2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-26116 | HIGH | 7.2 | 6.4% | Sep 27, 2020 | http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF inj... |
| CVE-2020-15214 | HIGH | 8.1 | 0.6% | Sep 25, 2020 | In TensorFlow Lite before versions 2.2.1 and 2.3.1, models using segment sum can trigger a write out bounds / segmentati... |
| CVE-2020-15213 | MEDIUM | 4 | 0.6% | Sep 25, 2020 | In TensorFlow Lite before versions 2.2.1 and 2.3.1, models using segment sum can trigger a denial of service by causing ... |
| CVE-2020-15212 | HIGH | 8.6 | 0.6% | Sep 25, 2020 | In TensorFlow Lite before versions 2.2.1 and 2.3.1, models using segment sum can trigger writes outside of bounds of hea... |
| CVE-2020-15211 | MEDIUM | 4.8 | 0.9% | Sep 25, 2020 | In TensorFlow Lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, saved models in the flatbuffer format use a do... |
| CVE-2020-15210 | MEDIUM | 6.5 | 0.7% | Sep 25, 2020 | In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, if a TFLite saved model uses the same tensor a... |
| CVE-2020-15209 | MEDIUM | 5.9 | 0.8% | Sep 25, 2020 | In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, a crafted TFLite model can force a node to hav... |
| CVE-2020-15208 | CRITICAL | 9.8 | 0.9% | Sep 25, 2020 | In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, when determining the common dimension size of ... |
| CVE-2020-15207 | CRITICAL | 9 | 1.2% | Sep 25, 2020 | In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, to mimic Python's indexing with negative value... |
| CVE-2020-15206 | HIGH | 7.5 | 0.9% | Sep 25, 2020 | In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, changing the TensorFlow's `SavedModel` protocol buf... |
| CVE-2020-15205 | CRITICAL | 9.8 | 1.0% | Sep 25, 2020 | In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `data_splits` argument of `tf.raw_ops.StringNGr... |
| CVE-2020-15204 | MEDIUM | 5.3 | 0.9% | Sep 25, 2020 | In eager mode, TensorFlow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1 does not set the session state. Hence, c... |
| CVE-2020-15203 | HIGH | 7.5 | 1.0% | Sep 25, 2020 | In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, by controlling the `fill` argument of tf.strings.as... |
| CVE-2020-15202 | CRITICAL | 9 | 1.2% | Sep 25, 2020 | In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `Shard` API in TensorFlow expects the last argu... |
| CVE-2020-15201 | MEDIUM | 4.8 | 0.6% | Sep 25, 2020 | In Tensorflow before version 2.3.1, the `RaggedCountSparseOutput` implementation does not validate that the input argume... |
| CVE-2020-15200 | MEDIUM | 5.9 | 0.8% | Sep 25, 2020 | In Tensorflow before version 2.3.1, the `RaggedCountSparseOutput` implementation does not validate that the input argume... |
| CVE-2020-15199 | MEDIUM | 5.9 | 0.8% | Sep 25, 2020 | In Tensorflow before version 2.3.1, the `RaggedCountSparseOutput` does not validate that the input arguments form a vali... |
| CVE-2020-15198 | MEDIUM | 5.4 | 0.5% | Sep 25, 2020 | In Tensorflow before version 2.3.1, the `SparseCountSparseOutput` implementation does not validate that the input argume... |
| CVE-2020-15197 | MEDIUM | 6.3 | 0.7% | Sep 25, 2020 | In Tensorflow before version 2.3.1, the `SparseCountSparseOutput` implementation does not validate that the input argume... |
| CVE-2020-15196 | CRITICAL | 9.9 | 0.9% | Sep 25, 2020 | In Tensorflow version 2.3.0, the `SparseCountSparseOutput` and `RaggedCountSparseOutput` implementations don't validate ... |
| CVE-2020-15195 | HIGH | 8.8 | 0.9% | Sep 25, 2020 | In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the implementation of `SparseFillEmptyRowsGrad` use... |
| CVE-2020-15194 | MEDIUM | 5.3 | 1.0% | Sep 25, 2020 | In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `SparseFillEmptyRowsGrad` implementation has in... |
| CVE-2020-15193 | HIGH | 7.1 | 0.7% | Sep 25, 2020 | In Tensorflow before versions 2.2.1 and 2.3.1, the implementation of `dlpack.to_dlpack` can be made to use uninitialized... |
| CVE-2020-15192 | MEDIUM | 4.3 | 0.7% | Sep 25, 2020 | In Tensorflow before versions 2.2.1 and 2.3.1, if a user passes a list of strings to `dlpack.to_dlpack` there is a memor... |
| CVE-2020-15191 | MEDIUM | 5.3 | 0.7% | Sep 25, 2020 | In Tensorflow before versions 2.2.1 and 2.3.1, if a user passes an invalid argument to `dlpack.to_dlpack` the expected v... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now