📦 Tensorflow

by Google

🔍 What is Tensorflow?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-25668

CRITICAL CVSS 9.8 Mar 25, 2023

This CVE describes a heap-based buffer overflow vulnerability in TensorFlow that allows attackers to access memory outside user-controlled bounds. This can lead to application crashes or potentially r...

CVE-2021-37678

CRITICAL CVSS 9.3 Aug 12, 2021

This vulnerability allows arbitrary code execution when TensorFlow or Keras deserializes a malicious YAML model file. Attackers can exploit unsafe YAML loading to run arbitrary commands on affected sy...

CVE-2021-35958

CRITICAL CVSS 9.1 Jun 30, 2021

This vulnerability in TensorFlow allows attackers to overwrite arbitrary files on the system when tf.keras.utils.get_file is used with extract=True on a malicious archive. It affects TensorFlow users ...

CVE-2025-55559

HIGH CVSS 7.5 Sep 25, 2025

A Denial of Service vulnerability exists in TensorFlow v2.18.0 where using 'valid' padding in tf.keras.layers.Conv2D operations can cause resource exhaustion and service disruption. This affects any s...

CVE-2023-33976

HIGH CVSS 7.5 Jul 30, 2024

CVE-2023-33976 is a vulnerability in TensorFlow's array_ops.upper_bound function that causes a segmentation fault when provided with a tensor that is not rank 2. This can lead to denial of service or ...

CVE-2023-25676

HIGH CVSS 7.5 Mar 25, 2023

This vulnerability in TensorFlow allows a denial of service attack through a null pointer dereference in the ParallelConcat operation when using XLA compilation. It affects users running TensorFlow ve...

CVE-2023-27579

HIGH CVSS 7.5 Mar 25, 2023

This CVE describes a floating-point exception (FPE) vulnerability in TensorFlow's TFLite component when constructing models with a filter_input_channel parameter less than 1. This can cause denial of ...

CVE-2023-25659

HIGH CVSS 7.5 Mar 25, 2023

This vulnerability in TensorFlow allows an out-of-bounds read when the DynamicStitch operation receives mismatched indices and data shapes, potentially leading to memory corruption or information disc...

CVE-2023-25662

HIGH CVSS 7.5 Mar 25, 2023

CVE-2023-25662 is an integer overflow vulnerability in TensorFlow's EditDistance function that could allow attackers to cause denial of service or potentially execute arbitrary code. This affects all ...

CVE-2023-25664

HIGH CVSS 7.5 Mar 25, 2023

This CVE describes a heap buffer overflow vulnerability in TensorFlow's TAvgPoolGrad operation. Attackers could exploit this to cause denial of service, memory corruption, or potentially execute arbit...

CVE-2023-25666

HIGH CVSS 7.5 Mar 25, 2023

This CVE describes a floating point exception vulnerability in TensorFlow's AudioSpectrogram function. Attackers can cause denial of service by triggering division by zero or invalid floating point op...

CVE-2023-25670

HIGH CVSS 7.5 Mar 25, 2023

This CVE describes a null pointer dereference vulnerability in TensorFlow's QuantizedMatMulWithBiasAndDequantize operation when MKL (Math Kernel Library) is enabled. It affects TensorFlow installation...

CVE-2023-25672

HIGH CVSS 7.5 Mar 25, 2023

This vulnerability in TensorFlow's LookupTableImportV2 function causes a Null Pointer Exception (NPE) when scalar values are passed, potentially leading to denial of service. It affects TensorFlow use...

CVE-2023-25674

HIGH CVSS 7.5 Mar 25, 2023

This CVE describes a null pointer dereference vulnerability in TensorFlow's RandomShuffle operation when XLA (Accelerated Linear Algebra) is enabled. It affects TensorFlow versions prior to 2.12.0 and...

CVE-2022-29208

HIGH CVSS 7.1 May 20, 2022

This CVE allows attackers to cause a segmentation fault and denial of service in TensorFlow by passing negative values to the tf.raw_ops.EditDistance function. The vulnerability affects users running ...

