CVE-2025-0312
- EPSS 0.62%
- Veröffentlicht 20.03.2025 10:10:53
- Zuletzt bearbeitet 28.03.2025 14:11:12
A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to create a customized GGUF model file that, when uploaded and created on the Ollama server, can cause a crash due to an unchecked null pointer dereference. This can lead to a...
CVE-2024-12886
- EPSS 0.71%
- Veröffentlicht 20.03.2025 10:10:28
- Zuletzt bearbeitet 15.04.2026 00:35:42
An Out-Of-Memory (OOM) vulnerability exists in the `ollama` server version 0.3.14. This vulnerability can be triggered when a malicious API server responds with a gzip bomb HTTP response, leading to the `ollama` server crashing. The vulnerability is ...
CVE-2025-0317
- EPSS 14.03%
- Veröffentlicht 20.03.2025 10:10:02
- Zuletzt bearbeitet 02.04.2025 16:07:20
A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to upload and create a customized GGUF model file on the Ollama server. This can lead to a division by zero error in the ggufPadding function, causing the server to crash and ...
CVE-2025-0315
- EPSS 0.64%
- Veröffentlicht 20.03.2025 10:09:48
- Zuletzt bearbeitet 02.04.2025 16:02:38
A vulnerability in ollama/ollama <=0.3.14 allows a malicious user to create a customized GGUF model file, upload it to the Ollama server, and create it. This can cause the server to allocate unlimited memory, leading to a Denial of Service (DoS) atta...
CVE-2024-12055
- EPSS 0.79%
- Veröffentlicht 20.03.2025 10:08:47
- Zuletzt bearbeitet 13.05.2025 13:28:08
A vulnerability in Ollama versions <=0.3.14 allows a malicious user to create a customized gguf model file that can be uploaded to the public Ollama server. When the server processes this malicious model, it crashes, leading to a Denial of Service (D...
CVE-2024-39722
- EPSS 3.97%
- Veröffentlicht 31.10.2024 20:15:05
- Zuletzt bearbeitet 13.05.2025 14:24:04
An issue was discovered in Ollama before 0.1.46. It exposes which files exist on the server on which it is deployed via path traversal in the api/push route.
CVE-2024-39721
- EPSS 2.67%
- Veröffentlicht 31.10.2024 20:15:04
- Zuletzt bearbeitet 13.05.2025 12:53:35
An issue was discovered in Ollama before 0.1.34. The CreateModelHandler function uses os.Open to read a file until completion. The req.Path parameter is user-controlled and can be set to /dev/random, which is blocking, causing the goroutine to run in...
CVE-2024-39720
- EPSS 2.46%
- Veröffentlicht 31.10.2024 20:15:04
- Zuletzt bearbeitet 13.05.2025 13:28:14
An issue was discovered in Ollama before 0.1.46. An attacker can use two HTTP requests to upload a malformed GGUF file containing just 4 bytes starting with the GGUF custom magic header. By leveraging a custom Modelfile that includes a FROM statement...
CVE-2024-39719
- EPSS 4.28%
- Veröffentlicht 31.10.2024 20:15:04
- Zuletzt bearbeitet 13.05.2025 13:32:48
An issue was discovered in Ollama through 0.3.14. File existence disclosure can occur via api/create. When calling the CreateModel route with a path parameter that does not exist, it reflects the "File does not exist" error message to the attacker, p...
CVE-2024-45436
- EPSS 2.56%
- Veröffentlicht 29.08.2024 03:15:05
- Zuletzt bearbeitet 30.08.2024 16:08:54
extractFromZipFile in model.go in Ollama before 0.1.47 can extract members of a ZIP archive outside of the parent directory.