Vulnerabilities
Vulnerable Software
PaddlePaddle before 2.5.0 has a command injection in fs.py. This resulted in the ability to execute arbitrary commands on the operating system.
CVSS Score
9.6
EPSS Score
0.003
Published
2023-07-26
Null pointer dereference in paddle.flip in PaddlePaddle before 2.5.0. This resulted in a runtime crash and denial of service.
CVSS Score
4.7
EPSS Score
0.002
Published
2023-07-26
Heap buffer overflow in paddle.trace in PaddlePaddle before 2.5.0. This flaw can lead to a denial of service, information disclosure, or more damage is possible.
CVSS Score
8.3
EPSS Score
0.003
Published
2023-07-26
Use after free in paddle.diagonal in PaddlePaddle before 2.5.0. This resulted in a potentially exploitable condition.
CVSS Score
8.3
EPSS Score
0.003
Published
2023-07-26
Out-of-bounds read in gather_tree in PaddlePaddle before 2.4. 
CVSS Score
7.1
EPSS Score
0.005
Published
2022-12-07
In PaddlePaddle before 2.4, paddle.audio.functional.get_window is vulnerable to code injection because it calls eval on a user-supplied winstr. This may lead to arbitrary code execution.
CVSS Score
9.8
EPSS Score
0.001
Published
2022-11-26


Contact Us

Shodan ® - All rights reserved