Записи ggml
29 опубликованных записей вендора ggml.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 41,4 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-190 Integer Overflow or Wraparound6
- CWE-122 Heap-based Buffer Overflow4
- CWE-125 Out-of-bounds Read4
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')2
- CWE-476 NULL Pointer Dereference2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
29 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2024-42479Эксплойта нет | llama.cpp allows write-what-where in rpc_server::set_tensorggml · llama.cpp · CWE-123 | Критическая9,8 | — | 2,6 % | 12 авг. 2024 г. |
39Наблюдать | CVE-2024-21802Эксплойта нет | A heap-based buffer overflow vulnerability exists in the GGUF library info->ne functionality of llama.cpp Commit 18c2e17.ggml · llama.cpp · CWE-122 | Критическая9,8 | — | 1,4 % | 26 февр. 2024 г. |
39Наблюдать | CVE-2024-21836Эксплойта нет | A heap-based buffer overflow vulnerability exists in the GGUF library header.n_tensors functionality of llama.cpp Commit 18c2e17.ggml · llama.cpp · CWE-190 | Критическая9,8 | — | 1,3 % | 26 февр. 2024 г. |
39Наблюдать | CVE-2024-23496Эксплойта нет | A heap-based buffer overflow vulnerability exists in the GGUF library gguf_fread_str functionality of llama.cpp Commit 18c2e17.ggml · llama.cpp · CWE-190 | Критическая9,8 | — | 1,3 % | 26 февр. 2024 г. |
39Наблюдать | CVE-2024-23605Эксплойта нет | A heap-based buffer overflow vulnerability exists in the GGUF library header.n_kv functionality of llama.cpp Commit 18c2e17.ggml · llama.cpp · CWE-190 | Критическая9,8 | — | 1,3 % | 26 февр. 2024 г. |
39Наблюдать | CVE-2024-21825Эксплойта нет | A heap-based buffer overflow vulnerability exists in the GGUF library GGUF_TYPE_ARRAY/GGUF_TYPE_STRING parsing functionality of llama.cpp Coggml · llama.cpp · CWE-190 | Критическая9,8 | — | 1,3 % | 26 февр. 2024 г. |
39Наблюдать | CVE-2026-34159Proof of concept | llama.cpp: Unauthenticated RCE via GRAPH_COMPUTE buffer=0 bypass in llama.cpp RPC backendggml · llama.cpp · CWE-119 | Критическая9,8 | — | 1,2 % | 1 апр. 2026 г. |
39Наблюдать | CVE-2024-42478Эксплойта нет | llama.cpp allows Arbitrary Address Read in rpc_server::get_tensorggml · llama.cpp · CWE-125 | Критическая9,8 | — | 0,6 % | 12 авг. 2024 г. |
39Наблюдать | CVE-2026-21869Эксплойта нет | llama.cpp has Out-of-bounds Write in llama-serverggml · llama.cpp · CWE-787 | Критическая9,8 | — | 0,5 % | 7 янв. 2026 г. |
36Наблюдать | CVE-2026-43629Эксплойта нет | llama.cpp b4882–b9058 Buffer Overflow in KV Cache State Restoreggml · llama.cpp · CWE-190 | Критическая9,2 | — | 0,7 % | 6 авг. 2026 г. |
36Наблюдать | CVE-2026-43631Эксплойта нет | llama.cpp b7492–b9060 Use-After-Free RCE via llama-serverggml · llama.cpp · CWE-362 | Критическая9,2 | — | 0,6 % | 6 авг. 2026 г. |
36Наблюдать | CVE-2026-43632Эксплойта нет | llama.cpp b7492–b9060 Use-After-Free in Tokenization Endpointsggml · llama.cpp · CWE-367 | Критическая9,2 | — | 0,5 % | 6 авг. 2026 г. |
35Наблюдать | CVE-2024-32878Эксплойта нет | Use of Uninitialized Variable Vulnerability in llama.cppggml · llama.cpp · CWE-456 | Высокая8,8 | — | 0,7 % | 26 апр. 2024 г. |
35Наблюдать | CVE-2025-49847Эксплойта нет | llama.cpp Vulnerable to Buffer Overflow via Malicious GGUF Modelggml · llama.cpp · CWE-119 | Высокая8,8 | — | 0,5 % | 17 июн. 2025 г. |
