| CVE-2023-33976CVE-2023-33976: TensorFlow is an end-to-end open source platform for machine learning. `array_ops.upper_bound` causes a segfault when… | High | < 2.12.1 | 2.12.1 | 2024-07-31 |
| CVE-2023-27579TensorFlow tflite filter_input_channel below 1 causes FPE | High | < 2.11.1 | 2.11.1 | 2023-03-25 |
| CVE-2023-25801TensorFlow fractional pooling ops accept unsupported pooling ratios | High | < 2.11.1 | 2.11.1 | 2023-03-25 |
| CVE-2023-25676TensorFlow null pointer dereference in tf.raw_ops.ParallelConcat with XLA | High | < 2.11.1 | 2.11.1 | 2023-03-25 |
| CVE-2023-25675TensorFlow segfault in tf.raw_ops.Bincount with mismatched weights under XLA | High | < 2.11.1 | 2.11.1 | 2023-03-25 |
| CVE-2023-25674TensorFlow null pointer dereference in RandomShuffle with XLA enabled | High | < 2.11.1 | 2.11.1 | 2023-03-25 |
| CVE-2023-25673TensorFlow floating point exception in TensorListSplit with XLA | High | < 2.11.1 | 2.11.1 | 2023-03-25 |
| CVE-2023-25672TensorFlow LookupTableImportV2 null pointer dereference on scalar values | High | < 2.11.1 | 2.11.1 | 2023-03-25 |
| CVE-2023-25670TensorFlow null pointer dereference in QuantizedMatMulWithBiasAndDequantize | High | < 2.11.1 | 2.11.1 | 2023-03-25 |
| CVE-2023-25669TensorFlow AvgPoolGrad floating point exception from bad stride | High | < 2.11.1 | 2.11.1 | 2023-03-25 |
| CVE-2023-25668TensorFlow heap memory access leading to crash or code execution | Critical | < 2.11.1 | 2.11.1 | 2023-03-25 |
| CVE-2023-25667TensorFlow integer overflow in frame, height, width and channel calculation | Medium | < 2.11.1 | 2.11.1 | 2023-03-25 |
| CVE-2023-25666TensorFlow floating point exception in AudioSpectrogram | High | < 2.11.1 | 2.11.1 | 2023-03-25 |
| CVE-2023-25665TensorFlow null pointer dereference in SparseSparseMaximum | High | < 2.11.1 | 2.11.1 | 2023-03-25 |
| CVE-2023-25663TensorFlow null pointer dereference in Lookup function | High | < 2.11.1 | 2.11.1 | 2023-03-25 |
| CVE-2023-25662TensorFlow integer overflow in EditDistance | High | < 2.11.1 | 2.11.1 | 2023-03-25 |
| CVE-2023-25660TensorFlow null pointer dereference in tf.raw_ops.Print | High | < 2.11.1 | 2.11.1 | 2023-03-25 |
| CVE-2023-25659TensorFlow DynamicStitch out-of-bounds read via mismatched shapes | High | < 2.11.1 | 2.11.1 | 2023-03-25 |
| CVE-2023-25658TensorFlow out-of-bounds read in GRUBlockCellGrad | High | < 2.11.1 | 2.11.1 | 2023-03-25 |
| CVE-2022-41910TensorFlow out-of-bounds read in MakeGrapplerFunctionItem via input sizes | Medium | < 2.8.4 | 2.8.4 | 2022-12-07 |
| CVE-2022-41902TensorFlow out-of-bounds memory read via MakeGrapplerFunctionItem | High | < 2.8.4 | 2.8.4 | 2022-12-07 |
| CVE-2022-41911TensorFlow tensor printing undefined behavior from invalid bool conversion | Medium | >= 2.10.0, < 2.10.1 | 2.10.1 | 2022-11-19 |
| CVE-2022-41909TensorFlow segfault in CompositeTensorVariantToComponents via invalid input | Medium | < 2.8.4 | 2.8.4 | 2022-11-19 |
| CVE-2022-41908CVE-2022-41908: TensorFlow is an open source platform for machine learning. An input `token` that is not a UTF-8 bytestring will… | Medium | < 2.8.4 | 2.8.4 | 2022-11-19 |
| CVE-2022-41907TensorFlow integer overflow in ResizeNearestNeighborGrad via large size input | Medium | < 2.8.4 | 2.8.4 | 2022-11-19 |
