目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1000 CNY

100.0%

tensorflow 厂商漏洞列表 / CVE 中文分析 403

tensorflow 厂商相关 403 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。

TensorFlow 是 Google 开发的开源机器学习框架,广泛用于构建和训练深度学习模型。其历史漏洞多涉及内存安全缺陷、拒绝服务及越权访问,部分源于底层 C++ 组件的缓冲区溢出或逻辑错误。近期关注点在于模型权重泄露及对抗样本攻击风险。尽管核心库安全性较高,但集成环境中的配置失误常导致数据暴露。建议及时更新版本并遵循最小权限原则,以缓解潜在的安全威胁。

上位製品 tensorflow: tensorflow keras
CVE IDタイトルCVSS深刻度公開日
CVE-2021-41202 Overflow/crash in `tf.range` — tensorflowCWE-681 5.5 Medium2021-11-05
CVE-2021-41209 FPE in convolutions with zero size filters — tensorflowCWE-369 5.5 Medium2021-11-05
CVE-2021-41203 Missing validation during checkpoint loading — tensorflowCWE-345 7.8 High2021-11-05
CVE-2021-41215 Null pointer exception in `DeserializeSparse` — tensorflowCWE-476 5.5 Medium2021-11-05
CVE-2021-41217 Null pointer exception when `Exit` node is not preceded by `Enter` op — tensorflowCWE-476 5.5 Medium2021-11-05
CVE-2021-41219 Undefined behavior via `nullptr` reference binding in sparse matrix multiplication — tensorflowCWE-824 7.8 High2021-11-05
CVE-2021-41214 Reference binding to `nullptr` in `tf.ragged.cross` — tensorflowCWE-824 7.8 High2021-11-05
CVE-2021-41204 Segfault while copying constant resource tensor — tensorflowCWE-824 5.5 Medium2021-11-05
CVE-2021-41226 Heap OOB read in `SparseBinCount` — tensorflowCWE-125 7.1 High2021-11-05
CVE-2021-41223 Heap OOB read in `FusedBatchNorm` kernels — tensorflowCWE-125 7.1 High2021-11-05
CVE-2021-41224 `SparseFillEmptyRows` heap OOB read — tensorflowCWE-125 7.1 High2021-11-05
CVE-2021-41212 Heap OOB read in `tf.ragged.cross` — tensorflowCWE-125 7.1 High2021-11-05
CVE-2021-41211 Heap OOB read in shape inference for `QuantizeV2` — tensorflowCWE-125 7.1 High2021-11-05
CVE-2021-41205 Heap OOB read in all `tf.raw_ops.QuantizeAndDequantizeV*` ops — tensorflowCWE-125 7.1 High2021-11-05
CVE-2021-41210 Heap OOB read in `tf.raw_ops.SparseCountSparseOutput` — tensorflowCWE-125 7.1 High2021-11-05
CVE-2021-41201 Unitialized access in `EinsumHelper::ParseEquation` — tensorflowCWE-824 7.8 High2021-11-05
CVE-2021-41200 Incomplete validation in `tf.summary.create_file_writer` — tensorflowCWE-617 5.5 Medium2021-11-05
CVE-2021-41197 Crashes due to overflow and `CHECK`-fail in ops with large tensor shapes — tensorflowCWE-190 5.5 Medium2021-11-05
CVE-2021-41198 Overflow/crash in `tf.tile` when tiling tensor is large — tensorflowCWE-190 5.5 Medium2021-11-05
CVE-2021-41199 Overflow/crash in `tf.image.resize` when size is large — tensorflowCWE-190 5.5 Medium2021-11-05
CVE-2021-41196 Crash in `max_pool3d` when size argument is 0 or negative — tensorflowCWE-191 5.5 Medium2021-11-05
CVE-2021-41195 Crash in `tf.math.segment_*` operations — tensorflowCWE-190 5.5 Medium2021-11-05
CVE-2021-37690 Use after free and segfault in shape inference functions in TensorFlow — tensorflowCWE-416 6.6 Medium2021-08-12
CVE-2021-37678 Arbitrary code execution due to YAML deserialization — tensorflowCWE-502 9.3 Critical2021-08-12
CVE-2021-37692 Segfault on strings tensors with mistmatched dimensions in TensorFlow — tensorflowCWE-20 5.5 Medium2021-08-12
CVE-2021-37669 Crash in NMS ops caused by integer conversion to unsigned in TensorFlow — tensorflowCWE-681 5.5 Medium2021-08-12
CVE-2021-37673 `CHECK`-fail in `MapStage` in TensorFlow — tensorflowCWE-20 5.5 Medium2021-08-12
CVE-2021-37663 Incomplete validation in `QuantizeV2` in TensorFlow — tensorflowCWE-20 7.8 High2021-08-12
CVE-2021-37682 Use of unitialized value in TensorFlow Lite — tensorflowCWE-908 4.4 Medium2021-08-12
CVE-2021-37674 Incomplete validation in `MaxPoolGrad` in TensorFlow — tensorflowCWE-20 5.5 Medium2021-08-12

本页汇总了 tensorflow 厂商截至目前公开的全部 403 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。