CVE-2018-21233

MEDIUM

Google Tensorflow < 1.7.0 - Out-of-Bounds Read

Title source: rule
STIX 2.1

Description

TensorFlow before 1.7.0 has an integer overflow that causes an out-of-bounds read, possibly causing disclosure of the contents of process memory. This occurs in the DecodeBmp feature of the BMP decoder in core/kernels/decode_bmp_op.cc.

Scores

CVSS v3 6.5
EPSS 0.0013
EPSS Percentile 31.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Details

CWE
CWE-125
Status published
Products (3)
google/tensorflow < 1.7.0
pypi/tensorflow 0 - 1.7.0PyPI
pypi/tensorflow-gpu 0 - 1.7.0PyPI
Published May 04, 2020
Tracked Since Feb 18, 2026