tensorflow vulnerabilities
CVEs whose affected-version data names the tensorflow package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
419 CVEsRSS
CVE-2021-41209Medium· 5.5FPE in convolutions with zero size filters
FPE in convolutions with zero size filters
CVE-2021-41199Medium· 5.5Overflow/crash in `tf.image.resize` when size is large
Overflow/crash in `tf.image.resize` when size is large
CVE-2021-41217Medium· 5.5Null pointer exception when `Exit` node is not preceded by `Enter` op
Null pointer exception when `Exit` node is not preceded by `Enter` op
CVE-2021-41208Critical· 9.3Incomplete validation in boosted trees code
Incomplete validation in boosted trees code
CVE-2021-41219High· 7.8Undefined behavior via `nullptr` reference binding in sparse matrix multiplication
Undefined behavior via `nullptr` reference binding in sparse matrix multiplication
CVE-2021-41205High· 7.1Heap OOB read in all `tf.raw_ops.QuantizeAndDequantizeV*` ops
Heap OOB read in all `tf.raw_ops.QuantizeAndDequantizeV*` ops
CVE-2021-41228High· 7.5Code injection in `saved_model_cli`
Code injection in `saved_model_cli`
CVE-2021-41216Medium· 5.5Heap buffer overflow in `Transpose`
Heap buffer overflow in `Transpose`
CVE-2021-41226High· 7.1Heap OOB in `SparseBinCount`
Heap OOB in `SparseBinCount`
CVE-2021-41198Medium· 5.5Overflow/crash in `tf.tile` when tiling tensor is large
Overflow/crash in `tf.tile` when tiling tensor is large
CVE-2021-37689High· 7.8Null pointer dereference in TFLite MLIR optimizations
Null pointer dereference in TFLite MLIR optimizations
CVE-2021-37666High· 7.8Reference binding to nullptr in `RaggedTensorToVariant`
Reference binding to nullptr in `RaggedTensorToVariant`
CVE-2021-37688High· 7.8Null pointer dereference in TFLite
Null pointer dereference in TFLite
CVE-2021-37659High· 7.3Reference binding to nullptr and heap OOB in binary cwise ops
Reference binding to nullptr and heap OOB in binary cwise ops
CVE-2021-37648High· 7.8Incorrect validation of `SaveV2` inputs
Incorrect validation of `SaveV2` inputs
CVE-2021-37667High· 7.8Reference binding to nullptr in unicode encoding
Reference binding to nullptr in unicode encoding
CVE-2021-37669Medium· 5.5Crash in NMS ops caused by integer conversion to unsigned
Crash in NMS ops caused by integer conversion to unsigned
CVE-2021-37665High· 7.8Incomplete validation in MKL requantization
Incomplete validation in MKL requantization
CVE-2021-37676High· 7.8Reference binding to nullptr in shape inference
Reference binding to nullptr in shape inference
CVE-2021-37683Medium· 5.5FPE in TFLite division operations
FPE in TFLite division operations
CVE-2021-37678Critical· 9.3PoCArbitrary code execution due to YAML deserialization
Arbitrary code execution due to YAML deserialization
CVE-2021-37664High· 7.3Heap OOB in boosted trees
Heap OOB in boosted trees
CVE-2021-37671High· 7.8Reference binding to nullptr in map operations
Reference binding to nullptr in map operations
CVE-2021-37653Medium· 5.5Division by 0 in `ResourceGather`
Division by 0 in `ResourceGather`
CVE-2021-37677Medium· 5.5Missing validation in shape inference for `Dequantize`
Missing validation in shape inference for `Dequantize`
CVE-2021-37684Medium· 5.5FPE in TFLite pooling operations
FPE in TFLite pooling operations
CVE-2021-37686Medium· 5.5Infinite loop in TFLite
Infinite loop in TFLite
CVE-2021-37652High· 7.8Use after free in boosted trees creation
Use after free in boosted trees creation
CVE-2021-37687Medium· 5.5Heap OOB in TFLite's `Gather*` implementations
Heap OOB in TFLite's `Gather*` implementations
CVE-2021-37638High· 7.7Null pointer dereference in `RaggedTensorToTensor`
Null pointer dereference in `RaggedTensorToTensor`