Описание
Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM functions have an off by one string copy.
Ссылки
- Patch
- Third Party Advisory
- Third Party Advisory
- Patch
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.16.0 (исключая)
cpe:2.3:a:linuxfoundation:onnx:*:*:*:*:*:*:*:*
Конфигурация 2
Одно из
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*
EPSS
Процентиль: 46%
0.00594
Низкий
4.4 Medium
CVSS3
9.1 Critical
CVSS3
Дефекты
CWE-125
CWE-125
Связанные уязвимости
CVSS3: 9.1
msrc
больше 1 года назад
Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM functions have an off by one string copy.
EPSS
Процентиль: 46%
0.00594
Низкий
4.4 Medium
CVSS3
9.1 Critical
CVSS3
Дефекты
CWE-125
CWE-125