Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ollama vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv3
CVE-2024-45436
extractFromZipFile in model.go in Ollama prior to 0.1.47 can extract members of a ZIP archive outside of the parent directory.
Ollama Ollama
4 Github repositories
7.5
CVSSv3
CVE-2025-0317
A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to upload and create a customized GGUF model file on the Ollama server. This can lead to a division by zero error in the ggufPadding function, causing the server to crash and resulting in a Denial of Se...
Ollama Ollama/ollama
NA
CVE-2024-37032
Ollama prior to 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path, and thus mishandles the TestGetBlobsPath test cases such as fewer than 64 hex digits, more than 64 hex digits, or an initial ../ substring.
3 Github repositories
1 Article
7.5
CVSSv3
CVE-2025-0315
A vulnerability in ollama/ollama <=0.3.14 allows a malicious user to create a customized GGUF model file, upload it to the Ollama server, and create it. This can cause the server to allocate unlimited memory, leading to a Denial of Service (DoS) attack.
7.5
CVSSv3
CVE-2025-0312
A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to create a customized GGUF model file that, when uploaded and created on the Ollama server, can cause a crash due to an unchecked null pointer dereference. This can lead to a Denial of Service (DoS) at...
7.5
CVSSv3
CVE-2024-8063
A divide by zero vulnerability exists in ollama/ollama version v0.3.3. The vulnerability occurs when importing GGUF models with a crafted type for `block_count` in the Modelfile. This can lead to a denial of service (DoS) condition when the server processes the model, causing it ...
7.5
CVSSv3
CVE-2025-0313
A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to create a GGUF model that can cause a denial of service (DoS) attack. The vulnerability is due to improper validation of array index bounds in the GGUF model handling code, which can be exploited via ...
7.5
CVSSv3
CVE-2024-39722
An issue exists in Ollama prior to 0.1.46. It exposes which files exist on the server on which it is deployed via path traversal in the api/push route.
7.5
CVSSv3
CVE-2024-12055
A vulnerability in Ollama versions <=0.3.14 allows a malicious user to create a customized gguf model file that can be uploaded to the public Ollama server. When the server processes this malicious model, it crashes, leading to a Denial of Service (DoS) attack. The root cause ...
7.5
CVSSv3
CVE-2024-12886
An Out-Of-Memory (OOM) vulnerability exists in the `ollama` server version 0.3.14. This vulnerability can be triggered when a malicious API server responds with a gzip bomb HTTP response, leading to the `ollama` server crashing. The vulnerability is present in the `makeRequestWit...
Preferred Score:
CVSSv3
CVSSv2
CVSSv3
CVSSv4
EPSS
VMScore
Recommendations:
CVE-2025-42599
CVE-2025-3808
phpgurukul
insecure direct object reference
CVE-2025-3840
CVE-2025-43967
men salon management system
denial of service
virtuemart component for joomla
pritunl
LFI
CVE-2025-32433
CVE-2022-47112
Home
/
Search Results
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »