CVE-2024-32878
- EPSS 0.7%
- Veröffentlicht 26.04.2024 21:15:49
- Zuletzt bearbeitet 02.09.2025 18:30:15
Llama.cpp is LLM inference in C/C++. There is a use of uninitialized heap variable vulnerability in gguf_init_from_file, the code will free this uninitialized variable later. In a simple POC, it will directly cause a crash. If the file is carefully c...
CVE-2024-23605
- EPSS 1.35%
- Veröffentlicht 26.02.2024 16:27:57
- Zuletzt bearbeitet 27.04.2026 17:44:30
A heap-based buffer overflow vulnerability exists in the GGUF library header.n_kv functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerabi...
CVE-2024-23496
- EPSS 1.35%
- Veröffentlicht 26.02.2024 16:27:56
- Zuletzt bearbeitet 27.04.2026 17:42:23
A heap-based buffer overflow vulnerability exists in the GGUF library gguf_fread_str functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code execution. An attacker can provide a malicious file to trigger this vulner...
CVE-2024-21802
- EPSS 1.38%
- Veröffentlicht 26.02.2024 16:27:55
- Zuletzt bearbeitet 27.04.2026 17:42:41
A heap-based buffer overflow vulnerability exists in the GGUF library info->ne functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerabi...
CVE-2024-21825
- EPSS 1.35%
- Veröffentlicht 26.02.2024 16:27:55
- Zuletzt bearbeitet 27.04.2026 17:42:08
A heap-based buffer overflow vulnerability exists in the GGUF library GGUF_TYPE_ARRAY/GGUF_TYPE_STRING parsing functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code execution. An attacker can provide a malicious f...
CVE-2024-21836
- EPSS 1.35%
- Veröffentlicht 26.02.2024 16:27:55
- Zuletzt bearbeitet 27.04.2026 17:42:49
A heap-based buffer overflow vulnerability exists in the GGUF library header.n_tensors functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code execution. An attacker can provide a malicious file to trigger this vuln...