CVE-2021-37644
Last Modified: 21 Nov 2024TensorFlow is an end-to-end open source platform for machine learning. In affected versions providing a negative element to `num_elements` list argument of `tf.raw_ops.TensorListReserve` causes the runtime to abort the process due to reallocating a `std::vector` to have a negative number of elements. The [implementation](https://github.com/tensorflow/tensorflow/blob/8d72537c6abf5a44103b57b9c2e22c14f5f49698/tensorflow/core/kernels/list_kernels.cc#L312) calls `std::vector.resize()` with the new size controlled by input given by the user, without checking that this input is valid. We have patched the issue in GitHub commit 8a6e874437670045e6c7dc6154c7412b4a2135e2. The fix will be included in TensorFlow 2.6.0. We will also cherrypick this commit on TensorFlow 2.5.1, TensorFlow 2.4.3, and TensorFlow 2.3.4, as these are also affected and still in supported range.
CVE-2021-37654
Last Modified: 21 Nov 2024TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can trigger a crash via a `CHECK`-fail in debug builds of TensorFlow using `tf.raw_ops.ResourceGather` or a read from outside the bounds of heap allocated data in the same API in a release build. The [implementation](https://github.com/tensorflow/tensorflow/blob/f24faa153ad31a4b51578f8181d3aaab77a1ddeb/tensorflow/core/kernels/resource_variable_ops.cc#L660-L668) does not check that the `batch_dims` value that the user supplies is less than the rank of the input tensor. Since the implementation uses several for loops over the dimensions of `tensor`, this results in reading data from outside the bounds of heap allocated buffer backing the tensor. We have patched the issue in GitHub commit bc9c546ce7015c57c2f15c168b3d9201de679a1d. The fix will be included in TensorFlow 2.6.0. We will also cherrypick this commit on TensorFlow 2.5.1, TensorFlow 2.4.3, and TensorFlow 2.3.4, as these are also affected and still in supported range.
CVE-2021-37641
Last Modified: 21 Nov 2024TensorFlow is an end-to-end open source platform for machine learning. In affected versions if the arguments to `tf.raw_ops.RaggedGather` don't determine a valid ragged tensor code can trigger a read from outside of bounds of heap allocated buffers. The [implementation](https://github.com/tensorflow/tensorflow/blob/8d72537c6abf5a44103b57b9c2e22c14f5f49698/tensorflow/core/kernels/ragged_gather_op.cc#L70) directly reads the first dimension of a tensor shape before checking that said tensor has rank of at least 1 (i.e., it is not a scalar). Furthermore, the implementation does not check that the list given by `params_nested_splits` is not an empty list of tensors. We have patched the issue in GitHub commit a2b743f6017d7b97af1fe49087ae15f0ac634373. The fix will be included in TensorFlow 2.6.0. We will also cherrypick this commit on TensorFlow 2.5.1, TensorFlow 2.4.3, and TensorFlow 2.3.4, as these are also affected and still in supported range.
CVE-2021-37635
Last Modified: 21 Nov 2024TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of sparse reduction operations in TensorFlow can trigger accesses outside of bounds of heap allocated data. The [implementation](https://github.com/tensorflow/tensorflow/blob/a1bc56203f21a5a4995311825ffaba7a670d7747/tensorflow/core/kernels/sparse_reduce_op.cc#L217-L228) fails to validate that each reduction group does not overflow and that each corresponding index does not point to outside the bounds of the input tensor. We have patched the issue in GitHub commit 87158f43f05f2720a374f3e6d22a7aaa3a33f750. The fix will be included in TensorFlow 2.6.0. We will also cherrypick this commit on TensorFlow 2.5.1, TensorFlow 2.4.3, and TensorFlow 2.3.4, as these are also affected and still in supported range.
CVE-2021-37664
Last Modified: 21 Nov 2024TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can read from outside of bounds of heap allocated data by sending specially crafted illegal arguments to `BoostedTreesSparseCalculateBestFeatureSplit`. The [implementation](https://github.com/tensorflow/tensorflow/blob/84d053187cb80d975ef2b9684d4b61981bca0c41/tensorflow/core/kernels/boosted_trees/stats_ops.cc) needs to validate that each value in `stats_summary_indices` is in range. We have patched the issue in GitHub commit e84c975313e8e8e38bb2ea118196369c45c51378. The fix will be included in TensorFlow 2.6.0. We will also cherrypick this commit on TensorFlow 2.5.1, TensorFlow 2.4.3, and TensorFlow 2.3.4, as these are also affected and still in supported range.
