Search CVE reports


Toggle filters

21 – 30 of 44 results


CVE-2025-2999

Medium priority
Needs evaluation

A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to memory corruption. Attacking locally is a requirement....

1 affected package

pytorch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pytorch Not in release Needs evaluation Not in release
Show less packages

CVE-2025-2998

Medium priority
Needs evaluation

A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the function torch.nn.utils.rnn.pad_packed_sequence. The manipulation leads to memory corruption. Local access is...

1 affected package

pytorch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pytorch Not in release Needs evaluation Not in release
Show less packages

CVE-2025-2953

Medium priority
Needs evaluation

A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of service. An attack has to be...

1 affected package

pytorch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pytorch Not in release Needs evaluation Not in release
Show less packages

CVE-2024-7804

Medium priority
Ignored

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

1 affected package

pytorch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pytorch Not in release Not affected Not in release
Show less packages

CVE-2025-2149

Medium priority
Needs evaluation

A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function nnq_Sigmoid of the component Quantized Sigmoid Module. The manipulation of the argument scale/zero_point...

1 affected package

pytorch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pytorch Not in release Needs evaluation Not in release
Show less packages

CVE-2025-2148

Medium priority
Needs evaluation

A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critical. Affected by this vulnerability is the function torch.ops.profiler._call_end_callbacks_on_jit_fut of the component Tuple Handler. The manipulation...

1 affected package

pytorch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pytorch Not in release Needs evaluation Not in release
Show less packages

CVE-2024-53849

Medium priority
Fixed

editorconfig-core-c is theEditorConfig core library written in C (for use by plugins supporting EditorConfig parsing). In affected versions several overflows may occur in switch case '[' when the input pattern contains...

1 affected package

editorconfig-core

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
editorconfig-core Not affected Fixed Fixed Fixed
Show less packages

CVE-2024-48063

Medium priority
Needs evaluation

In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch distributed computing.

1 affected package

pytorch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pytorch Not in release Needs evaluation Not in release
Show less packages

CVE-2024-40897

Medium priority
Fixed

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the...

1 affected package

orc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
orc Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-35198

Medium priority
Ignored

TorchServe is a flexible and easy-to-use tool for serving and scaling PyTorch models in production. TorchServe 's check on allowed_urls configuration can be by-passed if the URL contains characters such as ".." but it does not...

1 affected package

pytorch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pytorch Not in release Not affected Not in release
Show less packages