• 设为首页
  • 点击收藏
  • 手机版
    手机扫一扫访问
    迪恩网络手机版
  • 关注官方公众号
    微信扫一扫关注
    迪恩网络公众号

CVE漏洞

RSS
  • CVE-2022-23571
    CVE-2022-23571
    Tensorflow is an Open Source Machine Learning Framework. When decoding a tensor from protobuf, a TensorFlow process can encounter cases where a `CHECK` assertion is invalidated based on user controlle ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:214 | 回复:0
  • CVE-2022-23572
    CVE-2022-23572
    Tensorflow is an Open Source Machine Learning Framework. Under certain scenarios, TensorFlow can fail to specialize a type during shape inference. This case is covered by the `DCHECK` function however ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:209 | 回复:0
  • CVE-2022-23573
    CVE-2022-23573
    Tensorflow is an Open Source Machine Learning Framework. The implementation of `AssignOp` can result in copying uninitialized data to a new tensor. This later results in undefined behavior. The implem ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:213 | 回复:0
  • CVE-2022-23574
    CVE-2022-23574
    Tensorflow is an Open Source Machine Learning Framework. There is a typo in TensorFlow's `SpecializeType` which results in heap OOB read/write. Due to a typo, `arg` is initialized to the `i`th mut ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:216 | 回复:0
  • CVE-2022-23575
    CVE-2022-23575
    Tensorflow is an Open Source Machine Learning Framework. The implementation of `OpLevelCostEstimator::CalculateTensorSize` is vulnerable to an integer overflow if an attacker can create an operation w ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:203 | 回复:0
  • CVE-2022-23576
    CVE-2022-23576
    Tensorflow is an Open Source Machine Learning Framework. The implementation of `OpLevelCostEstimator::CalculateOutputSize` is vulnerable to an integer overflow if an attacker can create an operation w ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:203 | 回复:0
  • CVE-2022-23577
    CVE-2022-23577
    Tensorflow is an Open Source Machine Learning Framework. The implementation of `GetInitOp` is vulnerable to a crash caused by dereferencing a null pointer. The fix will be included in TensorFlow 2.8.0 ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:214 | 回复:0
  • CVE-2022-23578
    CVE-2022-23578
    Tensorflow is an Open Source Machine Learning Framework. If a graph node is invalid, TensorFlow can leak memory in the implementation of `ImmutableExecutorState::Initialize`. Here, we set `item-kernel ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:202 | 回复:0
  • CVE-2022-23579
    CVE-2022-23579
    Tensorflow is an Open Source Machine Learning Framework. The Grappler optimizer in TensorFlow can be used to cause a denial of service by altering a `SavedModel` such that `SafeToRemoveIdentity` would ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:201 | 回复:0
  • CVE-2022-23580
    CVE-2022-23580
    Tensorflow is an Open Source Machine Learning Framework. During shape inference, TensorFlow can allocate a large vector based on a value from a tensor controlled by the user. The fix will be included ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:191 | 回复:0
  • CVE-2022-23581
    CVE-2022-23581
    Tensorflow is an Open Source Machine Learning Framework. The Grappler optimizer in TensorFlow can be used to cause a denial of service by altering a `SavedModel` such that `IsSimplifiableReshape` woul ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:193 | 回复:0
  • CVE-2022-23582
    CVE-2022-23582
    Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a denial of service by altering a `SavedModel` such that `TensorByteSize` would trigger `CHECK` failures. `TensorSha ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:194 | 回复:0
  • CVE-2022-23583
    CVE-2022-23583
    Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a denial of service by altering a `SavedModel` such that any binary op would trigger `CHECK` failures. This occurs w ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:194 | 回复:0
  • CVE-2022-23584
    CVE-2022-23584
    Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a use after free behavior when decoding PNG images. After `png::CommonFreeDecode(decode)` gets called, the values of ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:211 | 回复:0
  • CVE-2022-23585
    CVE-2022-23585
    Tensorflow is an Open Source Machine Learning Framework. When decoding PNG images TensorFlow can produce a memory leak if the image is invalid. After calling `png::CommonInitDecode(..., decode)`, the ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:196 | 回复:0
  • CVE-2022-23586
    CVE-2022-23586
    Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a denial of service by altering a `SavedModel` such that assertions in `function.cc` would be falsified and crash th ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:239 | 回复:0
  • CVE-2022-23587
    CVE-2022-23587
    Tensorflow is an Open Source Machine Learning Framework. Under certain scenarios, Grappler component of TensorFlow is vulnerable to an integer overflow during cost estimation for crop and resize. Sinc ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:216 | 回复:0
  • CVE-2022-23588
    CVE-2022-23588
    Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a denial of service by altering a `SavedModel` such that Grappler optimizer would attempt to build a tensor using a ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:207 | 回复:0
  • CVE-2022-23589
    CVE-2022-23589
    Tensorflow is an Open Source Machine Learning Framework. Under certain scenarios, Grappler component of TensorFlow can trigger a null pointer dereference. There are 2 places where this can occur, for ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:205 | 回复:0
  • CVE-2022-23590
    CVE-2022-23590
