| CVE-2025-66960 |
unknown |
— |
— |
|
|
|
4mo ago |
An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the fs/ggml/gguf.go, function readGGUFV1String reads a string length from untrusted GGUF metadata |
| CVE-2025-66959 |
unknown |
— |
— |
|
|
|
4mo ago |
An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the GGUF decoder |
| CVE-2025-44779 |
unknown |
— |
— |
|
|
|
10mo ago |
An issue in Ollama v0.1.33 allows attackers to delete arbitrary files via sending a crafted packet to the endpoint /api/pull. |
| CVE-2025-51471 |
unknown |
— |
— |
|
|
|
11mo ago |
Cross-Domain Token Exposure in server.auth.getAuthorizationToken in Ollama 0.6.7 allows remote attackers to steal authentication tokens and bypass access controls via a malicious realm value in a WWW… |
| CVE-2025-1975 |
unknown |
— |
— |
|
|
|
1y ago |
A vulnerability in the Ollama server version 0.5.11 allows a malicious user to cause a Denial of Service (DoS) attack by customizing the manifest content and spoofing a service. This is due to improp… |
| CVE-2024-8063 |
unknown |
— |
— |
|
|
|
1y ago |
A divide by zero vulnerability exists in ollama/ollama version v0.3.3. The vulnerability occurs when importing GGUF models with a crafted type for `block_count` in the Modelfile. This can lead to a d… |