Latest CVE Feed
-
7.8
HIGHCVE-2021-41201
TensorFlow is an open source platform for machine learning. In affeced versions during execution, `EinsumHelper::ParseEquation()` is supposed to set the flags in `input_has_ellipsis` vector and `*output_has_ellipsis` boolean to indicate whether there is e... Read more
Affected Products : tensorflow- Published: Nov. 05, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-41200
TensorFlow is an open source platform for machine learning. In affected versions if `tf.summary.create_file_writer` is called with non-scalar arguments code crashes due to a `CHECK`-fail. The fix will be included in TensorFlow 2.7.0. We will also cherrypi... Read more
Affected Products : tensorflow- Published: Nov. 05, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-41199
TensorFlow is an open source platform for machine learning. In affected versions if `tf.image.resize` is called with a large input argument then the TensorFlow process will crash due to a `CHECK`-failure caused by an overflow. The number of elements in th... Read more
Affected Products : tensorflow- Published: Nov. 05, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-41198
TensorFlow is an open source platform for machine learning. In affected versions if `tf.tile` is called with a large input argument then the TensorFlow process will crash due to a `CHECK`-failure caused by an overflow. The number of elements in the output... Read more
Affected Products : tensorflow- Published: Nov. 05, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-41197
TensorFlow is an open source platform for machine learning. In affected versions TensorFlow allows tensor to have a large number of dimensions and each dimension can be as large as desired. However, the total number of elements in a tensor must fit within... Read more
Affected Products : tensorflow- Published: Nov. 05, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-41196
TensorFlow is an open source platform for machine learning. In affected versions the Keras pooling layers can trigger a segfault if the size of the pool is 0 or if a dimension is negative. This is due to the TensorFlow's implementation of pooling operatio... Read more
Affected Products : tensorflow- Published: Nov. 05, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-41195
TensorFlow is an open source platform for machine learning. In affected versions the implementation of `tf.math.segment_*` operations results in a `CHECK`-fail related abort (and denial of service) if a segment id in `segment_ids` is large. This is simila... Read more
Affected Products : tensorflow- Published: Nov. 05, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41194
FirstUseAuthenticator is a JupyterHub authenticator that helps new users set their password on their first login to JupyterHub. When JupyterHub is used with FirstUseAuthenticator, a vulnerability in versions prior to 1.0.0 allows unauthorized access to an... Read more
Affected Products : first_use_authenticator- Published: Oct. 28, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41193
wire-avs is the audio visual signaling (AVS) component of Wire, an open-source messenger. A remote format string vulnerability in versions prior to 7.1.12 allows an attacker to cause a denial of service or possibly execute arbitrary code. The issue has be... Read more
Affected Products : wire-audio_video_signaling- Published: Mar. 01, 2022
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-41192
Redash is a package for data visualization and sharing. If an admin sets up Redash versions 10.0.0 and prior without explicitly specifying the `REDASH_COOKIE_SECRET` or `REDASH_SECRET_KEY` environment variables, a default value is used for both that is th... Read more
Affected Products : redash- Published: Nov. 24, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41191
Roblox-Purchasing-Hub is an open source Roblox product purchasing hub. A security risk in versions 1.0.1 and prior allowed people who have someone's API URL to get product files without an API key. This issue is fixed in version 1.0.2. As a workaround, ad... Read more
Affected Products : roblox_purchasing_hub- Published: Oct. 27, 2021
- Modified: Nov. 21, 2024
-
5.0
MEDIUMCVE-2021-41190
The OCI Distribution Spec project defines an API protocol to facilitate and standardize the distribution of content. In the OCI Distribution Specification version 1.0.0 and prior, the Content-Type header alone was used to determine the type of document du... Read more
- Published: Nov. 17, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-41189
DSpace is an open source turnkey repository application. In version 7.0, any community or collection administrator can escalate their permission up to become system administrator. This vulnerability only exists in 7.0 and does not impact 6.x or below. Thi... Read more
Affected Products : dspace- Published: Oct. 29, 2021
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2021-41188
Shopware is open source e-commerce software. Versions prior to 5.7.6 contain a cross-site scripting vulnerability. This issue is patched in version 5.7.6. Two workarounds are available. Using the security plugin or adding a particular following config to ... Read more
Affected Products : shopware- Published: Oct. 26, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-41187
DHIS 2 is an information system for data capture, management, validation, analytics and visualization. A SQL injection security vulnerability has been found in specific versions of DHIS2. This vulnerability affects the API endpoints for /api/trackedEntity... Read more
Affected Products : dhis_2- Published: Nov. 01, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41186
Fluentd collects events from various data sources and writes them to files to help unify logging infrastructure. The parser_apache2 plugin in Fluentd v0.14.14 to v1.14.1 suffers from a regular expression denial of service (ReDoS) vulnerability. A broken a... Read more
Affected Products : fluentd- Published: Oct. 29, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-41185
Mycodo is an environmental monitoring and regulation system. An exploit in versions prior to 8.12.7 allows anyone with access to endpoints to download files outside the intended directory. A patch has been applied and a release made. Users should upgrade ... Read more
Affected Products : mycodo- Published: Oct. 26, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-41184
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value ... Read more
Affected Products : fedora drupal h410c_firmware hospitality_suite8 weblogic_server peoplesoft_enterprise_peopletools primavera_unifier h300s_firmware h500s_firmware h700s_firmware +25 more products- Published: Oct. 26, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-41183
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values... Read more
Affected Products : fedora debian_linux drupal h410c_firmware hospitality_suite8 weblogic_server peoplesoft_enterprise_peopletools h300s_firmware h500s_firmware h700s_firmware +26 more products- Published: Oct. 26, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-41182
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string v... Read more
Affected Products : fedora debian_linux drupal h410c_firmware hospitality_suite8 weblogic_server peoplesoft_enterprise_peopletools primavera_unifier h300s_firmware h500s_firmware +27 more products- Published: Oct. 26, 2021
- Modified: Nov. 21, 2024