Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM functions have an off by one string copy.
2024-02-23T18:15:50.960
2025-02-13T18:17:29.507
Modified
6f8de1f0-f67e-45a6-b68f-98777fdb759c
CVSSv3.1: 4.4 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | linuxfoundation | onnx | < 1.16.0 | Yes |
Operating System | fedoraproject | fedora | 39 | Yes |
Operating System | fedoraproject | fedora | 40 | Yes |