Linux Foundation ONNX (Open Neural Network Exchange) 1.3.0

CPE Details

Linux Foundation ONNX (Open Neural Network Exchange) 1.3.0
1.3.0
2023-02-01
11h13 +00:00
2023-02-02
11h16 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:linuxfoundation:onnx:1.3.0:*:*:*:*:*:*:*

Informations

Vendor

linuxfoundation

Product

onnx

Version

1.3.0

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-27319 2024-02-23 17h39 +00:00 Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM functions have an off by one string copy.
9.1
Critical
CVE-2024-27318 2024-02-23 17h37 +00:00 Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory. The vulnerability occurs as a bypass for the patch added for CVE-2022-25882.
7.5
High
CVE-2022-25882 2023-01-25 05h00 +00:00 Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory, for example "../../../etc/passwd"
7.5
High