Ollama
cpe:2.3:a:ollama:ollama:*:*:*:*:*:*:*
- <= 0.3.14
A denial-of-service vulnerability has been identified in Ollama versions through 0.3.14. This issue allows a malicious user to upload a customized gguf model file to the public Ollama server. The server crashes while processing this harmful model, leading to a denial-of-service condition. The vulnerability arises from an out-of-bounds read in the gguf.go file.
Exploitation of this vulnerability causes the server to crash, creating a denial-of-service condition.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.