‼ CVE-2023-25801 ‼
📖 Read
via "National Vulnerability Database".
TensorFlow is an open source machine learning platform. Prior to versions 2.12.0 and 2.11.1, `nn_ops.fractional_avg_pool_v2` and `nn_ops.fractional_max_pool_v2` require the first and fourth elements of their parameter `pooling_ratio` to be equal to 1.0, as pooling on batch and channel dimensions is not supported. A fix is included in TensorFlow 2.12.0 and 2.11.1.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25664 ‼
📖 Read
via "National Vulnerability Database".
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, there is a heap buffer overflow in TAvgPoolGrad. A fix is included in TensorFlow 2.12.0 and 2.11.1.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25673 ‼
📖 Read
via "National Vulnerability Database".
TensorFlow is an open source platform for machine learning. Versions prior to 2.12.0 and 2.11.1 have a Floating Point Exception in TensorListSplit with XLA. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25658 ‼
📖 Read
via "National Vulnerability Database".
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, an out of bounds read is in GRUBlockCellGrad. A fix is included in TensorFlow 2.12.0 and 2.11.1.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25662 ‼
📖 Read
via "National Vulnerability Database".
TensorFlow is an open source platform for machine learning. Versions prior to 2.12.0 and 2.11.1 are vulnerable to integer overflow in EditDistance. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25670 ‼
📖 Read
via "National Vulnerability Database".
TensorFlow is an open source platform for machine learning. Versions prior to 2.12.0 and 2.11.1 have a null point error in QuantizedMatMulWithBiasAndDequantize with MKL enabled. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-28437 ‼
📖 Read
via "National Vulnerability Database".
Dataease is an open source data visualization and analysis tool. The blacklist for SQL injection protection is missing entries. This vulnerability has been fixed in version 1.18.5. There are no known workarounds.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25660 ‼
📖 Read
via "National Vulnerability Database".
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, when the parameter `summarize` of `tf.raw_ops.Print` is zero, the new method `SummarizeArray<bool>` will reference to a nullptr, leading to a seg fault. A fix is included in TensorFlow version 2.12 and version 2.11.1.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25663 ‼
📖 Read
via "National Vulnerability Database".
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, when `ctx->step_containter()` is a null ptr, the Lookup function will be executed with a null pointer. A fix is included in TensorFlow 2.12.0 and 2.11.1.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25659 ‼
📖 Read
via "National Vulnerability Database".
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, if the parameter `indices` for `DynamicStitch` does not match the shape of the parameter `data`, it can trigger an stack OOB read. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25672 ‼
📖 Read
via "National Vulnerability Database".
TensorFlow is an open source platform for machine learning. The function `tf.raw_ops.LookupTableImportV2` cannot handle scalars in the `values` parameter and gives an NPE. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25666 ‼
📖 Read
via "National Vulnerability Database".
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, there is a floating point exception in AudioSpectrogram. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25671 ‼
📖 Read
via "National Vulnerability Database".
TensorFlow is an open source platform for machine learning. There is out-of-bounds access due to mismatched integer type sizes. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25674 ‼
📖 Read
via "National Vulnerability Database".
TensorFlow is an open source machine learning platform. Versions prior to 2.12.0 and 2.11.1 have a null pointer error in RandomShuffle with XLA enabled. A fix is included in TensorFlow 2.12.0 and 2.11.1.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25669 ‼
📖 Read
via "National Vulnerability Database".
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, if the stride and window size are not positive for `tf.raw_ops.AvgPoolGrad`, it can give a floating point exception. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-27579 ‼
📖 Read
via "National Vulnerability Database".
TensorFlow is an end-to-end open source platform for machine learning. Constructing a tflite model with a paramater `filter_input_channel` of less than 1 gives a FPE. This issue has been patched in version 2.12. TensorFlow will also cherrypick the fix commit on TensorFlow 2.11.1.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25676 ‼
📖 Read
via "National Vulnerability Database".
TensorFlow is an open source machine learning platform. When running versions prior to 2.12.0 and 2.11.1 with XLA, `tf.raw_ops.ParallelConcat` segfaults with a nullptr dereference when given a parameter `shape` with rank that is not greater than zero. A fix is available in TensorFlow 2.12.0 and 2.11.1.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25668 ‼
📖 Read
via "National Vulnerability Database".
TensorFlow is an open source platform for machine learning. Attackers using Tensorflow prior to 2.12.0 or 2.11.1 can access heap memory which is not in the control of user, leading to a crash or remote code execution. The fix will be included in TensorFlow version 2.12.0 and will also cherrypick this commit on TensorFlow version 2.11.1.📖 Read
via "National Vulnerability Database".
❤1🔥1
‼ CVE-2023-1629 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability classified as critical was found in Jianming Antivirus 16.2.2022.418. Affected by this vulnerability is an unknown functionality in the library kvcore.sys of the component IoControlCode Handler. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-224011.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-1627 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability was found in Jianming Antivirus 16.2.2022.418. It has been rated as problematic. This issue affects some unknown processing in the library kvcore.sys of the component IoControlCode Handler. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The identifier VDB-224009 was assigned to this vulnerability.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-1631 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability, which was classified as problematic, was found in Jianming Antivirus 16.2.2022.418. This affects an unknown part in the library kvcore.sys of the component IoControlCode Handler. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The identifier VDB-224013 was assigned to this vulnerability.📖 Read
via "National Vulnerability Database".