    Tensorflow is an Open Source Machine Learning Framework. A `GraphDef` from a TensorFlow `SavedModel` can be maliciously altered to cause a TensorFlow process to crash due to encountering a `StatusOr` ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:198 | 回复:0
  • CVE-2022-23591
    CVE-2022-23591
    Tensorflow is an Open Source Machine Learning Framework. The `GraphDef` format in TensorFlow does not allow self recursive functions. The runtime assumes that this invariant is satisfied. However, a ` ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:212 | 回复:0
  • CVE-2022-23592
    CVE-2022-23592
    Tensorflow is an Open Source Machine Learning Framework. TensorFlow's type inference can cause a heap out of bounds read as the bounds checking is done in a `DCHECK` (which is a no-op during produ ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:186 | 回复:0
  • CVE-2022-23593
    CVE-2022-23593
    Tensorflow is an Open Source Machine Learning Framework. The `simplifyBroadcast` function in the MLIR-TFRT infrastructure in TensorFlow is vulnerable to a segfault (hence, denial of service), if calle ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:200 | 回复:0
  • CVE-2022-23594
    CVE-2022-23594
    Tensorflow is an Open Source Machine Learning Framework. The TFG dialect of TensorFlow (MLIR) makes several assumptions about the incoming `GraphDef` before converting it to the MLIR-based dialect. If ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:201 | 回复:0
  • CVE-2022-23595
    CVE-2022-23595
    Tensorflow is an Open Source Machine Learning Framework. When building an XLA compilation cache, if default settings are used, TensorFlow triggers a null pointer dereference. In the default scenario, ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:187 | 回复:0
  • CVE-2022-23600
    CVE-2022-23600
    fleet is an open source device management, built on osquery. Versions prior to 4.9.1 expose a limited ability to spoof SAML authentication with missing audience verification. This impacts deployments ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:169 | 回复:0
  • CVE-2022-23605
    CVE-2022-23605
    Wire webapp is a web client for the wire messaging protocol. In versions prior to 2022-01-27-production.0 expired ephemeral messages were not reliably removed from local chat history of Wire Webapp. I ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:171 | 回复:0
  • CVE-2022-23609
    CVE-2022-23609
    iTunesRPC-Remastered is a Discord Rich Presence for iTunes on Windows utility. In affected versions iTunesRPC-Remastered did not properly sanitize user input used to remove files leading to file delet ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:142 | 回复:0
  • CVE-2022-23611
    CVE-2022-23611
    iTunesRPC-Remastered is a Discord Rich Presence for iTunes on Windows utility. In affected versions iTunesRPC-Remastered did not properly sanitize image file paths leading to OS level command injectio ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:131 | 回复:0
  • CVE-2022-23614
    CVE-2022-23614
    Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions. In ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:165 | 回复:0
  • CVE-2022-23805
    CVE-2022-23805
    A security out-of-bounds read information disclosure vulnerability in Trend Micro Worry-Free Business Security Server could allow a local attacker to send garbage data to a specific named pipe and cra ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:133 | 回复:0
  • CVE-2022-23913
    CVE-2022-23913
    In Apache ActiveMQ Artemis prior to 2.20.0 or 2.19.1, an attacker could partially disrupt availability (DoS) through uncontrolled resource consumption of memory.……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:154 | 回复:0
  • CVE-2022-23946
    CVE-2022-23946
    A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon GCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerbe ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:159 | 回复:0
  • CVE-2022-23947
    CVE-2022-23947
    A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon DCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerbe ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:159 | 回复:0
  • CVE-2022-23980
    CVE-2022-23980
    Cross-Site Scripting (XSS) vulnerability discovered in Yasr – Yet Another Stars Rating WordPress plugin (versions = 2.9.9), vulnerable at parameter 'source'.……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:153 | 回复:0
  • CVE-2022-24113
    CVE-2022-24113
    Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035, Acronis Agent (Windows) ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:204 | 回复:0
  • CVE-2022-24114
    CVE-2022-24114
    Local privilege escalation due to race condition on application startup. The following products are affected: Acronis Cyber Protect Home Office (macOS) before build 39605, Acronis True Image 2021 (mac ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:172 | 回复:0
  • CVE-2022-24115
    CVE-2022-24115
    Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acronis Cyber Protect Home Office (macOS) before build 39605, Acronis True Image 2021 ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:42 | 阅读:176 | 回复:0
  • CVE-2020-5953
    CVE-2020-5953
    A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT (EFI_RUNTIME_SERVICES) pointer to call a GetVariabl ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:41 | 阅读:111 | 回复:0
  • CVE-2021-33625
    CVE-2021-33625
    An issue was discovered in Kernel 5.x (starting from 5.1) in Insyde InsydeH2O, has a SMM memory corruption vulnerability allowing a possible attacker to write fixed or predictable data to SMRAM. Explo ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 08:41 | 阅读:102 | 回复:0

关注我们

极客给你想要的成长

关注极客中国获取最新资讯

热门推荐
专题导读
阅读排行榜

扫描微信二维码

查看手机版网站

随时了解更新最新资讯

139-2527-9053

在线客服(服务时间 9:00~18:00)

在线QQ客服
地址:深圳市南山区西丽大学城创智工业园
电邮:jeky_zhao#qq.com
移动电话:139-2527-9053

Powered by 互联科技 X3.4© 2001-2213 极客世界.|Sitemap