7.5
CVE-2024-8063
- EPSS 0.59%
- Veröffentlicht 20.03.2025 10:10:56
- Zuletzt bearbeitet 13.05.2025 13:28:05
- Quelle security@huntr.dev
- CVE-Watchlists
- Unerledigt
Divide by Zero in ollama/ollama
A divide by zero vulnerability exists in ollama/ollama version v0.3.3. The vulnerability occurs when importing GGUF models with a crafted type for `block_count` in the Modelfile. This can lead to a denial of service (DoS) condition when the server processes the model, causing it to crash.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.59% | 0.435 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| security@huntr.dev | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-369 Divide By Zero
The product divides a value by zero.
https://huntr.com/bounties/fd8e1ed6-21d2-4c9e-8395-2098f11b7db9