CVE-2021-37659
Last Modified: 21 Nov 2024TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause undefined behavior via binding a reference to null pointer in all binary cwise operations that don't require broadcasting (e.g., gradients of binary cwise operations). The [implementation](https://github.com/tensorflow/tensorflow/blob/84d053187cb80d975ef2b9684d4b61981bca0c41/tensorflow/core/kernels/cwise_ops_common.h#L264) assumes that the two inputs have exactly the same number of elements but does not check that. Hence, when the eigen functor executes it triggers heap OOB reads and undefined behavior due to binding to nullptr. We have patched the issue in GitHub commit 93f428fd1768df147171ed674fee1fc5ab8309ec. The fix will be included in TensorFlow 2.6.0. We will also cherrypick this commit on TensorFlow 2.5.1, TensorFlow 2.4.3, and TensorFlow 2.3.4, as these are also affected and still in supported range.
CVE-2021-37655
Last Modified: 21 Nov 2024TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can trigger a read from outside of bounds of heap allocated data by sending invalid arguments to `tf.raw_ops.ResourceScatterUpdate`. The [implementation](https://github.com/tensorflow/tensorflow/blob/f24faa153ad31a4b51578f8181d3aaab77a1ddeb/tensorflow/core/kernels/resource_variable_ops.cc#L919-L923) has an incomplete validation of the relationship between the shapes of `indices` and `updates`: instead of checking that the shape of `indices` is a prefix of the shape of `updates` (so that broadcasting can happen), code only checks that the number of elements in these two tensors are in a divisibility relationship. We have patched the issue in GitHub commit 01cff3f986259d661103412a20745928c727326f. The fix will be included in TensorFlow 2.6.0. We will also cherrypick this commit on TensorFlow 2.5.1, TensorFlow 2.4.3, and TensorFlow 2.3.4, as these are also affected and still in supported range.
CVE-2021-38366
Last Modified: 21 Nov 2024Sitecore through 10.1, when Update Center is enabled, allows remote authenticated users to upload arbitrary files and achieve remote code execution by visiting an uploaded .aspx file at an admin/Packages URL.
CVE-2021-37704
Last Modified: 21 Nov 2024PhpFastCache is a high-performance backend cache system (packagist package phpfastcache/phpfastcache). In versions before 6.1.5, 7.1.2, and 8.0.7 the `phpinfo()` can be exposed if the `/vendor` is not protected from public access. This is a rare situation today since the vendor directory is often located outside the web directory or protected via server rule (.htaccess, etc). Only the v6, v7 and v8 will be patched respectively in 8.0.7, 7.1.2, 6.1.5. Older versions such as v5, v4 are not longer supported and will **NOT** be patched. As a workaround, protect the `/vendor` directory from public access.
CVE-2020-18464
Last Modified: 21 Nov 2024Cross Site Request Forgery (CSRF) vulnerability in AikCms 2.0.0 in video_list.php, which can let a malicious user delete movie information.
CVE-2020-18463
Last Modified: 21 Nov 2024Cross Site Request Forgery (CSRF) vulnerability exists in v2.0.0 in video_list.php, which can let a malicious user delete a video message.
CVE-2020-18462
Last Modified: 21 Nov 2024File Upload vulnerabilty in AikCms v2.0.0 in poster_edit.php because the background file management office does not verify the uploaded file.
CVE-2021-37637
Last Modified: 21 Nov 2024TensorFlow is an end-to-end open source platform for machine learning. It is possible to trigger a null pointer dereference in TensorFlow by passing an invalid input to `tf.raw_ops.CompressElement`. The [implementation](https://github.com/tensorflow/tensorflow/blob/47a06f40411a69c99f381495f490536972152ac0/tensorflow/core/data/compression_utils.cc#L34) was accessing the size of a buffer obtained from the return of a separate function call before validating that said buffer is valid. We have patched the issue in GitHub commit 5dc7f6981fdaf74c8c5be41f393df705841fb7c5. The fix will be included in TensorFlow 2.6.0. We will also cherrypick this commit on TensorFlow 2.5.1, TensorFlow 2.4.3, and TensorFlow 2.3.4, as these are also affected and still in supported range.
