Tagged “pip”
CVEs tagged pip, newest first.
4669 CVEsRSS
CVE-2021-32849High· 8.8PoCAn authenticated user can execute arbitrary command in Gerapy
An authenticated user can execute arbitrary command in Gerapy
CVE-2021-43837High· 8.4vault-cli contains possible RCE when reading user-defined data
vault-cli contains possible RCE when reading user-defined data
CVE-2021-43818High· 8.2lxml's HTML Cleaner allows crafted and SVG embedded scripts to pass through
lxml's HTML Cleaner allows crafted and SVG embedded scripts to pass through
CVE-2021-37941High· 7.8APM Java Agent Local Privilege Escalation
APM Java Agent Local Privilege Escalation
CVE-2021-41265High· 8.1Improper Authentication in Flask-AppBuilder
Improper Authentication in Flask-AppBuilder
CVE-2021-43811High· 7.8PoCCode injection via unsafe YAML loading
Code injection via unsafe YAML loading
CVE-2021-43781Medium· 6.4Permissions not properly checked in Invenio-Drafts-Resources
Permissions not properly checked in Invenio-Drafts-Resources
CVE-2019-14867High· 8.8Code injection in FreeIPA
Code injection in FreeIPA
CVE-2021-44227High· 8.0mailman: CSRF token bypass allows to perform CSRF attacks and admin takeover (CVE-2021-44227)
A Cross-Site Request Forgery (CSRF) attack can be performed in mailman due to a CSRF token bypass. CSRF tokens are not checked against the right type of user when performing admin operations and a token created by a regular user can be use…
CVE-2021-43775High· 8.6Arbitrary file reading vulnerability in Aim
Arbitrary file reading vulnerability in Aim
CVE-2021-41281High· 7.5Path traversal in Matrix Synapse
Path traversal in Matrix Synapse
CVE-2021-41867MediumInformation disclosure vulnerability in OnionShare
Information disclosure vulnerability in OnionShare
CVE-2021-41202Medium· 5.5Overflow/crash in `tf.range`
Overflow/crash in `tf.range`
CVE-2021-41215Medium· 5.5Null pointer exception in `DeserializeSparse`
Null pointer exception in `DeserializeSparse`
CVE-2021-41214High· 7.8Reference binding to `nullptr` in `tf.ragged.cross`
Reference binding to `nullptr` in `tf.ragged.cross`
CVE-2021-41224High· 7.1`SparseFillEmptyRows` heap OOB
`SparseFillEmptyRows` heap OOB
CVE-2021-41197Medium· 5.5Crashes due to overflow and `CHECK`-fail in ops with large tensor shapes
Crashes due to overflow and `CHECK`-fail in ops with large tensor shapes
CVE-2021-41206High· 7.0Incomplete validation of shapes in multiple TF ops
Incomplete validation of shapes in multiple TF ops
CVE-2021-41196Medium· 5.5Crash in `max_pool3d` when size argument is 0 or negative
Crash in `max_pool3d` when size argument is 0 or negative
CVE-2021-41210High· 7.1Heap OOB read in `tf.raw_ops.SparseCountSparseOutput`
Heap OOB read in `tf.raw_ops.SparseCountSparseOutput`
CVE-2021-41227Medium· 6.6Arbitrary memory read in `ImmutableConst`
Arbitrary memory read in `ImmutableConst`
CVE-2021-41201High· 7.8Unitialized access in `EinsumHelper::ParseEquation`
Unitialized access in `EinsumHelper::ParseEquation`
CVE-2021-41213Medium· 5.5Deadlock in mutually recursive `tf.function` objects
Deadlock in mutually recursive `tf.function` objects
CVE-2021-41220High· 7.8Use after free / memory leak in `CollectiveReduceV2`
Use after free / memory leak in `CollectiveReduceV2`
CVE-2021-41200Medium· 5.5Incomplete validation in `tf.summary.create_file_writer`
Incomplete validation in `tf.summary.create_file_writer`
CVE-2021-41212High· 7.1Heap OOB read in `tf.ragged.cross`
Heap OOB read in `tf.ragged.cross`
CVE-2021-41223High· 7.1Heap OOB in `FusedBatchNorm` kernels
Heap OOB in `FusedBatchNorm` kernels
CVE-2021-41211High· 7.1Heap OOB in shape inference for `QuantizeV2`
Heap OOB in shape inference for `QuantizeV2`
CVE-2021-41221High· 7.8Access to invalid memory during shape inference in `Cudnn*` ops
Access to invalid memory during shape inference in `Cudnn*` ops
CVE-2021-41195Medium· 5.5Crash in `tf.math.segment_*` operations
Crash in `tf.math.segment_*` operations