Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2023-25659High· 7.5TensorFlow vulnerable to Out-of-Bounds Read in DynamicStitch
TensorFlow vulnerable to Out-of-Bounds Read in DynamicStitch
CVE-2023-25675High· 7.5TensorFlow has Segfault in Bincount with XLA
TensorFlow has Segfault in Bincount with XLA
CVE-2023-25662High· 7.5TensorFlow vulnerable to integer overflow in EditDistance
TensorFlow vulnerable to integer overflow in EditDistance
CVE-2023-25676High· 7.5TensorFlow has null dereference on ParallelConcat with XLA
TensorFlow has null dereference on ParallelConcat with XLA
CVE-2023-25664High· 7.5TensorFlow has Heap-buffer-overflow in AvgPoolGrad
TensorFlow has Heap-buffer-overflow in AvgPoolGrad
CVE-2023-25658High· 7.5TensorFlow vulnerable to Out-of-Bounds Read in GRUBlockCellGrad
TensorFlow vulnerable to Out-of-Bounds Read in GRUBlockCellGrad
CVE-2023-25663High· 7.5TensorFlow has Null Pointer Error in TensorArrayConcatV2
TensorFlow has Null Pointer Error in TensorArrayConcatV2
CVE-2023-25673High· 7.5TensorFlow has Floating Point Exception in TensorListSplit with XLA
TensorFlow has Floating Point Exception in TensorListSplit with XLA
CVE-2023-27579High· 7.5TensorFlow has Floating Point Exception in TFLite in conv kernel
TensorFlow has Floating Point Exception in TFLite in conv kernel
CVE-2023-25665High· 7.5TensorFlow has Null Pointer Error in SparseSparseMaximum
TensorFlow has Null Pointer Error in SparseSparseMaximum
CVE-2023-25670High· 7.5TensorFlow has Null Pointer Error in QuantizedMatMulWithBiasAndDequantize
TensorFlow has Null Pointer Error in QuantizedMatMulWithBiasAndDequantize
CVE-2023-1410Medium· 6.2Grafana Stored Cross-site Scripting in Graphite FunctionDescription tooltip
Grafana Stored Cross-site Scripting in Graphite FunctionDescription tooltip
CVE-2022-41354Medium· 5.3Argo CD authenticated but unauthorized users may enumerate Application names via the API
Argo CD authenticated but unauthorized users may enumerate Application names via the API
CVE-2022-3146Medium· 5.5tripleo-ansible may disclose important configuration details from an OpenStack deployment
tripleo-ansible may disclose important configuration details from an OpenStack deployment
CVE-2022-3101Medium· 5.5tripleo-ansible may disclose important configuration details from an OpenStack deployment
tripleo-ansible may disclose important configuration details from an OpenStack deployment
CVE-2023-28119High· 7.5crewjam/saml vulnerable to Denial Of Service Via Deflate Decompression Bomb
crewjam/saml vulnerable to Denial Of Service Via Deflate Decompression Bomb
CVE-2023-28114Medium· 4.8`cilium-cli` disables etcd authorization for clustermesh clusters
`cilium-cli` disables etcd authorization for clustermesh clusters
CVE-2023-1314High· 7.5cloudflared's Installer has Local Privilege Escalation Vulnerability
cloudflared's Installer has Local Privilege Escalation Vulnerability
CVE-2023-28117High· 7.6Sentry SDK leaks sensitive session information when `sendDefaultPII` is set to `True`
Sentry SDK leaks sensitive session information when `sendDefaultPII` is set to `True`
CVE-2023-27586Critical· 9.9CairoSVG improperly processes SVG files loaded from external resources
CairoSVG improperly processes SVG files loaded from external resources
CVE-2023-27593Medium· 4.4cilium-agent container can access the host via `hostPath` mount
cilium-agent container can access the host via `hostPath` mount
CVE-2021-29456Medium· 5.4Authelia allows open redirects on the logout endpoint
Authelia allows open redirects on the logout endpoint
CVE-2023-27582Critical· 9.1Full authentication bypass if SASL authorization username is specified
Full authentication bypass if SASL authorization username is specified
CVE-2017-20182Medium· 6.1Cross-site Scripting in django-ajax-utilities
Cross-site Scripting in django-ajax-utilities
CVE-2023-0845Medium· 6.5Consul Server Panic when Ingress and API Gateways Configured with Peering Connections
Consul Server Panic when Ingress and API Gateways Configured with Peering Connections
CVE-2022-3277Medium· 6.5openstack-neutron uncontrolled resource consumption flaw
openstack-neutron uncontrolled resource consumption flaw
CVE-2023-27522High· 7.5httpd: mod_proxy_uwsgi HTTP response splitting (CVE-2023-27522)
An HTTP Response Smuggling vulnerability was found in the Apache HTTP Server via mod_proxy_uwsgi. This security issue occurs when special characters in the origin response header can truncate or split the response forwarded to the client.
CVE-2023-22432Medium· 6.1PoCOpen redirect in web2py
Open redirect in web2py
CVE-2023-26051Medium· 6.5Saleor has Staff-Authenticated Error Message Information Disclosure Vulnerability via Python Exceptions
Saleor has Staff-Authenticated Error Message Information Disclosure Vulnerability via Python Exceptions
CVE-2023-26483Medium· 5.3gosaml2 vulnerable to Denial Of Service Via Deflate Decompression Bomb
gosaml2 vulnerable to Denial Of Service Via Deflate Decompression Bomb