Логотип exploitDog
bind:CVE-2020-15205
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-15205

Количество 4

Количество 4

nvd логотип

CVE-2020-15205

больше 5 лет назад

In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `data_splits` argument of `tf.raw_ops.StringNGrams` lacks validation. This allows a user to pass values that can cause heap overflow errors and even leak contents of memory In the linked code snippet, all the binary strings after `ee ff` are contents from the memory stack. Since these can contain return addresses, this data leak can be used to defeat ASLR. The issue is patched in commit 0462de5b544ed4731aa2fb23946ac22c01856b80, and is released in TensorFlow versions 1.15.4, 2.0.3, 2.1.2, 2.2.1, or 2.3.1.

CVSS3: 9
EPSS: Низкий
debian логотип

CVE-2020-15205

больше 5 лет назад

In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, t ...

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-g7p5-5759-qv46

больше 5 лет назад

Data leak in Tensorflow

CVSS3: 9
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:1766-1

больше 5 лет назад

Security update for tensorflow2

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-15205

In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `data_splits` argument of `tf.raw_ops.StringNGrams` lacks validation. This allows a user to pass values that can cause heap overflow errors and even leak contents of memory In the linked code snippet, all the binary strings after `ee ff` are contents from the memory stack. Since these can contain return addresses, this data leak can be used to defeat ASLR. The issue is patched in commit 0462de5b544ed4731aa2fb23946ac22c01856b80, and is released in TensorFlow versions 1.15.4, 2.0.3, 2.1.2, 2.2.1, or 2.3.1.

CVSS3: 9
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-15205

In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, t ...

CVSS3: 9
1%
Низкий
больше 5 лет назад
github логотип
GHSA-g7p5-5759-qv46

Data leak in Tensorflow

CVSS3: 9
1%
Низкий
больше 5 лет назад
suse-cvrf логотип
openSUSE-SU-2020:1766-1

Security update for tensorflow2

больше 5 лет назад

Уязвимостей на страницу