CVE-2018-21233: Google Tensorflow
Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.
TensorFlow before 1.7.0 has an integer overflow that causes an out-of-bounds read, possibly causing disclosure of the contents of process memory. This occurs in the DecodeBmp feature of the BMP decoder in core/kernels/decode_bmp_op.cc.
Affected products
- Google Tensorflow: before 1.7.0 (fixed in 1.7.0)
Published 2020-05-04. Last modified 2026-06-17.