35Наблюдать | CVE-2025-52566Эксплойта нет | llama.cpp tokenizer signed vs. unsigned heap overflowggml · llama.cpp · CWE-119 | Высокая8,8 | — | 0,4 % | 24 июн. 2025 г. |
34Наблюдать | CVE-2026-43628Эксплойта нет | llama.cpp b3978–b9058 Integer Underflow via DRY Samplerggml · llama.cpp · CWE-125 | Высокая8,5 | — | 0,2 % | 6 авг. 2026 г. |
34Наблюдать | CVE-2026-43622Эксплойта нет | llama.cpp b1886–b7445 Double Free via llama-android.cppggml · llama.cpp · CWE-415 | Высокая8,5 | — | 0,2 % | 6 авг. 2026 г. |
34Наблюдать | CVE-2026-70638Proof of concept | llama.cpp b1886–b7445 Integer Overflow via new_1batch() in llama-android.cppggml · llama.cpp · CWE-122 | Высокая8,5 | — | 0,2 % | 6 авг. 2026 г. |
34Наблюдать | CVE-2026-43627Эксплойта нет | llama.cpp b1283–b9058 Integer Overflow in llama_batch_init() Functionggml · llama.cpp · CWE-190 | Высокая8,5 | — | 0,2 % | 6 авг. 2026 г. |
31Наблюдать | CVE-2026-33298Эксплойта нет | llama.cpp has a Heap Buffer Overflow via Integer Overflow in GGUF Tensor Parsingggml · llama.cpp · CWE-122 | Высокая7,8 | — | 0,4 % | 23 мар. 2026 г. |
31Наблюдать | CVE-2026-27940Proof of concept | llama.cpp has a Heap Buffer Overflow via Integer Overflow in `mem_size` Calculation — Bypass of CVE-2025-53630 Fixggml · llama.cpp · CWE-122 | Высокая7,8 | — | 0,2 % | 12 мар. 2026 г. |
30Наблюдать | CVE-2026-52132Эксплойта нет | llama.cpp through commit 97f06e9, when started with the --reranking flag, allows remote attackers to cause a denial of service (std::bad_allggml · llama.cpp · CWE-674 | Высокая7,5 | — | 0,6 % | 1 сент. 2026 г. |
30Наблюдать | CVE-2026-52130Эксплойта нет | llama.cpp b5693 and before is vulnerable to Uncontrolled Recursion in common/json-schema-to-grammar.cpp, resulting in a denial of service.ggml · llama.cpp · CWE-674 | Высокая7,5 | — | 0,5 % | 1 сент. 2026 г. |
30Наблюдать | CVE-2024-42477Эксплойта нет | llama.cpp global-buffer-overflow in ggml_type_sizeggml · llama.cpp · CWE-125 | Высокая7,5 | — | 0,5 % | 12 авг. 2024 г. |
30Наблюдать | CVE-2026-52131Эксплойта нет | llama.cpp b5693 and before has a Reachable Assertion via the gguf_reader::read function.ggml · llama.cpp · CWE-617 | Высокая7,5 | — | 0,4 % | 1 сент. 2026 г. |
- CVE-2024-4247940В плане
llama.cpp allows write-what-where in rpc_server::set_tensor
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %ggml · llama.cpp12 авг. 2024 г.
- CVE-2024-2180239Наблюдать
A heap-based buffer overflow vulnerability exists in the GGUF library info->ne functionality of llama.cpp Commit 18c2e17.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ggml · llama.cpp26 февр. 2024 г.
- CVE-2024-2183639Наблюдать
A heap-based buffer overflow vulnerability exists in the GGUF library header.n_tensors functionality of llama.cpp Commit 18c2e17.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ggml · llama.cpp26 февр. 2024 г.
- CVE-2024-2349639Наблюдать
A heap-based buffer overflow vulnerability exists in the GGUF library gguf_fread_str functionality of llama.cpp Commit 18c2e17.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ggml · llama.cpp26 февр. 2024 г.
- CVE-2024-2360539Наблюдать
A heap-based buffer overflow vulnerability exists in the GGUF library header.n_kv functionality of llama.cpp Commit 18c2e17.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ggml · llama.cpp26 февр. 2024 г.