CVE-2020-18460
Last Modified: 21 Nov 2024Cross Site Request Forgery (CSRF) vulnerability exists in 711cms v1.0.7 that can add an admin account via admin.php?c=Admin&m=content.
CVE-2021-36958
Last Modified: 10 Aug 2026A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
CVE-2021-36950
Last Modified: 10 Aug 2026Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2021-36949
Last Modified: 10 Aug 2026Microsoft Azure Active Directory Connect Authentication Bypass Vulnerability
CVE-2021-36948
Last Modified: 10 Aug 2026Windows Update Medic Service Elevation of Privilege Vulnerability
CVE-2021-36947
Last Modified: 10 Aug 2026Windows Print Spooler Remote Code Execution Vulnerability
CVE-2021-36946
Last Modified: 10 Aug 2026Microsoft Dynamics Business Central Cross-site Scripting Vulnerability
CVE-2021-36945
Last Modified: 10 Aug 2026Windows 10 Update Assistant Elevation of Privilege Vulnerability
CVE-2021-36943
Last Modified: 10 Aug 2026Azure CycleCloud Elevation of Privilege Vulnerability
CVE-2021-36942
Last Modified: 10 Aug 2026Windows LSA Spoofing Vulnerability
CVE-2021-36941
Last Modified: 10 Aug 2026Microsoft Word Remote Code Execution Vulnerability
CVE-2021-36940
Last Modified: 10 Aug 2026Microsoft SharePoint Server Spoofing Vulnerability
CVE-2021-36938
Last Modified: 10 Aug 2026Windows Cryptographic Primitives Library Information Disclosure Vulnerability
CVE-2021-36937
Last Modified: 10 Aug 2026Windows Media MPEG-4 Video Decoder Remote Code Execution Vulnerability
CVE-2021-36936
Last Modified: 10 Aug 2026Windows Print Spooler Remote Code Execution Vulnerability
CVE-2021-36933
Last Modified: 10 Aug 2026Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
CVE-2021-36932
Last Modified: 10 Aug 2026Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
CVE-2021-36927
Last Modified: 10 Aug 2026Windows Digital TV Tuner device registration application Elevation of Privilege Vulnerability
CVE-2021-36926
Last Modified: 10 Aug 2026Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
CVE-2021-34537
Last Modified: 10 Aug 2026Windows Bluetooth Driver Elevation of Privilege Vulnerability
CVE-2021-34536
Last Modified: 10 Aug 2026Windows Storage Spaces Controller Elevation of Privilege Vulnerability
CVE-2021-34535
Last Modified: 10 Aug 2026Remote Desktop Client Remote Code Execution Vulnerability
CVE-2021-34534
Last Modified: 10 Aug 2026Windows MSHTML Platform Remote Code Execution Vulnerability
CVE-2021-34533
Last Modified: 10 Aug 2026Windows Graphics Component Font Parsing Remote Code Execution Vulnerability
CVE-2021-34530
Last Modified: 10 Aug 2026Windows Graphics Component Remote Code Execution Vulnerability
CVE-2021-34524
Last Modified: 10 Aug 2026Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
CVE-2021-34487
Last Modified: 10 Aug 2026Windows Event Tracing Elevation of Privilege Vulnerability
CVE-2021-34486
Last Modified: 10 Aug 2026Windows Event Tracing Elevation of Privilege Vulnerability
CVE-2021-34484
Last Modified: 10 Aug 2026Windows User Profile Service Elevation of Privilege Vulnerability
CVE-2021-34483
Last Modified: 10 Aug 2026Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2021-34480
Last Modified: 10 Aug 2026Scripting Engine Memory Corruption Vulnerability
CVE-2021-34478
Last Modified: 10 Aug 2026Microsoft Office Remote Code Execution Vulnerability
CVE-2021-34471
Last Modified: 10 Aug 2026Microsoft Defender Elevation of Privilege Vulnerability
CVE-2021-33762
Last Modified: 10 Aug 2026Azure CycleCloud Elevation of Privilege Vulnerability
CVE-2021-26433
Last Modified: 10 Aug 2026Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
CVE-2021-26432
Last Modified: 10 Aug 2026Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability
CVE-2021-26431
Last Modified: 10 Aug 2026Windows Recovery Environment Agent Elevation of Privilege Vulnerability
