Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38371
HistoryDec 08, 2022 - 5:38 a.m.

Denial Of Service (DoS)

2022-12-0805:38:22
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6
tensorflow
vulnerability
denial of service
improper input validation
out-of-bounds memory read
crash.

0.001 Low

EPSS

Percentile

48.7%

tensorflow is vulnerable to denial of service. The vulnerability exists because the MakeGrapplerFunctionItem in functions.cc does not properly validate the input-output arguments, allowing an attacker to cause out-of-bounds memory read or crash the application if the inputs given are greater than or equal to the sizes of the outputs.

0.001 Low

EPSS

Percentile

48.7%