Google TensorFlow 1.7 and below is affected by: Buffer Overflow. The impact is: execute arbitrary code (local). Users passing a malformed or malicious version of a TFLite graph into TOCO will cause TOCO to crash or cause a buffer overflow, potentially allowing malicious code to be executed.
{ "severity": "HIGH", "nvd_published_at": "2019-04-23T21:29:00Z", "github_reviewed": true, "github_reviewed_at": "2019-04-24T16:11:11Z", "cwe_ids": [ "CWE-119" ] }