CVE-2022-23587

HIGH CVSS 8.8 Feb 4, 2022

This CVE describes an integer overflow vulnerability in TensorFlow's Grappler component during cost estimation for crop and resize operations. Attackers can trigger undefined behavior by manipulating ...

CVE-2022-23591

HIGH CVSS 7.5 Feb 4, 2022

This CVE describes a stack overflow vulnerability in TensorFlow's GraphDef format that occurs when loading a SavedModel containing self-recursive functions. The vulnerability affects TensorFlow users ...

CVE-2022-23594

HIGH CVSS 8.8 Feb 4, 2022

This vulnerability in TensorFlow's TFG dialect allows attackers to cause crashes or potentially execute arbitrary code by manipulating SavedModel files on disk. When these malicious files are processe...

CVE-2022-23566

HIGH CVSS 8.8 Feb 4, 2022

CVE-2022-23566 is a heap out-of-bounds write vulnerability in TensorFlow's Grappler component that allows attackers to write arbitrary data to memory. This can lead to remote code execution, denial of...

CVE-2022-23573

HIGH CVSS 7.6 Feb 4, 2022

This vulnerability in TensorFlow's AssignOp implementation allows copying uninitialized data to new tensors, leading to undefined behavior. It affects users of TensorFlow who perform tensor assignment...

CVE-2022-23584

HIGH CVSS 7.6 Feb 4, 2022

This vulnerability in TensorFlow allows a malicious user to trigger use-after-free behavior when decoding PNG images, potentially leading to memory corruption. It affects TensorFlow versions before th...

CVE-2022-23562

HIGH CVSS 7.6 Feb 4, 2022

This CVE describes an integer overflow vulnerability in TensorFlow's Range operation that can lead to undefined behavior or excessive memory allocations. Attackers could exploit this to cause denial o...

CVE-2022-23558

HIGH CVSS 7.6 Feb 4, 2022

This CVE describes an integer overflow vulnerability in TensorFlow's TFLite component where an attacker can craft a malicious TFLite model to trigger memory corruption. The vulnerability affects Tenso...

CVE-2022-23560

HIGH CVSS 8.8 Feb 4, 2022

This vulnerability in TensorFlow allows attackers to craft malicious TFLite models that can read and write memory outside of allocated arrays during sparse-to-dense tensor conversion. This affects all...

CVE-2022-21740

HIGH CVSS 7.6 Feb 3, 2022

CVE-2022-21740 is a heap overflow vulnerability in TensorFlow's SparseCountSparseOutput implementation that allows attackers to write beyond allocated memory boundaries. This can lead to arbitrary cod...

CVE-2022-21736

HIGH CVSS 7.6 Feb 3, 2022

This vulnerability in TensorFlow's SparseTensorSliceDataset allows attackers to cause a null pointer dereference by providing invalid input arguments that bypass validation checks. This affects all sy...

CVE-2022-21728

HIGH CVSS 8.1 Feb 3, 2022

This vulnerability in TensorFlow's ReverseSequence operation allows heap out-of-bounds reads when processing negative batch_dim values. Attackers could potentially read sensitive memory contents or ca...

CVE-2022-21726

HIGH CVSS 8.1 Feb 3, 2022

This vulnerability in TensorFlow's Dequantize operation allows attackers to read past the end of memory arrays by providing invalid axis values, potentially exposing sensitive data or causing crashes....

CVE-2021-41220

HIGH CVSS 7.8 Nov 5, 2021

This CVE describes a memory leak and use-after-free vulnerability in TensorFlow's CollectiveReduceV2 async implementation. Attackers could potentially cause denial of service or execute arbitrary code...

CVE-2021-41228

HIGH CVSS 7.5 Nov 5, 2021

TensorFlow's saved_model_cli tool is vulnerable to code injection via unsafe eval() calls on user-supplied strings, allowing attackers to execute arbitrary code on systems where the CLI tool runs. Thi...

