavior when users supply invalid resource handles