目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1000 CNY

100.0%

tensorflow 厂商漏洞列表 / CVE 中文分析 403

tensorflow 厂商相关 403 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。

TensorFlow 是 Google 开发的开源机器学习框架,广泛用于构建和训练深度学习模型。其历史漏洞多涉及内存安全缺陷、拒绝服务及越权访问,部分源于底层 C++ 组件的缓冲区溢出或逻辑错误。近期关注点在于模型权重泄露及对抗样本攻击风险。尽管核心库安全性较高,但集成环境中的配置失误常导致数据暴露。建议及时更新版本并遵循最小权限原则,以缓解潜在的安全威胁。

上位製品 tensorflow: tensorflow keras
CVE IDタイトルCVSS深刻度公開日
CVE-2026-2492 TensorFlow HDF5 Library Uncontrolled Search Path Element Local Privilege Escalation Vulnerability — TensorFlowCWE-427 7.8AIHighAI2026-02-20
CVE-2023-33976 TensorFlow segfault in array_ops.upper_bound — tensorflowCWE-190 7.5 High2024-07-30
CVE-2024-3660 Arbitrary code injection vulnerability in Keras framework < 2.13 — keras 9.8AICriticalAI2024-04-16
CVE-2023-25661 Denial of Service in TensorFlow — tensorflowCWE-20 6.5 Medium2023-03-27
CVE-2023-25660 TensorFlow vulnerable to seg fault in `tf.raw_ops.Print` — tensorflowCWE-476 7.5 High2023-03-24
CVE-2023-25659 TensorFlow vulnerable to Out-of-Bounds Read in DynamicStitch — tensorflowCWE-125 7.5 High2023-03-24
CVE-2023-25658 TensorFlow vulnerable to Out-of-Bounds Read in GRUBlockCellGrad — tensorflowCWE-125 7.5 High2023-03-24
CVE-2023-25662 TensorFlow vulnerable to integer overflow in EditDistance — tensorflowCWE-190 7.5 High2023-03-24
CVE-2023-25663 TensorFlow has Null Pointer Error in TensorArrayConcatV2 — tensorflowCWE-476 7.5 High2023-03-24
CVE-2023-25664 TensorFlow vulnerable to Heap Buffer Overflow in AvgPoolGrad — tensorflowCWE-120 7.5 High2023-03-24
CVE-2023-25667 TensorFlow vulnerable to segfault when opening multiframe gif — tensorflowCWE-190 6.5 Medium2023-03-24
CVE-2023-25666 TensorFlow has Floating Point Exception in AudioSpectrogram — tensorflowCWE-697 7.5 High2023-03-24
CVE-2023-25665 TensorFlow has Null Pointer Error in SparseSparseMaximum — tensorflowCWE-476 7.5 High2023-03-24
CVE-2023-25668 TensorFlow vulnerable to heap out-of-buffer read in the QuantizeAndDequantize operation — tensorflowCWE-122 9.8 Critical2023-03-24
CVE-2023-25669 TensorFlow has Floating Point Exception in AvgPoolGrad with XLA — tensorflowCWE-697 7.5 High2023-03-24
CVE-2023-25670 TensorFlow has Null Pointer Error in QuantizedMatMulWithBiasAndDequantize — tensorflowCWE-476 7.5 High2023-03-24
CVE-2023-25671 TensorFlow has segmentation fault in tfg-translate — tensorflowCWE-787 7.5 High2023-03-24
CVE-2023-25672 TensorFlow has Null Pointer Error in LookupTableImportV2 — tensorflowCWE-476 7.5 High2023-03-24
CVE-2023-25673 TensorFlow has Floating Point Exception in TensorListSplit with XLA — tensorflowCWE-697 7.5 High2023-03-24
CVE-2023-25674 TensorFlow has Null Pointer Error in RandomShuffle with XLA enable — tensorflowCWE-476 7.5 High2023-03-24
CVE-2023-25675 TensorFlow has Segfault in Bincount with XLA — tensorflowCWE-697 7.5 High2023-03-24
CVE-2023-25676 TensorFlow has null dereference on ParallelConcat with XLA — tensorflowCWE-476 7.5 High2023-03-24
CVE-2023-25801 TensorFlow has double free in Fractional(Max/Avg)Pool — tensorflowCWE-415 8.0 High2023-03-24
CVE-2023-27579 TensorFlow has Floating Point Exception in TFLite in conv kernel — tensorflowCWE-697 7.5 High2023-03-24
CVE-2022-41910 Heap out of bounds read in `QuantizeAndDequantizeV2` in Tensorflow — tensorflowCWE-125 4.8 Medium2022-12-06
CVE-2022-41902 Out of bounds write in grappler in Tensorflow — tensorflowCWE-787 7.1 High2022-12-06
CVE-2022-41890 `CHECK` fail in `BCast` overflow in Tensorflow — tensorflowCWE-704 4.8 Medium2022-11-18
CVE-2022-41888 Unckecked rank size in `tf.image.generate_bounding_box_proposals` in Tensorflow — tensorflowCWE-20 4.8 Medium2022-11-18
CVE-2022-41889 Segfault via invalid attributes in `pywrap_tfe_src.cc` in Tensorflow — tensorflowCWE-476 5.5 Medium2022-11-18
CVE-2022-41887 Overflow in `tf.keras.losses.poisson` in Tensorflow — tensorflowCWE-131 4.8 Medium2022-11-18

本页汇总了 tensorflow 厂商截至目前公开的全部 403 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。