tensorflow has 419 CVEs on record between 2019 and 2024. The median CVSS is 5.5 (medium), with 6 rated critical. None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.5
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Products
- tensorflow 419
Worst active — by depth score
CVE-2021-37678Critical· 9.3Arbitrary code execution due to YAML deserialization63CVE-2022-21728High· 8.1Out of bounds read in Tensorflow57CVE-2021-41208Critical· 9.3Incomplete validation in boosted trees code51CVE-2020-26269Critical· 9.1TensorFlow vulnerable to heap out of bounds read in filesystem glob matching50CVE-2020-15206Critical· 9.0Denial of Service in Tensorflow50
tensorflow vulnerabilities
CVEs affecting tensorflow, newest first. Open any entry for full detail, references, and exploit status.
419 CVEsRSS
CVE-2021-37651High· 7.1Heap buffer overflow in `FractionalAvgPoolGrad`
Heap buffer overflow in `FractionalAvgPoolGrad`
CVE-2021-37636Medium· 5.5Floating point exception in `SparseDenseCwiseDiv`
Floating point exception in `SparseDenseCwiseDiv`
CVE-2021-37646Medium· 5.5Bad alloc in `StringNGrams` caused by integer conversion
Bad alloc in `StringNGrams` caused by integer conversion
CVE-2021-37639High· 8.4Null pointer dereference and heap OOB read in operations restoring tensors
Null pointer dereference and heap OOB read in operations restoring tensors
CVE-2021-37661Medium· 5.5Crash caused by integer conversion to unsigned
Crash caused by integer conversion to unsigned
CVE-2021-37679High· 7.1Heap OOB in nested `tf.map_fn` with `RaggedTensor`s
Heap OOB in nested `tf.map_fn` with `RaggedTensor`s
CVE-2021-37663High· 7.8Incomplete validation in `QuantizeV2`
Incomplete validation in `QuantizeV2`
CVE-2021-37643High· 7.7Null pointer dereference in `MatrixDiagPartOp`
Null pointer dereference in `MatrixDiagPartOp`
CVE-2021-37650High· 7.8Segfault and heap buffer overflow in `{Experimental,}DatasetToTFRecord`
Segfault and heap buffer overflow in `{Experimental,}DatasetToTFRecord`
CVE-2021-37662High· 7.1Reference binding to nullptr in boosted trees
Reference binding to nullptr in boosted trees
CVE-2021-37692Medium· 5.5Segfault on strings tensors with mistmatched dimensions, due to Go code
Segfault on strings tensors with mistmatched dimensions, due to Go code
CVE-2021-37660Medium· 5.5Division by 0 in inplace operations
Division by 0 in inplace operations
CVE-2021-37642Medium· 5.5Division by 0 in `ResourceScatterDiv`
Division by 0 in `ResourceScatterDiv`
CVE-2021-37635High· 7.3Heap out of bounds access in sparse reduction operations
Heap out of bounds access in sparse reduction operations
CVE-2021-37680Medium· 5.5Division by zero in TFLite
Division by zero in TFLite
CVE-2021-37637High· 7.7Null pointer dereference in `CompressElement`
Null pointer dereference in `CompressElement`
CVE-2021-37647High· 7.7Null pointer dereference in `SparseTensorSliceDataset`
Null pointer dereference in `SparseTensorSliceDataset`
CVE-2021-37685Medium· 5.5Heap OOB in TFLite
Heap OOB in TFLite
CVE-2021-37645Medium· 5.5Integer overflow due to conversion to unsigned
Integer overflow due to conversion to unsigned
CVE-2021-37641High· 7.1Heap OOB in `RaggedGather`
Heap OOB in `RaggedGather`
CVE-2021-37675Medium· 5.5Division by 0 in most convolution operators
Division by 0 in most convolution operators
CVE-2021-37670Medium· 5.5Heap OOB in `UpperBound` and `LowerBound`
Heap OOB in `UpperBound` and `LowerBound`
CVE-2021-37640Medium· 5.5Integer division by 0 in sparse reshaping
Integer division by 0 in sparse reshaping
CVE-2021-37681High· 7.8NPE in TFLite
NPE in TFLite
CVE-2021-37674Medium· 5.5Incomplete validation in `MaxPoolGrad`
Incomplete validation in `MaxPoolGrad`
CVE-2021-37655High· 7.3Heap OOB in `ResourceScatterUpdate`
Heap OOB in `ResourceScatterUpdate`
CVE-2021-37658High· 7.1Reference binding to nullptr in `MatrixSetDiagV*` ops
Reference binding to nullptr in `MatrixSetDiagV*` ops
CVE-2021-37649High· 7.7Null pointer dereference in `UncompressElement`
Null pointer dereference in `UncompressElement`
CVE-2021-37657High· 7.1Reference binding to nullptr in `MatrixDiagV*` ops
Reference binding to nullptr in `MatrixDiagV*` ops
CVE-2021-37672Medium· 5.5Heap OOB in `SdcaOptimizerV2`
Heap OOB in `SdcaOptimizerV2`