High
CVSS: 7.5
An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the fs/ggml/gguf.go, function readGGUFV1String reads a string length from untrusted GGUF metadata
High
CVSS: 7.5
An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the GGUF decoder
High
CVSS: 8.7
Ollama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in the multi-modal model image processing functionality. When processing base64-encoded image data via the /api/chat endpoint, the application…
Critical
CVSS: 9.8
A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exposes multiple API endpoints without requiring authentication, enabling remote attackers to…
Medium
CVSS: 6.6
An issue in Ollama v0.1.33 allows attackers to delete arbitrary files via sending a crafted packet to the endpoint /api/pull.
Medium
CVSS: 6.9
Cross-Domain Token Exposure in server.auth.getAuthorizationToken in Ollama 0.6.7 allows remote attackers to steal authentication tokens and bypass access controls via a malicious realm value in a WWW-Authenticate header returned by the /api…
High
CVSS: 7.5
A vulnerability in the Ollama server version 0.5.11 allows a malicious user to cause a Denial of Service (DoS) attack by customizing the manifest content and spoofing a service. This is due to improper validation of array index access when…
High
CVSS: 7.5
A vulnerability in ollama/ollama versions
High
CVSS: 7.5
A vulnerability in ollama/ollama
High
CVSS: 7.5
A vulnerability in ollama/ollama versions
High
CVSS: 7.5
A divide by zero vulnerability exists in ollama/ollama version v0.3.3. The vulnerability occurs when importing GGUF models with a crafted type for `block_count` in the Modelfile. This can lead to a denial of service (DoS) condition when the…
High
CVSS: 7.5
A vulnerability in Ollama versions