Tagged “pip”
CVEs tagged pip, newest first.
4668 CVEsRSS
CVE-2022-36026Medium· 5.9TensorFlow vulnerable to `CHECK` fail in `QuantizeAndDequantizeV3`
TensorFlow vulnerable to `CHECK` fail in `QuantizeAndDequantizeV3`
CVE-2022-35985Medium· 5.9TensorFlow vulnerable to `CHECK` fail in `LRNGrad`
TensorFlow vulnerable to `CHECK` fail in `LRNGrad`
CVE-2022-35935Medium· 5.9TensorFlow vulnerable to `CHECK` failure in `SobolSample` via missing validation
TensorFlow vulnerable to `CHECK` failure in `SobolSample` via missing validation
CVE-2022-35963Medium· 5.9TensorFlow vulnerable to `CHECK` failures in `FractionalAvgPoolGrad`
TensorFlow vulnerable to `CHECK` failures in `FractionalAvgPoolGrad`
CVE-2022-36013Medium· 5.9TensorFlow vulnerable to null-dereference in `mlir::tfg::GraphDefImporter::ConvertNodeDef`
TensorFlow vulnerable to null-dereference in `mlir::tfg::GraphDefImporter::ConvertNodeDef`
CVE-2022-36014Medium· 5.9TensorFlow vulnerable to null-dereference in `mlir::tfg::TFOp::nameAttr`
TensorFlow vulnerable to null-dereference in `mlir::tfg::TFOp::nameAttr`
CVE-2022-36027Medium· 5.9TensorFlow segfault TFLite converter on per-channel quantized transposed convolutions
TensorFlow segfault TFLite converter on per-channel quantized transposed convolutions
CVE-2022-35973Medium· 5.9TensorFlow vulnerable to segfault in `QuantizedMatMul`
TensorFlow vulnerable to segfault in `QuantizedMatMul`
CVE-2022-35966Medium· 5.9TensorFlow vulnerable to segfault in `QuantizedAvgPool`
TensorFlow vulnerable to segfault in `QuantizedAvgPool`
CVE-2022-35972Medium· 5.9TensorFlow vulnerable to segfault in `QuantizedBiasAdd`
TensorFlow vulnerable to segfault in `QuantizedBiasAdd`
CVE-2022-35982Medium· 5.9TensorFlow vulnerable to segfault in `SparseBincount`
TensorFlow vulnerable to segfault in `SparseBincount`
CVE-2022-35999Medium· 5.9TensorFlow vulnerable to `CHECK` fail in `Conv2DBackpropInput`
TensorFlow vulnerable to `CHECK` fail in `Conv2DBackpropInput`
CVE-2022-35968Medium· 5.9TensorFlow vulnerable to `CHECK` fail in `AvgPoolGrad`
TensorFlow vulnerable to `CHECK` fail in `AvgPoolGrad`
CVE-2022-37189High· 7.5MEI2Volpiano is vulnerable to XML External Entity (XXE), leading to a Denial of Service (DoS)
MEI2Volpiano is vulnerable to XML External Entity (XXE), leading to a Denial of Service (DoS)
CVE-2022-23451High· 8.1Barbican authorization flaw before v14.0.0
Barbican authorization flaw before v14.0.0
CVE-2022-38369High· 8.8Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue.
Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue.
CVE-2022-2806Medium· 5.5sosreport Exposure of Sensitive Information vulnerability
sosreport Exposure of Sensitive Information vulnerability
CVE-2022-23452Medium· 4.9openstack-barbican Denial of Service vulnerability
openstack-barbican Denial of Service vulnerability
CVE-2022-36046Medium· 5.3Next.js is a React framework that can provide building blocks to create web applications. All of the following must be true to be affecte…
Next.js is a React framework that can provide building blocks to create web applications. All of the following must be true to be affected by this CVE: Next.js version 12.2.3, Node.js version above v15.0.0 being used with strict `unhandl…
CVE-2022-34668Critical· 9.8PoCNVFLARE unsafe deserialization due to Pickle
NVFLARE unsafe deserialization due to Pickle
CVE-2022-25304High· 7.5Uncontrolled Resource Consumption in asyncua and opcua
Uncontrolled Resource Consumption in asyncua and opcua
CVE-2022-1930Medium· 5.9Regular expression denial of service in eth-account
Regular expression denial of service in eth-account
CVE-2022-38362High· 8.8Remote code execution in Apache Airflow Docker's Provider
Remote code execution in Apache Airflow Docker's Provider
CVE-2022-2822Low· 3.7OctoPrint does not have rate limiting on the login page
OctoPrint does not have rate limiting on the login page
CVE-2021-32862Medium· 5.4nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths
nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths
CVE-2022-35920High· 8.3sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
CVE-2022-37394Low· 3.3OpenStack Nova Changing vnic_type breaks compute service restart
OpenStack Nova Changing vnic_type breaks compute service restart
CVE-2022-34558Critical· 9.8WMAgent v1.3.3rc2 and 1.3.3rc1, reqmgr 2 1.4.1rc5 and 1.4.0rc2, reqmon 1.4.1rc5, and global-workqueue 1.4.1rc5 allows attackers to execut…
WMAgent v1.3.3rc2 and 1.3.3rc1, reqmgr 2 1.4.1rc5 and 1.4.0rc2, reqmon 1.4.1rc5, and global-workqueue 1.4.1rc5 allows attackers to execute arbitrary code via a crafted dbs-client package.
CVE-2022-2514Medium· 6.1Fava time and filter parameters vulnerable to reflected Cross-site Scripting
Fava time and filter parameters vulnerable to reflected Cross-site Scripting
CVE-2022-24294High· 7.5Apache MXNet vulnerable to potential denial-of-service by excessive resource consumption
Apache MXNet vulnerable to potential denial-of-service by excessive resource consumption