CVE-2023-25664

TensorFlow vulnerable to Heap Buffer Overflow in AvgPoolGrad

TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, there is a heap buffer overflow in TAvgPoolGrad. A fix is included in TensorFlow 2.12.0 and 2.11.1.


We have discovered 29 live websites that are affected by CVE-2023-25664.

Run a Free Instant Scan




Affected Software

Product  tensorflow
Category JavaScript Libraries
Vulnerable Domains29 live websites (8.10% of tensorflow install base)
Vulnerable Versions
  • from 0 through 2.11.1
Vulnerable Versions Count5 versions ( 71% of all versions)


Common Weakness Enumeration

CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')



Details

  • Published - Mar 24, 2023
  • Updated - Feb 19, 2025

Website Distribution by Country

Number of websites using CVE-2023-25664
United States20 websites



Germany2 websites
India2 websites
United Arab Emirates1 websites
Brazil1 websites
Canada1 websites
Korea, South1 websites
Netherlands1 websites

Website Distribution by TLD

Number of websites using CVE-2023-25664
.com15 websites
.net3 websites
.com.br1 websites
.io1 websites
.org1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-25664

Top websites that are affected by CVE-2023-25664. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.com United States***,***
************.com United States***,***
******.me United States*,***,***
***********.com United States*,***,***
************.com United States*,***,***
****.net United States*,***,***
***********.com United States*,***,***
**********.*****.agency United Arab Emirates*,***,***
*******.**.kr Korea, South*,***,***
**********.com Netherlands*,***,***
See full domain list

FAQ

CVE-2023-25664 is Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in tensorflow
A total of 29 websites have been identified as vulnerable to CVE-2023-25664, based on global website indexing conducted by WebTechSurvey.
The tensorflow is affected by the CVE-2023-25664 vulnerability.
tensorflow versions up to 2.11.1 are vulnerable to CVE-2023-25664.
CVE-2023-25664 is resolved in version 2.11.1 of tensorflow.