tensorflow vulnerabilities
CVEs whose affected-version data names the tensorflow package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
419 CVEsRSS
CVE-2022-23584High· 7.6Use after free in `DecodePng` kernel
Use after free in `DecodePng` kernel
CVE-2022-23591High· 7.5Stack overflow in TensorFlow
Stack overflow in TensorFlow
CVE-2022-21726High· 8.1Out of bounds read in Tensorflow
Out of bounds read in Tensorflow
CVE-2022-23594High· 8.8Out of bounds read in Tensorflow
Out of bounds read in Tensorflow
CVE-2022-23581Medium· 6.5`CHECK`-failures during Grappler's `IsSimplifiableReshape` in Tensorflow
`CHECK`-failures during Grappler's `IsSimplifiableReshape` in Tensorflow
CVE-2022-23580Medium· 6.5Abort caused by allocating a vector that is too large in Tensorflow
Abort caused by allocating a vector that is too large in Tensorflow
CVE-2021-41202Medium· 5.5Overflow/crash in `tf.range`
Overflow/crash in `tf.range`
CVE-2021-41215Medium· 5.5Null pointer exception in `DeserializeSparse`
Null pointer exception in `DeserializeSparse`
CVE-2021-41214High· 7.8Reference binding to `nullptr` in `tf.ragged.cross`
Reference binding to `nullptr` in `tf.ragged.cross`
CVE-2021-41224High· 7.1`SparseFillEmptyRows` heap OOB
`SparseFillEmptyRows` heap OOB
CVE-2021-41197Medium· 5.5Crashes due to overflow and `CHECK`-fail in ops with large tensor shapes
Crashes due to overflow and `CHECK`-fail in ops with large tensor shapes
CVE-2021-41206High· 7.0Incomplete validation of shapes in multiple TF ops
Incomplete validation of shapes in multiple TF ops
CVE-2021-41196Medium· 5.5Crash in `max_pool3d` when size argument is 0 or negative
Crash in `max_pool3d` when size argument is 0 or negative
CVE-2021-41210High· 7.1Heap OOB read in `tf.raw_ops.SparseCountSparseOutput`
Heap OOB read in `tf.raw_ops.SparseCountSparseOutput`
CVE-2021-41227Medium· 6.6Arbitrary memory read in `ImmutableConst`
Arbitrary memory read in `ImmutableConst`
CVE-2021-41201High· 7.8Unitialized access in `EinsumHelper::ParseEquation`
Unitialized access in `EinsumHelper::ParseEquation`
CVE-2021-41213Medium· 5.5Deadlock in mutually recursive `tf.function` objects
Deadlock in mutually recursive `tf.function` objects
CVE-2021-41220High· 7.8Use after free / memory leak in `CollectiveReduceV2`
Use after free / memory leak in `CollectiveReduceV2`
CVE-2021-41200Medium· 5.5Incomplete validation in `tf.summary.create_file_writer`
Incomplete validation in `tf.summary.create_file_writer`
CVE-2021-41212High· 7.1Heap OOB read in `tf.ragged.cross`
Heap OOB read in `tf.ragged.cross`
CVE-2021-41223High· 7.1Heap OOB in `FusedBatchNorm` kernels
Heap OOB in `FusedBatchNorm` kernels
CVE-2021-41211High· 7.1Heap OOB in shape inference for `QuantizeV2`
Heap OOB in shape inference for `QuantizeV2`
CVE-2021-41221High· 7.8Access to invalid memory during shape inference in `Cudnn*` ops
Access to invalid memory during shape inference in `Cudnn*` ops
CVE-2021-41195Medium· 5.5Crash in `tf.math.segment_*` operations
Crash in `tf.math.segment_*` operations
CVE-2021-41222Medium· 5.5Segfault due to negative splits in `SplitV`
Segfault due to negative splits in `SplitV`
CVE-2021-41218Medium· 5.5Integer division by 0 in `tf.raw_ops.AllToAll`
Integer division by 0 in `tf.raw_ops.AllToAll`
CVE-2021-41207Medium· 5.5FPE in `ParallelConcat`
FPE in `ParallelConcat`
CVE-2021-41225Medium· 5.5A use of uninitialized value vulnerability in Tensorflow
A use of uninitialized value vulnerability in Tensorflow
CVE-2021-41203High· 7.8Missing validation during checkpoint loading
Missing validation during checkpoint loading
CVE-2021-41204Medium· 5.5Segfault while copying constant resource tensor
Segfault while copying constant resource tensor