CVE-2025-65887
- EPSS 0.3%
- Veröffentlicht 28.01.2026 00:00:00
- Zuletzt bearbeitet 05.07.2026 02:17:30
A division-by-zero vulnerability in the flow.floor_divide() component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input tensor with zero.
CVE-2025-65888
- EPSS 0.37%
- Veröffentlicht 28.01.2026 00:00:00
- Zuletzt bearbeitet 05.07.2026 02:17:30
A dimension validation flaw in the flow.empty() component of OneFlow 0.9.0 allows attackers to cause a Denial of Service (DoS) via a negative or excessively large dimension value.
CVE-2025-71003
- EPSS 0.37%
- Veröffentlicht 28.01.2026 00:00:00
- Zuletzt bearbeitet 03.02.2026 16:54:53
An input validation vulnerability in the flow.arange() component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2025-71002
- EPSS 0.28%
- Veröffentlicht 28.01.2026 00:00:00
- Zuletzt bearbeitet 03.02.2026 16:56:38
A floating-point exception (FPE) in the flow.column_stack component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2025-65891
- EPSS 0.54%
- Veröffentlicht 28.01.2026 00:00:00
- Zuletzt bearbeitet 05.07.2026 02:17:30
A GPU device-ID validation flaw in OneFlow v0.9.0 allows attackers to trigger a Denial of Dervice (DoS) by invoking flow.cuda.get_device_properties() with an invalid or negative device index.
CVE-2025-70999
- EPSS 0.38%
- Veröffentlicht 28.01.2026 00:00:00
- Zuletzt bearbeitet 05.07.2026 02:17:39
A GPU device-ID validation flaw in the flow.cuda.get_device_capability() component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted device ID.
CVE-2025-71000
- EPSS 0.31%
- Veröffentlicht 28.01.2026 00:00:00
- Zuletzt bearbeitet 05.07.2026 02:17:39
An issue in the flow.cuda.BoolTensor component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2025-71001
- EPSS 0.3%
- Veröffentlicht 28.01.2026 00:00:00
- Zuletzt bearbeitet 05.07.2026 02:17:39
A segmentation violation in the flow.column_stack component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2025-63397
- EPSS 0.32%
- Veröffentlicht 10.11.2025 00:00:00
- Zuletzt bearbeitet 05.07.2026 02:17:20
Improper input validation in OneFlow v0.9.0 allows attackers to cause a segmentation fault via adding a Python sequence to the native code during broadcasting/type conversion.
CVE-2024-36734
- EPSS 0.52%
- Veröffentlicht 06.06.2024 19:15:58
- Zuletzt bearbeitet 02.05.2025 12:49:19
Improper input validation in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputting a negative value into the dim parameter.