📦 Oneflow

by Oneflow

🔍 What is Oneflow?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-36736

CRITICAL CVSS 9.8 Jun 6, 2024

CVE-2024-36736 is a critical vulnerability in OneFlow's permute component that causes incorrect calculations when performing same-dimension operations. This could lead to memory corruption, data integ...

CVE-2025-71007

HIGH CVSS 7.5 Jan 28, 2026

An input validation vulnerability in OneFlow's oneflow.index_add component allows attackers to trigger a Denial of Service (DoS) by sending specially crafted inputs. This affects systems running OneFl...

CVE-2025-71003

HIGH CVSS 7.5 Jan 28, 2026

An input validation vulnerability in OneFlow's flow.arange() function allows attackers to trigger a Denial of Service (DoS) by sending specially crafted inputs. This affects systems running OneFlow v0...

CVE-2025-70999

HIGH CVSS 7.5 Jan 28, 2026

A GPU device-ID validation flaw in OneFlow's CUDA component allows attackers to trigger a Denial of Service (DoS) by providing a crafted device ID. This affects OneFlow v0.9.0 users who utilize GPU ac...

CVE-2025-71000

HIGH CVSS 7.5 Jan 28, 2026

A vulnerability in OneFlow v0.9.0's flow.cuda.BoolTensor component allows attackers to cause Denial of Service (DoS) by sending specially crafted input. This affects systems running OneFlow with CUDA ...

CVE-2025-65891

HIGH CVSS 7.5 Jan 28, 2026

A GPU device-ID validation flaw in OneFlow v0.9.0 allows attackers to trigger a Denial of Service (DoS) by calling flow.cuda.get_device_properties() with an invalid or negative device index. This affe...

CVE-2024-36734

HIGH CVSS 7.5 Jun 6, 2024

This vulnerability in OneFlow v0.9.1 allows attackers to cause Denial of Service (DoS) by sending negative values to the dim parameter. The improper input validation enables crashing or freezing of th...

CVE-2024-36740

HIGH CVSS 7.5 Jun 6, 2024

This vulnerability in OneFlow v0.9.1 allows attackers to cause Denial of Service (DoS) by providing a negative index that exceeds the valid range, potentially crashing the application. It affects syst...

CVE-2024-36730

HIGH CVSS 7.5 Jun 6, 2024

This vulnerability in OneFlow v0.9.1 allows attackers to cause Denial of Service (DoS) by providing negative values to the oneflow.zeros/ones parameter. Improper input validation leads to resource exh...

CVE-2024-36743

HIGH CVSS 7.5 Jun 6, 2024

This vulnerability in OneFlow v0.9.1 allows attackers to cause Denial of Service (DoS) by passing an empty array to the oneflow.dot function. The issue affects systems using OneFlow for machine learni...

CVE-2025-71011

MEDIUM CVSS 6.2 Jan 29, 2026

An input validation vulnerability in OneFlow's tensor creation functions allows attackers to trigger a Denial of Service (DoS) by providing specially crafted inputs. This affects systems running OneFl...

CVE-2025-71004

MEDIUM CVSS 6.5 Jan 28, 2026

A segmentation violation vulnerability in OneFlow's logical_or component allows attackers to crash the application via specially crafted input, causing Denial of Service. This affects systems running ...

CVE-2025-71005

MEDIUM CVSS 6.5 Jan 28, 2026

A floating point exception vulnerability in OneFlow's oneflow.view component allows attackers to crash the application via specially crafted input, causing denial of service. This affects systems runn...

CVE-2025-71006

MEDIUM CVSS 6.5 Jan 28, 2026

A floating point exception vulnerability in OneFlow's reshape component allows attackers to crash the application via specially crafted input, causing denial of service. This affects systems running O...

CVE-2025-71002

MEDIUM CVSS 6.5 Jan 28, 2026

A floating-point exception vulnerability in OneFlow's flow.column_stack component allows attackers to trigger a Denial of Service (DoS) by providing specially crafted input. This affects OneFlow v0.9....

CVE-2025-71001

MEDIUM CVSS 6.5 Jan 28, 2026

A segmentation violation vulnerability in OneFlow's flow.column_stack component allows attackers to cause Denial of Service (DoS) through crafted input. This affects OneFlow v0.9.0 users who process u...

CVE-2025-63397

MEDIUM CVSS 6.5 Nov 10, 2025

This vulnerability in OneFlow v0.9.0 allows attackers to trigger a segmentation fault through improper input validation during broadcasting and type conversion operations. Attackers can exploit this b...