Google TensorFlow 1.7 and below is affected by: Buffer Overflow. The impact is: execute arbitrary code (local). Users passing a malformed or malicious version of a TFLite graph into TOCO will cause TOCO to crash or cause a buffer overflow, potentially allowing malicious code to be executed.
{
"nvd_published_at": "2019-04-23T21:29:00Z",
"github_reviewed_at": "2019-04-24T16:11:11Z",
"severity": "HIGH",
"cwe_ids": [
"CWE-119"
],
"github_reviewed": true
}