2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-26116HIGH7.2http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF inj...
CVE-2020-15214HIGH8.1In TensorFlow Lite before versions 2.2.1 and 2.3.1, models using segment sum can trigger a write out bounds / segmentati...
CVE-2020-15213MEDIUM4In TensorFlow Lite before versions 2.2.1 and 2.3.1, models using segment sum can trigger a denial of service by causing ...
CVE-2020-15212HIGH8.6In TensorFlow Lite before versions 2.2.1 and 2.3.1, models using segment sum can trigger writes outside of bounds of hea...
CVE-2020-15211MEDIUM4.8In TensorFlow Lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, saved models in the flatbuffer format use a do...
CVE-2020-15210MEDIUM6.5In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, if a TFLite saved model uses the same tensor a...
CVE-2020-15209MEDIUM5.9In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, a crafted TFLite model can force a node to hav...
CVE-2020-15208CRITICAL9.8In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, when determining the common dimension size of ...
CVE-2020-15207CRITICAL9In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, to mimic Python's indexing with negative value...
CVE-2020-15206HIGH7.5In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, changing the TensorFlow's `SavedModel` protocol buf...
CVE-2020-15205CRITICAL9.8In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `data_splits` argument of `tf.raw_ops.StringNGr...
CVE-2020-15204MEDIUM5.3In eager mode, TensorFlow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1 does not set the session state. Hence, c...
CVE-2020-15203HIGH7.5In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, by controlling the `fill` argument of tf.strings.as...
CVE-2020-15202CRITICAL9In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `Shard` API in TensorFlow expects the last argu...
CVE-2020-15201MEDIUM4.8In Tensorflow before version 2.3.1, the `RaggedCountSparseOutput` implementation does not validate that the input argume...
CVE-2020-15200MEDIUM5.9In Tensorflow before version 2.3.1, the `RaggedCountSparseOutput` implementation does not validate that the input argume...
CVE-2020-15199MEDIUM5.9In Tensorflow before version 2.3.1, the `RaggedCountSparseOutput` does not validate that the input arguments form a vali...
CVE-2020-15198MEDIUM5.4In Tensorflow before version 2.3.1, the `SparseCountSparseOutput` implementation does not validate that the input argume...
CVE-2020-15197MEDIUM6.3In Tensorflow before version 2.3.1, the `SparseCountSparseOutput` implementation does not validate that the input argume...
CVE-2020-15196CRITICAL9.9In Tensorflow version 2.3.0, the `SparseCountSparseOutput` and `RaggedCountSparseOutput` implementations don't validate ...
CVE-2020-15195HIGH8.8In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the implementation of `SparseFillEmptyRowsGrad` use...
CVE-2020-15194MEDIUM5.3In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `SparseFillEmptyRowsGrad` implementation has in...
CVE-2020-15193HIGH7.1In Tensorflow before versions 2.2.1 and 2.3.1, the implementation of `dlpack.to_dlpack` can be made to use uninitialized...
CVE-2020-15192MEDIUM4.3In Tensorflow before versions 2.2.1 and 2.3.1, if a user passes a list of strings to `dlpack.to_dlpack` there is a memor...
CVE-2020-15191MEDIUM5.3In Tensorflow before versions 2.2.1 and 2.3.1, if a user passes an invalid argument to `dlpack.to_dlpack` the expected v...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now