目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1000 CNY

100.0%

tensorflow 厂商漏洞列表 / CVE 中文分析 403

tensorflow 厂商相关 403 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。

TensorFlow 是 Google 开发的开源机器学习框架,广泛用于构建和训练深度学习模型。其历史漏洞多涉及内存安全缺陷、拒绝服务及越权访问,部分源于底层 C++ 组件的缓冲区溢出或逻辑错误。近期关注点在于模型权重泄露及对抗样本攻击风险。尽管核心库安全性较高,但集成环境中的配置失误常导致数据暴露。建议及时更新版本并遵循最小权限原则,以缓解潜在的安全威胁。

上位製品 tensorflow: tensorflow keras
CVE IDタイトルCVSS深刻度公開日
CVE-2022-41901 `CHECK_EQ` fail via input in `SparseMatrixNNZ` in Tensorflow — tensorflowCWE-20 4.8 Medium2022-11-18
CVE-2022-41900 FractionalMaxPool and FractionalAVGPool heap out-of-bounds acess in Tensorflow — tensorflowCWE-787 7.1 High2022-11-18
CVE-2022-41899 `CHECK` fail via inputs in `SdcaOptimizer` in Tensorflow — tensorflowCWE-20 4.8 Medium2022-11-18
CVE-2022-41898 `CHECK` fail via inputs in `SparseFillEmptyRowsGrad` in Tensorflow — tensorflowCWE-20 4.8 Medium2022-11-18
CVE-2022-41897 `FractionalMaxPoolGrad` Heap out of bounds read in Tensorflow — tensorflowCWE-125 4.8 Medium2022-11-18
CVE-2022-41896 `tf.raw_ops.Mfcc` crashes in Tensorflow — tensorflowCWE-20 4.8 Medium2022-11-18
CVE-2022-41895 `MirrorPadGrad` heap out of bounds read in Tensorflow — tensorflowCWE-125 4.8 Medium2022-11-18
CVE-2022-41894 Buffer overflow in `CONV_3D_TRANSPOSE` on TFLite — tensorflowCWE-120 7.1 High2022-11-18
CVE-2022-41893 `CHECK_EQ` fail in `tf.raw_ops.TensorListResize` in Tensorflow — tensorflowCWE-617 4.8 Medium2022-11-18
CVE-2022-41891 Segfault in `tf.raw_ops.TensorListConcat` in Tensorflow — tensorflowCWE-20 4.8 Medium2022-11-18
CVE-2022-41890 `CHECK` fail in `BCast` overflow in Tensorflow — tensorflowCWE-704 4.8 Medium2022-11-18
CVE-2022-41889 Segfault via invalid attributes in `pywrap_tfe_src.cc` in Tensorflow — tensorflowCWE-476 5.5 Medium2022-11-18
CVE-2022-41888 Unckecked rank size in `tf.image.generate_bounding_box_proposals` in Tensorflow — tensorflowCWE-20 4.8 Medium2022-11-18
CVE-2022-41887 Overflow in `tf.keras.losses.poisson` in Tensorflow — tensorflowCWE-131 4.8 Medium2022-11-18
CVE-2022-41886 Overflow in `ImageProjectiveTransformV2` in Tensorflow — tensorflowCWE-131 4.8 Medium2022-11-18
CVE-2022-41885 Overflow in `FusedResizeAndPadConv2D` in Tensorflow — tensorflowCWE-131 4.8 Medium2022-11-18
CVE-2022-41884 Seg fault in `ndarray_tensor_bridge` due to zero and large inputs in Tensorflow — tensorflowCWE-670 4.8 Medium2022-11-18
CVE-2022-41883 Out of bounds segmentation fault due to unequal op inputs in Tensorflow — tensorflowCWE-125 6.8 Medium2022-11-18
CVE-2022-41880 ThreadUnsafeUnigramCandidateSampler Heap out of bounds in Tensorflow — tensorflowCWE-125 6.8 Medium2022-11-18
CVE-2022-36015 Integer overflow in math ops in TensorFlow — tensorflowCWE-190 5.9 Medium2022-09-16
CVE-2022-36012 Assertion fail on MLIR empty edge names in TensorFlow — tensorflowCWE-617 5.9 Medium2022-09-16
CVE-2022-35996 Floating point exception in `Conv2D` in TensorFlow — tensorflowCWE-369 5.9 Medium2022-09-16
CVE-2022-36027 Segfault TFLite converter on per-channel quantized transposed convolutions in TensorFlow — tensorflowCWE-20 5.9 Medium2022-09-16
CVE-2022-36017 Segfault in `Requantize` in TensorFlow — tensorflowCWE-20 5.9 Medium2022-09-16
CVE-2022-36014 Null-dereference in `mlir::tfg::TFOp::nameAttr` in TensorFlow — tensorflowCWE-476 5.9 Medium2022-09-16
CVE-2022-36000 Null dereference on MLIR on empty function attributes in TensorFlow — tensorflowCWE-476 5.9 Medium2022-09-16
CVE-2022-36011 Null dereference on MLIR on empty function attributes in TensorFlow — tensorflowCWE-476 5.9 Medium2022-09-16
CVE-2022-36013 Null-dereference in `mlir::tfg::GraphDefImporter::ConvertNodeDef` in TensorFlow — tensorflowCWE-476 5.9 Medium2022-09-16
CVE-2022-35994 `CHECK` fail in `CollectiveGather` in TensorFlow — tensorflowCWE-617 5.9 Medium2022-09-16
CVE-2022-35993 `CHECK` fail in `SetSize` in TensorFlow — tensorflowCWE-617 5.9 Medium2022-09-16

本页汇总了 tensorflow 厂商截至目前公开的全部 403 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。