Логотип exploitDog
bind:CVE-2021-35958
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-35958

Количество 3

Количество 3

nvd логотип

CVE-2021-35958

больше 4 лет назад

TensorFlow through 2.5.0 allows attackers to overwrite arbitrary files via a crafted archive when tf.keras.utils.get_file is used with extract=True. NOTE: the vendor's position is that tf.keras.utils.get_file is not intended for untrusted archives

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2021-35958

больше 4 лет назад

TensorFlow through 2.5.0 allows attackers to overwrite arbitrary files ...

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-4cm9-63x5-55wm

больше 3 лет назад

** DISPUTED ** TensorFlow through 2.5.0 allows attackers to overwrite arbitrary files via a crafted archive when tf.keras.utils.get_file is used with extract=True. NOTE: the vendor's position is that tf.keras.utils.get_file is not intended for untrusted archives.

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-35958

TensorFlow through 2.5.0 allows attackers to overwrite arbitrary files via a crafted archive when tf.keras.utils.get_file is used with extract=True. NOTE: the vendor's position is that tf.keras.utils.get_file is not intended for untrusted archives

CVSS3: 9.1
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-35958

TensorFlow through 2.5.0 allows attackers to overwrite arbitrary files ...

CVSS3: 9.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4cm9-63x5-55wm

** DISPUTED ** TensorFlow through 2.5.0 allows attackers to overwrite arbitrary files via a crafted archive when tf.keras.utils.get_file is used with extract=True. NOTE: the vendor's position is that tf.keras.utils.get_file is not intended for untrusted archives.

CVSS3: 9.1
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу