-
CVE-2022-23587 – Grappler component of TensorFlow is vulnerable to an integer overflow during cost estimation for crop and resize. (15th Feb 2022)
Preface: The number 2,147,483,647 (or hexadecimal 7FFF,FFFF) is the maximum positive value for a 32-bit signed binary integer. Background: TensorFlow is an end-to-end open source platform for machine learning. It has a comprehensive, flexible ecosystem of tools, libraries and community resources that lets researchers push the state-of-the-art in ML and developers easily build and deploy…
-
About CVE-2022-21818 (NIVIDIA License System) – 15th Feb 2022
Preface: The registration of CVE records is largely out of sync with the time of the event. Perhaps the new release of CVE record by today, however it was happened few weeks or months ago. But with reference of these vulnerabilities records. Vulnerability scanner can precisely provide a result to you after scan. Background: NVIDIA…
-
CVE-2022-0572 – Heap-based Buffer Overflow in vim (13th Feb, 2022)
Preface: The registration of CVE records is largely out of sync with the time of the event. Perhaps the new release of CVE record by today, however it was happened few weeks or months ago. But with reference of these vulnerabilities records. Vulnerability scanner can precisely provide a result to you after scan. Background: Vim…
-
About CVE-2021-44850 – Zynq 7000 SoC devices design weakness (10th Feb 2022)
Preface: SOC → System on Chip. It is basically a cluster collection or group of different types of processor components like CPU[,GPU,Modems, DSP units and memory units. ASIC → Application Specific Integrated Circuits. ASICs are chip that is basically hardwired to do a specific job. Background: The SD/SDIO controller is compatible with the standard SD…
-
Design weakness found on SwiftNIO HTTP2 (9th Feb 2022)
Preface: Apple has announced the launch of its new operating system, macOS 10.15 Catalina on October 7, 2019. In keeping with Apple’s release cycle, macOS 10.12 Sierra will no longer be receiving security updates. Sierra was replaced by High Sierra 10.13, Mojave 10.14, and the newest Catalina 10.15. Background: SwiftNIO is Apple non-blocking networking library.…
-
About CVE-2022-21173 – ELECOM LAN Router design weakness (8th Feb, 2022)
Preface: Did you know someone is behind your computer? Background: WRH–300x series is wireless LAN router for microminiature hotel corresponding to 11bgn300Mbps which can enjoy the Internet with the speed of about 4 times of LTE line. Ref: 11BGN, 11AGN, and 11AC are wireless standards supported by wireless products. Among them, 11BGN refers to the…
-
CVE-2022-21816 NVIDIA vGPU software vulnerability details (7th Feb, 2022)
Preface: In addition to the traditional CVE risk level criteria, the critical level of vulnerability risk will depend on the processing technique. Background: NVIDIA vGPU software is a graphics virtualization platform that provides virtual machines (VMs) access to NVIDIA GPU technology. In order to fulfill design objective, it is necessary enable an GPUDirect RDMA connection…
-
About CVE-2022-23206 – Apache (Traffic Control) design weakness (6th Feb, 2022)
Preface: The traditional content distribution network (CDN) can no longer meet the specifications of 5G networks because it requires high bandwidth, low latency and on demand massive connections. The bottlenecks of traditional CDN cannot been resolved the rapidly growth in video traffic, rate, and cost. Background: Apache Traffic Server™ software is a fast, scalable and…
-
CVE-2022-23833 – Django triggers an infinite loop when parsing a file. Since design defects consume resources on their own, they may cause denial of service. (3rd Feb, 2022)
Preface: If the loop can be influenced by an attacker, this weakness could allow attackers to consume excessive resources such as CPU or memory. Background: Django itself is web framework used for developing web applications based on python. Which is used for making development proccess more simple and easy. It provides various built in things…
-
About CVE-2022-24122 – Vulnerability resolved two and a half months ago. Just to understanding what is happened (29-01-2022)
Preface: If you are a Kubernetes administrator, doing the resources distribution, may be it is a daily routine job. Regarding to this vulnerability, have you resolve yet? Background: Namespaces are one of the main features of the Linux kernel – they carry out the distinction between kernel resources. It makes sure that a process can…