Latest CVE Feed
-
5.5
MEDIUMCVE-2022-29358
epub2txt2 v2.04 was discovered to contain an integer overflow via the function bug in _parse_special_tag at sxmlc.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted XML file.... Read more
Affected Products : epub2txt2- Published: May. 25, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-53146
In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent a potential integer overflow If the tag length is >= U32_MAX - 3 then the "length + 4" addition can result in an integer overflow. Address this by splitting the decoding i... Read more
Affected Products : linux_kernel- Published: Dec. 24, 2024
- Modified: Jan. 07, 2025
-
5.5
MEDIUMCVE-2022-29204
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.UnsortedSegmentJoin` does not fully validate the input arguments. This results in a `CHECK`-failure which can b... Read more
Affected Products : tensorflow- Published: May. 20, 2022
- Modified: Jun. 25, 2025
-
5.5
MEDIUMCVE-2022-29212
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, certain TFLite models that were created using TFLite model converter would crash when loaded in the TFLite interpreter. The culprit is that durin... Read more
Affected Products : tensorflow- Published: May. 21, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-29210
TensorFlow is an open source platform for machine learning. In version 2.8.0, the `TensorKey` hash function used total estimated `AllocatedBytes()`, which (a) is an estimate per tensor, and (b) is a very poor hash function for constants (e.g. `int32_t`). ... Read more
Affected Products : tensorflow- Published: May. 21, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-29202
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.ragged.constant` does not fully validate the input arguments. This results in a denial of service by consuming all avai... Read more
Affected Products : tensorflow- Published: May. 20, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-29196
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.Conv3DBackpropFilterV2` does not fully validate the input arguments. This results in a `CHECK`-failure which ca... Read more
Affected Products : tensorflow- Published: May. 20, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-29191
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.GetSessionTensor` does not fully validate the input arguments. This results in a `CHECK`-failure which can be u... Read more
Affected Products : tensorflow- Published: May. 20, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-29195
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.StagePeek` does not fully validate the input arguments. This results in a `CHECK`-failure which can be used to ... Read more
Affected Products : tensorflow- Published: May. 20, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-29192
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.QuantizeAndDequantizeV4Grad` does not fully validate the input arguments. This results in a `CHECK`-failure whi... Read more
Affected Products : tensorflow- Published: May. 20, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-29201
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.QuantizedConv2D` does not fully validate the input arguments. In this case, references get bound to `nullptr` f... Read more
Affected Products : tensorflow- Published: May. 20, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-29197
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.UnsortedSegmentJoin` does not fully validate the input arguments. This results in a `CHECK`-failure which can b... Read more
Affected Products : tensorflow- Published: May. 20, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-29140
Windows Print Spooler Information Disclosure Vulnerability... Read more
Affected Products : windows_10 windows_server_2016 windows_server_2019 windows_server windows_10_1607 windows_10_1809 windows_10_20h2 windows_10_21h2 windows_server_2022 windows_11_21h2 +5 more products- Published: May. 10, 2022
- Modified: Jan. 02, 2025
-
5.5
MEDIUM- Published: May. 10, 2022
- Modified: Jan. 02, 2025
-
5.5
MEDIUMCVE-2024-53145
In the Linux kernel, the following vulnerability has been resolved: um: Fix potential integer overflow during physmem setup This issue happens when the real map size is greater than LONG_MAX, which can be easily triggered on UML/i386.... Read more
Affected Products : linux_kernel- Published: Dec. 24, 2024
- Modified: Jan. 07, 2025
-
5.5
MEDIUMCVE-2022-29199
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.LoadAndRemapMatrix does not fully validate the input arguments. This results in a `CHECK`-failure which can be ... Read more
Affected Products : tensorflow- Published: May. 20, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-29102
Windows Failover Cluster Information Disclosure Vulnerability... Read more
- Published: May. 10, 2022
- Modified: Jan. 02, 2025
-
5.5
MEDIUMCVE-2022-29114
Windows Print Spooler Information Disclosure Vulnerability... Read more
Affected Products : windows_10 windows_8.1 windows_rt_8.1 windows_server_2012 windows_server_2016 windows_server_2019 windows_server windows_10_1607 windows_10_1809 windows_10_20h2 +10 more products- Published: May. 10, 2022
- Modified: Jan. 02, 2025
-
5.5
MEDIUMCVE-2022-29203
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.SpaceToBatchND` (in all backends such as XLA and handwritten kernels) is vulnerable to an integer overflow: The... Read more
Affected Products : tensorflow- Published: May. 20, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-53137
In the Linux kernel, the following vulnerability has been resolved: ARM: fix cacheflush with PAN It seems that the cacheflush syscall got broken when PAN for LPAE was implemented. User access was not enabled around the cache maintenance instructions, ca... Read more
Affected Products : linux_kernel- Published: Dec. 04, 2024
- Modified: Dec. 11, 2024