Onnx Onnx vulnerabilities
2 known vulnerabilities affecting onnx/onnx_onnx.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1
Vulnerabilities
Page 1 of 1
CVE-2024-7776CRITICALCVSS 9.1≥ unspecified, ≤ latest2025-03-20
CVE-2024-7776 [CRITICAL] CWE-22 CVE-2024-7776: A vulnerability in the `download_model` function of the onnx/onnx framework, before and including ve
A vulnerability in the `download_model` function of the onnx/onnx framework, before and including version 1.16.1, allows for arbitrary file overwrite due to inadequate prevention of path traversal attacks in malicious tar files. This vulnerability can be exploited by an attacker to overwrite files in the user's directory, potentially leading to remot
cvelistv5nvd
CVE-2024-5187HIGHCVSS 8.8≥ unspecified, ≤ latest2024-06-06
CVE-2024-5187 [HIGH] CWE-22 CVE-2024-5187: A vulnerability in the `download_model_with_test_data` function of the onnx/onnx framework, version
A vulnerability in the `download_model_with_test_data` function of the onnx/onnx framework, version 1.16.0, allows for arbitrary file overwrite due to inadequate prevention of path traversal attacks in malicious tar files. This vulnerability enables attackers to overwrite any file on the system, potentially leading to remote code execution, deletion of sy
cvelistv5nvd