- CVE-2024-2182539Наблюдать
A heap-based buffer overflow vulnerability exists in the GGUF library GGUF_TYPE_ARRAY/GGUF_TYPE_STRING parsing functionality of llama.cpp Co
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ggml · llama.cpp26 февр. 2024 г.
- CVE-2026-3415939Наблюдать
llama.cpp: Unauthenticated RCE via GRAPH_COMPUTE buffer=0 bypass in llama.cpp RPC backend
КритическаяCVSS 9,8Proof of conceptEPSS 1 %ggml · llama.cpp1 апр. 2026 г.
- CVE-2024-4247839Наблюдать
llama.cpp allows Arbitrary Address Read in rpc_server::get_tensor
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ggml · llama.cpp12 авг. 2024 г.
- CVE-2026-2186939Наблюдать
llama.cpp has Out-of-bounds Write in llama-server
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ggml · llama.cpp7 янв. 2026 г.
- CVE-2026-4362936Наблюдать
llama.cpp b4882–b9058 Buffer Overflow in KV Cache State Restore
КритическаяCVSS 9,2Эксплойта нетEPSS 1 %ggml · llama.cpp6 авг. 2026 г.
- CVE-2026-4363136Наблюдать
llama.cpp b7492–b9060 Use-After-Free RCE via llama-server
КритическаяCVSS 9,2Эксплойта нетEPSS 1 %ggml · llama.cpp6 авг. 2026 г.
- CVE-2026-4363236Наблюдать
llama.cpp b7492–b9060 Use-After-Free in Tokenization Endpoints
КритическаяCVSS 9,2Эксплойта нетEPSS 0 %ggml · llama.cpp6 авг. 2026 г.
- CVE-2024-3287835Наблюдать
Use of Uninitialized Variable Vulnerability in llama.cpp
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %ggml · llama.cpp26 апр. 2024 г.
- CVE-2025-4984735Наблюдать
llama.cpp Vulnerable to Buffer Overflow via Malicious GGUF Model
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %ggml · llama.cpp17 июн. 2025 г.
- CVE-2025-5256635Наблюдать
llama.cpp tokenizer signed vs. unsigned heap overflow
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %ggml · llama.cpp24 июн. 2025 г.
- CVE-2026-4362834Наблюдать
llama.cpp b3978–b9058 Integer Underflow via DRY Sampler
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %ggml · llama.cpp6 авг. 2026 г.
- CVE-2026-4362234Наблюдать
llama.cpp b1886–b7445 Double Free via llama-android.cpp
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %ggml · llama.cpp6 авг. 2026 г.
- CVE-2026-7063834Наблюдать
llama.cpp b1886–b7445 Integer Overflow via new_1batch() in llama-android.cpp
ВысокаяCVSS 8,5Proof of conceptEPSS 0 %ggml · llama.cpp6 авг. 2026 г.
- CVE-2026-4362734Наблюдать
llama.cpp b1283–b9058 Integer Overflow in llama_batch_init() Function
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %ggml · llama.cpp6 авг. 2026 г.
- CVE-2026-3329831Наблюдать
llama.cpp has a Heap Buffer Overflow via Integer Overflow in GGUF Tensor Parsing
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %ggml · llama.cpp23 мар. 2026 г.
- CVE-2026-2794031Наблюдать
llama.cpp has a Heap Buffer Overflow via Integer Overflow in `mem_size` Calculation — Bypass of CVE-2025-53630 Fix
ВысокаяCVSS 7,8Proof of conceptEPSS 0 %ggml · llama.cpp12 мар. 2026 г.
- CVE-2026-5213230Наблюдать
llama.cpp through commit 97f06e9, when started with the --reranking flag, allows remote attackers to cause a denial of service (std::bad_all
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %ggml · llama.cpp1 сент. 2026 г.
- CVE-2026-5213030Наблюдать
llama.cpp b5693 and before is vulnerable to Uncontrolled Recursion in common/json-schema-to-grammar.cpp, resulting in a denial of service.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %ggml · llama.cpp1 сент. 2026 г.
- CVE-2024-4247730Наблюдать
llama.cpp global-buffer-overflow in ggml_type_size
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %ggml · llama.cpp12 авг. 2024 г.
- CVE-2026-5213130Наблюдать
llama.cpp b5693 and before has a Reachable Assertion via the gguf_reader::read function.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %ggml · llama.cpp1 сент. 2026 г.