liqun Fu

2 exploits Active since Feb 2024
CVE-2024-27318 WRITEUP HIGH WRITEUP
ONNX < 1.16.0 - Path Traversal via External Data Field
Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory. The vulnerability occurs as a bypass for the patch added for CVE-2022-25882.
CVSS 7.5
CVE-2024-27319 WRITEUP MEDIUM WRITEUP
ONNX < 1.16.0 - Out-of-bounds Read via ONNX_ASSERT Function
Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM functions have an off by one string copy.
CVSS 4.4