Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2022-35988Medium· 5.9TensorFlow vulnerable to `CHECK` fail in `tf.linalg.matrix_rank`
TensorFlow vulnerable to `CHECK` fail in `tf.linalg.matrix_rank`
CVE-2022-35992Medium· 5.9TensorFlow vulnerable to `CHECK` fail in `TensorListFromTensor`
TensorFlow vulnerable to `CHECK` fail in `TensorListFromTensor`
CVE-2022-36019Medium· 5.9TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVarsPerChannel`
TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVarsPerChannel`
CVE-2022-35971Medium· 5.9TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVars`
TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVars`
CVE-2022-36026Medium· 5.9TensorFlow vulnerable to `CHECK` fail in `QuantizeAndDequantizeV3`
TensorFlow vulnerable to `CHECK` fail in `QuantizeAndDequantizeV3`
CVE-2022-35985Medium· 5.9TensorFlow vulnerable to `CHECK` fail in `LRNGrad`
TensorFlow vulnerable to `CHECK` fail in `LRNGrad`
CVE-2022-35935Medium· 5.9TensorFlow vulnerable to `CHECK` failure in `SobolSample` via missing validation
TensorFlow vulnerable to `CHECK` failure in `SobolSample` via missing validation
CVE-2022-35963Medium· 5.9TensorFlow vulnerable to `CHECK` failures in `FractionalAvgPoolGrad`
TensorFlow vulnerable to `CHECK` failures in `FractionalAvgPoolGrad`
CVE-2022-36013Medium· 5.9TensorFlow vulnerable to null-dereference in `mlir::tfg::GraphDefImporter::ConvertNodeDef`
TensorFlow vulnerable to null-dereference in `mlir::tfg::GraphDefImporter::ConvertNodeDef`
CVE-2022-36014Medium· 5.9TensorFlow vulnerable to null-dereference in `mlir::tfg::TFOp::nameAttr`
TensorFlow vulnerable to null-dereference in `mlir::tfg::TFOp::nameAttr`
CVE-2022-36027Medium· 5.9TensorFlow segfault TFLite converter on per-channel quantized transposed convolutions
TensorFlow segfault TFLite converter on per-channel quantized transposed convolutions
CVE-2022-35973Medium· 5.9TensorFlow vulnerable to segfault in `QuantizedMatMul`
TensorFlow vulnerable to segfault in `QuantizedMatMul`
CVE-2022-35966Medium· 5.9TensorFlow vulnerable to segfault in `QuantizedAvgPool`
TensorFlow vulnerable to segfault in `QuantizedAvgPool`
CVE-2022-35972Medium· 5.9TensorFlow vulnerable to segfault in `QuantizedBiasAdd`
TensorFlow vulnerable to segfault in `QuantizedBiasAdd`
CVE-2022-35982Medium· 5.9TensorFlow vulnerable to segfault in `SparseBincount`
TensorFlow vulnerable to segfault in `SparseBincount`
CVE-2022-35999Medium· 5.9TensorFlow vulnerable to `CHECK` fail in `Conv2DBackpropInput`
TensorFlow vulnerable to `CHECK` fail in `Conv2DBackpropInput`
CVE-2022-35968Medium· 5.9TensorFlow vulnerable to `CHECK` fail in `AvgPoolGrad`
TensorFlow vulnerable to `CHECK` fail in `AvgPoolGrad`
GHSA-qv98-3369-g364HighKubeVirt vulnerable to arbitrary file read on host
KubeVirt vulnerable to arbitrary file read on host
CVE-2022-32190NoneFailure to strip relative path components in net/url
Failure to strip relative path components in net/url
CVE-2022-37189High· 7.5MEI2Volpiano is vulnerable to XML External Entity (XXE), leading to a Denial of Service (DoS)
MEI2Volpiano is vulnerable to XML External Entity (XXE), leading to a Denial of Service (DoS)
CVE-2022-27664High· 7.5golang.org/x/net/http2 Denial of Service vulnerability
golang.org/x/net/http2 Denial of Service vulnerability
CVE-2022-23451High· 8.1Barbican authorization flaw before v14.0.0
Barbican authorization flaw before v14.0.0
CVE-2022-38369High· 8.8Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue.
Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue.
GO-2022-0965NoneUnbounded recursion in JSON parsing in k8s.io/apimachinery
Unbounded recursion in JSON parsing in k8s.io/apimachinery
CVE-2022-2806Medium· 5.5sosreport Exposure of Sensitive Information vulnerability
sosreport Exposure of Sensitive Information vulnerability
CVE-2022-23452Medium· 4.9openstack-barbican Denial of Service vulnerability
openstack-barbican Denial of Service vulnerability
CVE-2022-31677Medium· 4.9Pinniped Supervisor Insufficient Session Expiration vulnerability
Pinniped Supervisor Insufficient Session Expiration vulnerability
CVE-2022-36046Medium· 5.3Next.js is a React framework that can provide building blocks to create web applications. All of the following must be true to be affecte…
Next.js is a React framework that can provide building blocks to create web applications. All of the following must be true to be affected by this CVE: Next.js version 12.2.3, Node.js version above v15.0.0 being used with strict `unhandl…
CVE-2022-34668Critical· 9.8PoCNVFLARE unsafe deserialization due to Pickle
NVFLARE unsafe deserialization due to Pickle
CVE-2022-36055Medium· 6.5Helm Vulnerable to denial of service through string value parsing
Helm Vulnerable to denial of service through string value parsing