| CVE-2022-41901TensorFlow sparse matrix input validation flaw in tf.raw_ops.SparseMatrixNNZ | Medium | < 2.8.4 | 2.8.4 | 2022-11-19 |
| CVE-2022-41900TensorFlow heap access via FractionalMax(AVG)Pool illegal ratio | High | < 2.8.4 | 2.8.4 | 2022-11-19 |
| CVE-2022-41899TensorFlow SdcaOptimizer assertion failure from rank-invalid dense_features | Medium | < 2.8.4 | 2.8.4 | 2022-11-19 |
| CVE-2022-41898TensorFlow crash in SparseFillEmptyRowsGrad with empty inputs | Medium | < 2.8.4 | 2.8.4 | 2022-11-19 |
| CVE-2022-41897TensorFlow crash in FractionMaxPoolGrad with oversized pooling sequence inputs | Medium | < 2.8.4 | 2.8.4 | 2022-11-19 |
| CVE-2022-41896TensorFlow crash in ThreadUnsafeUnigramCandidateSampler via oversized | Medium | < 2.8.4 | 2.8.4 | 2022-11-19 |
| CVE-2022-41895TensorFlow heap out-of-bounds error in MirrorPadGrad via outsize paddings input | Medium | < 2.8.4 | 2.8.4 | 2022-11-19 |
| CVE-2022-41893TensorFlow denial of service through nonscalar size in TensorListResize | Medium | < 2.8.4 | 2.8.4 | 2022-11-19 |
| CVE-2022-41891TensorFlow segmentation fault in TensorListConcat via empty element_shape | Medium | < 2.8.4 | 2.8.4 | 2022-11-19 |
| CVE-2022-41890TensorFlow crash in BCast::ToShape with input larger than int32 | Medium | < 2.8.4 | 2.8.4 | 2022-11-19 |
| CVE-2022-41889TensorFlow null pointer dereference in quantized tensor list assignment | Medium | < 2.8.4 | 2.8.4 | 2022-11-19 |
| CVE-2022-41888TensorFlow missing rank check on scores input in generate_bounding_box_proposals | Medium | < 2.8.4 | 2.8.4 | 2022-11-19 |
| CVE-2022-41887TensorFlow crash from integer overflow in tf.keras.losses.poisson | Medium | < 2.9.3 | 2.9.3 | 2022-11-19 |
| CVE-2022-41886TensorFlow buffer overflow in ImageProjectiveTransformV2 | Medium | < 2.8.4 | 2.8.4 | 2022-11-19 |
| CVE-2022-41885TensorFlow buffer overflow in tf.raw_ops.FusedResizeAndPadConv2D | Medium | < 2.7.4 | 2.7.4 | 2022-11-19 |
| CVE-2022-41884TensorFlow numpy array creation error with zero-sized shape element | Medium | < 2.8.4 | 2.8.4 | 2022-11-19 |
| CVE-2022-41880TensorFlow heap out-of-bounds read in BaseCandidateSamplerOp | Medium | >= 2.10.0, < 2.10.1 | 2.10.1 | 2022-11-19 |
| CVE-2022-41883TensorFlow crash in ops with specified input sizes when input count differs | Medium | = 2.10.0 | 2.10.1 | 2022-11-19 |
| CVE-2022-36027TensorFlow crash in converter with per-channel quantization | Medium | < 2.7.2 | 2.7.2 | 2022-09-17 |
| CVE-2022-36017TensorFlow segfault in Requantize with nonzero rank tensors | Medium | < 2.7.2 | 2.7.2 | 2022-09-17 |
| CVE-2022-36016TensorFlow CHECK failure in full type substitution from attributes | Medium | < 2.7.2 | 2.7.2 | 2022-09-17 |
| CVE-2022-36015TensorFlow crash in RangeSize when values exceed int64_t | Medium | < 2.7.2 | 2.7.2 | 2022-09-17 |
| CVE-2022-36014TensorFlow crash in nameAttr when type list attributes are null | Medium | < 2.7.2 | 2.7.2 | 2022-09-17 |
| CVE-2022-36013TensorFlow crash when converting NodeDefs without an op name | Medium | < 2.7.2 | 2.7.2 | 2022-09-17 |
| CVE-2022-36012TensorFlow crash in ConvertGenericFunctionToFunctionDef on empty attributes | Medium | < 2.7.2 | 2.7.2 | 2022-09-17 |