Vulnerabilities > Paddlepaddle > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-01-03 CVE-2023-52304 Out-of-bounds Write vulnerability in Paddlepaddle 0.8.0/0.9.0/1.0.1
Stack overflow in paddle.searchsorted in PaddlePaddle before 2.6.0.
network
low complexity
paddlepaddle CWE-787
critical
9.8
2024-01-03 CVE-2023-52307 Out-of-bounds Write vulnerability in Paddlepaddle 0.8.0/0.9.0/1.0.1
Stack overflow in paddle.linalg.lu_unpack in PaddlePaddle before 2.6.0.
network
low complexity
paddlepaddle CWE-787
critical
9.8
2024-01-03 CVE-2023-52309 Out-of-bounds Write vulnerability in Paddlepaddle 0.8.0/0.9.0/1.0.1
Heap buffer overflow in paddle.repeat_interleave in PaddlePaddle before 2.6.0.
network
low complexity
paddlepaddle CWE-787
critical
9.8
2024-01-03 CVE-2023-52310 OS Command Injection vulnerability in Paddlepaddle 0.8.0/0.9.0/1.0.1
PaddlePaddle before 2.6.0 has a command injection in get_online_pass_interval.
network
low complexity
paddlepaddle CWE-78
critical
9.8
2024-01-03 CVE-2023-52311 OS Command Injection vulnerability in Paddlepaddle 0.8.0/0.9.0/1.0.1
PaddlePaddle before 2.6.0 has a command injection in _wget_download.
network
low complexity
paddlepaddle CWE-78
critical
9.8
2024-01-03 CVE-2023-52314 OS Command Injection vulnerability in Paddlepaddle 0.8.0/0.9.0/1.0.1
PaddlePaddle before 2.6.0 has a command injection in convert_shape_compare.
network
low complexity
paddlepaddle CWE-78
critical
9.8
2023-07-26 CVE-2023-38673 OS Command Injection vulnerability in Paddlepaddle
PaddlePaddle before 2.5.0 has a command injection in fs.py.
network
low complexity
paddlepaddle CWE-78
critical
9.8
2023-07-26 CVE-2023-38671 Out-of-bounds Write vulnerability in Paddlepaddle
Heap buffer overflow in paddle.trace in PaddlePaddle before 2.5.0.
network
low complexity
paddlepaddle CWE-787
critical
9.8
2023-07-26 CVE-2023-38669 Use After Free vulnerability in Paddlepaddle
Use after free in paddle.diagonal in PaddlePaddle before 2.5.0.
network
low complexity
paddlepaddle CWE-416
critical
9.8
2022-12-07 CVE-2022-46742 Code Injection vulnerability in Paddlepaddle 2.4.0
Code injection in paddle.audio.functional.get_window in PaddlePaddle 2.4.0-rc0 allows arbitrary code execution.
network
low complexity
paddlepaddle CWE-94
critical
9.8