tensorflow vulnerabilities
CVEs whose affected-version data names the tensorflow package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
419 CVEsRSS
CVE-2022-36019Medium· 5.9TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVarsPerChannel`
TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVarsPerChannel`
CVE-2022-35971Medium· 5.9TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVars`
TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVars`
CVE-2022-36026Medium· 5.9TensorFlow vulnerable to `CHECK` fail in `QuantizeAndDequantizeV3`
TensorFlow vulnerable to `CHECK` fail in `QuantizeAndDequantizeV3`
CVE-2022-35985Medium· 5.9TensorFlow vulnerable to `CHECK` fail in `LRNGrad`
TensorFlow vulnerable to `CHECK` fail in `LRNGrad`
CVE-2022-35935Medium· 5.9TensorFlow vulnerable to `CHECK` failure in `SobolSample` via missing validation
TensorFlow vulnerable to `CHECK` failure in `SobolSample` via missing validation
CVE-2022-35963Medium· 5.9TensorFlow vulnerable to `CHECK` failures in `FractionalAvgPoolGrad`
TensorFlow vulnerable to `CHECK` failures in `FractionalAvgPoolGrad`
CVE-2022-36013Medium· 5.9TensorFlow vulnerable to null-dereference in `mlir::tfg::GraphDefImporter::ConvertNodeDef`
TensorFlow vulnerable to null-dereference in `mlir::tfg::GraphDefImporter::ConvertNodeDef`
CVE-2022-36014Medium· 5.9TensorFlow vulnerable to null-dereference in `mlir::tfg::TFOp::nameAttr`
TensorFlow vulnerable to null-dereference in `mlir::tfg::TFOp::nameAttr`
CVE-2022-36027Medium· 5.9TensorFlow segfault TFLite converter on per-channel quantized transposed convolutions
TensorFlow segfault TFLite converter on per-channel quantized transposed convolutions
CVE-2022-35973Medium· 5.9TensorFlow vulnerable to segfault in `QuantizedMatMul`
TensorFlow vulnerable to segfault in `QuantizedMatMul`
CVE-2022-35966Medium· 5.9TensorFlow vulnerable to segfault in `QuantizedAvgPool`
TensorFlow vulnerable to segfault in `QuantizedAvgPool`
CVE-2022-35972Medium· 5.9TensorFlow vulnerable to segfault in `QuantizedBiasAdd`
TensorFlow vulnerable to segfault in `QuantizedBiasAdd`
CVE-2022-35982Medium· 5.9TensorFlow vulnerable to segfault in `SparseBincount`
TensorFlow vulnerable to segfault in `SparseBincount`
CVE-2022-35999Medium· 5.9TensorFlow vulnerable to `CHECK` fail in `Conv2DBackpropInput`
TensorFlow vulnerable to `CHECK` fail in `Conv2DBackpropInput`
CVE-2022-35968Medium· 5.9TensorFlow vulnerable to `CHECK` fail in `AvgPoolGrad`
TensorFlow vulnerable to `CHECK` fail in `AvgPoolGrad`
CVE-2022-29211Medium· 5.5Segfault if `tf.histogram_fixed_width` is called with NaN values in TensorFlow
Segfault if `tf.histogram_fixed_width` is called with NaN values in TensorFlow
CVE-2022-29206Medium· 5.5Missing validation results in undefined behavior in `SparseTensorDenseAdd
Missing validation results in undefined behavior in `SparseTensorDenseAdd
CVE-2022-29201Medium· 5.5Missing validation results in undefined behavior in `QuantizedConv2D`
Missing validation results in undefined behavior in `QuantizedConv2D`
CVE-2022-29199Medium· 5.5Missing validation causes denial of service via `LoadAndRemapMatrix`
Missing validation causes denial of service via `LoadAndRemapMatrix`
CVE-2022-29198Medium· 5.5Missing validation causes denial of service via `SparseTensorToCSRSparseMatrix`
Missing validation causes denial of service via `SparseTensorToCSRSparseMatrix`
CVE-2022-29203Medium· 5.5Integer overflow in `SpaceToBatchND`
Integer overflow in `SpaceToBatchND`
CVE-2022-29204Medium· 5.5Missing validation causes denial of service via `Conv3DBackpropFilterV2`
Missing validation causes denial of service via `Conv3DBackpropFilterV2`
CVE-2022-29197Medium· 5.5Missing validation causes denial of service via `UnsortedSegmentJoin`
Missing validation causes denial of service via `UnsortedSegmentJoin`
CVE-2022-29210Medium· 5.5Heap buffer overflow due to incorrect hash function in TensorFlow
Heap buffer overflow due to incorrect hash function in TensorFlow
CVE-2022-29194Medium· 5.5Missing validation causes denial of service via `DeleteSessionTensor`
Missing validation causes denial of service via `DeleteSessionTensor`
CVE-2022-29195Medium· 5.5Missing validation causes denial of service via `StagePeek`
Missing validation causes denial of service via `StagePeek`
CVE-2022-29192Medium· 5.5Missing validation crashes `QuantizeAndDequantizeV4Grad`
Missing validation crashes `QuantizeAndDequantizeV4Grad`
CVE-2022-29191Medium· 5.5Missing validation causes denial of service via `GetSessionTensor`
Missing validation causes denial of service via `GetSessionTensor`
CVE-2022-29209Medium· 5.5Type confusion leading to `CHECK`-failure based denial of service in TensorFlow
Type confusion leading to `CHECK`-failure based denial of service in TensorFlow
CVE-2022-29202Medium· 5.5Denial of service in `tf.ragged.constant` due to lack of validation
Denial of service in `tf.ragged.constant` due to lack of validation