Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2022-41895Medium· 4.8`MirrorPadGrad` heap out of bounds read
`MirrorPadGrad` heap out of bounds read
CVE-2022-41901Medium· 4.8`CHECK_EQ` fail via input in `SparseMatrixNNZ`
`CHECK_EQ` fail via input in `SparseMatrixNNZ`
CVE-2022-41910Medium· 4.8Heap overflow in `QuantizeAndDequantizeV2`
Heap overflow in `QuantizeAndDequantizeV2`
CVE-2022-41897Medium· 4.8`FractionalMaxPoolGrad` Heap out of bounds read
`FractionalMaxPoolGrad` Heap out of bounds read
CVE-2022-41902High· 7.1Out of bounds write in grappler in Tensorflow
Out of bounds write in grappler in Tensorflow
CVE-2022-41887Medium· 4.8Overflow in `tf.keras.losses.poisson`
Overflow in `tf.keras.losses.poisson`
CVE-2022-41885Medium· 4.8Overflow in `FusedResizeAndPadConv2D`
Overflow in `FusedResizeAndPadConv2D`
CVE-2022-41888Medium· 4.8FPE in `tf.image.generate_bounding_box_proposals`
FPE in `tf.image.generate_bounding_box_proposals`
CVE-2022-41893Medium· 4.8`CHECK_EQ` fail in `tf.raw_ops.TensorListResize`
`CHECK_EQ` fail in `tf.raw_ops.TensorListResize`
CVE-2022-41891Medium· 4.8Segfault in `tf.raw_ops.TensorListConcat`
Segfault in `tf.raw_ops.TensorListConcat`
CVE-2022-41886Medium· 4.8Overflow in `ImageProjectiveTransformV2`
Overflow in `ImageProjectiveTransformV2`
CVE-2022-41907Medium· 4.8Overflow in `ResizeNearestNeighborGrad`
Overflow in `ResizeNearestNeighborGrad`
CVE-2022-41899Medium· 4.8`CHECK` fail via inputs in `SdcaOptimizer`
`CHECK` fail via inputs in `SdcaOptimizer`
CVE-2022-3920High· 7.5Missing Authorization in HashiCorp Consul
Missing Authorization in HashiCorp Consul
CVE-2022-42964Medium· 5.9pymatgen is vulnerable to Regular Expression Denial of Service (ReDoS)
pymatgen is vulnerable to Regular Expression Denial of Service (ReDoS)
CVE-2022-44244Medium· 6.6Lin CMS vulnerable to Improper Authentication
Lin CMS vulnerable to Improper Authentication
CVE-2022-42965Medium· 5.9snowflake-connector-python is vulnerable to Regular Expression Denial of Service (ReDoS)
snowflake-connector-python is vulnerable to Regular Expression Denial of Service (ReDoS)
CVE-2022-42966Medium· 5.9cleo is vulnerable to Regular Expression Denial of Service (ReDoS)
cleo is vulnerable to Regular Expression Denial of Service (ReDoS)
CVE-2022-39307Medium· 5.3grafana: User enumeration via forget password (CVE-2022-39307)
An information leak was discovered in Grafana. Remote unauthenticated users could exploit the forget password feature to discover which user accounts exist.
CVE-2022-39306High· 8.1grafana: email addresses and usernames cannot be trusted (CVE-2022-39306)
An authentication bypass flaw was discovered in Grafana. This issue could allow a remote unauthenticated attacker to create an account and provide access to a certain organization, which can be exploited by gaining access to the signup lin…
CVE-2022-3023Critical· 9.8TiDB vulnerable to Use of Externally-Controlled Format String
TiDB vulnerable to Use of Externally-Controlled Format String
CVE-2022-33684High· 8.1Apache Pulsar Disabled Certificate Validation for OAuth Client Credential Requests makes C++/Python Clients vulnerable to MITM attack
Apache Pulsar Disabled Certificate Validation for OAuth Client Credential Requests makes C++/Python Clients vulnerable to MITM attack
CVE-2022-3616Medium· 5.4OctoRPKI crashes when max iterations is reached
OctoRPKI crashes when max iterations is reached
CVE-2022-44020Medium· 5.5OpenStack Sushy-Tools and VirtualBMC Improper Preservation of Permissions
OpenStack Sushy-Tools and VirtualBMC Improper Preservation of Permissions
CVE-2022-3697High· 7.5Ansible leaks password to logs
Ansible leaks password to logs
CVE-2022-39348Medium· 5.4Twisted vulnerable to NameVirtualHost Host header injection
Twisted vulnerable to NameVirtualHost Host header injection
CVE-2022-3644Medium· 5.5Plaintext storage of tokens in pulp_ansible
Plaintext storage of tokens in pulp_ansible
CVE-2022-31683Medium· 5.4Team scope authorization bypass when Post/Put request with :team_name in body, allows HTTP parameter pollution
Team scope authorization bypass when Post/Put request with :team_name in body, allows HTTP parameter pollution
CVE-2022-41547High· 7.5MobSF allows attackers to read arbitrary files via a crafted HTTP request
MobSF allows attackers to read arbitrary files via a crafted HTTP request
CVE-2022-32149High· 7.5golang.org/x/text/language Denial of service via crafted Accept-Language header
golang.org/x/text/language Denial of service via crafted Accept-Language header