CVE-2021-41206

HIGH CVSS 7.0 Nov 5, 2021

TensorFlow is vulnerable to shape validation flaws in multiple operations, allowing attackers to trigger undefined behavior including crashes or potential memory corruption. This affects all users run...

CVE-2021-41208

HIGH CVSS 8.8 Nov 5, 2021

This vulnerability in TensorFlow's boosted trees implementation allows attackers to trigger denial of service, exploit undefined behavior, and potentially read/write heap buffers. It affects all users...

CVE-2021-41219

HIGH CVSS 7.8 Nov 5, 2021

This vulnerability in TensorFlow's sparse matrix multiplication allows attackers to trigger undefined behavior and potential heap out-of-bounds access by providing zero or negative dimensions. This af...

CVE-2021-41224

HIGH CVSS 7.1 Nov 5, 2021

This vulnerability in TensorFlow allows attackers to trigger a heap out-of-bounds memory access by providing mismatched sizes for indices and values arrays to the SparseFillEmptyRows function. This co...

CVE-2021-41212

HIGH CVSS 7.1 Nov 5, 2021

This vulnerability in TensorFlow allows attackers to trigger an out-of-bounds read in the tf.ragged.cross function, potentially leading to memory disclosure or application crashes. It affects TensorFl...

CVE-2021-41205

HIGH CVSS 7.1 Nov 5, 2021

This CVE describes an out-of-bounds read vulnerability in TensorFlow's QuantizeAndDequantizeV* operations that could allow attackers to read sensitive memory contents. It affects TensorFlow users runn...

CVE-2021-41201

HIGH CVSS 7.8 Nov 5, 2021

This CVE describes an uninitialized variable access vulnerability in TensorFlow's EinsumHelper::ParseEquation() function. The bug occurs when the function fails to properly set boolean flags to false,...

CVE-2021-37663

HIGH CVSS 7.8 Aug 12, 2021

This vulnerability in TensorFlow's QuantizeV2 operation allows attackers to trigger undefined behavior by accessing invalid memory locations. Attackers can cause crashes or potentially execute arbitra...

CVE-2021-37688

HIGH CVSS 7.8 Aug 12, 2021

This vulnerability allows attackers to craft malicious TFLite models that trigger a null pointer dereference in TensorFlow, causing a crash and denial of service. It affects TensorFlow users who proce...

CVE-2021-37648

HIGH CVSS 7.8 Aug 12, 2021

This vulnerability in TensorFlow allows attackers to trigger a null pointer dereference in the SaveV2 operation, potentially causing denial of service or memory corruption. It affects TensorFlow users...

CVE-2021-37666

HIGH CVSS 7.8 Aug 12, 2021

This vulnerability in TensorFlow allows an attacker to cause undefined behavior by triggering a null pointer dereference in the RaggedTensorToVariant operation. Attackers could potentially crash the a...

CVE-2021-37671

HIGH CVSS 7.8 Aug 12, 2021

This vulnerability in TensorFlow allows attackers to cause undefined behavior by triggering null pointer dereferences in Map* and OrderedMap* operations. Attackers can exploit this by passing empty in...

CVE-2021-37676

HIGH CVSS 7.8 Aug 12, 2021

This vulnerability in TensorFlow allows attackers to cause undefined behavior by passing empty tensors to the SparseFillEmptyRows operation, potentially leading to crashes or memory corruption. It aff...

CVE-2025-55556

MEDIUM CVSS 6.5 Sep 25, 2025

TensorFlow v2.18.0 has a bug where Embedding layers produce random outputs during compilation instead of expected results, causing ML models to generate incorrect predictions. This affects application...

CVE-2023-25661

MEDIUM CVSS 6.5 Mar 27, 2023

This vulnerability in TensorFlow allows an attacker with input privileges to provide malicious data to the Convolution3DTranspose function, causing a crash and denial of service. It affects TensorFlow...