Russell Bryant
18 exploits
Active since Apr 2008
Asterisk Open Source <1.2.28-1.4.19.1 - DoS
Asterisk Open Source <1.2.28-1.4.19.1 - DoS
OpenStack Compute (Nova) Essex and Folsom - Authenticated Path Traversal via Disk Image File Path Attribute
OpenStack Compute (Nova) Diablo Essex Folsom - Authenticated Arbitrary File Write via Symlink Attack
vllm < 0.11.0 - Timing Attack via API Key Validation
CVSS 7.5
vLLM 0.5.5-0.11.1 - Denial of Service via Unvalidated chat_template_kwargs Parameter
CVSS 6.5
vLLM Affected by Unauthenticated OOM Denial of Service via Unbounded `n` Parameter in OpenAI API Server
CVSS 6.5
vLLM's hardcoded trust_remote_code=True in NemotronVL and KimiK25 bypasses user security opt-out
CVSS 8.8
vLLM 0.15.1-0.17.0 - Server-Side Request Forgery via URL Parsing Inconsistency
CVSS 7.1
vllm < 0.7.0 - Remote Code Execution via Pickle Deserialization in Model Weight Loading
CVSS 7.5
vLLM 0.5.2-0.8.5 - Denial of Service and Data Exposure via ZeroMQ Socket
CVSS 7.5
vllm 0.6.5-0.8.5 - Remote Code Execution via Pickle Deserialization
CVSS 10.0
vllm 0.8.0-0.9.0 - Denial of Service via Invalid JSON Schema in /v1/completions API
CVSS 6.5
vLLM 0.8.0-0.8.9 - Denial of Service via Invalid Regex in Structured Output
CVSS 6.5
vLLM 0.1.0-0.10.1.0 - Unauthenticated Denial of Service via Large HTTP Header
CVSS 7.5
vLLM 0.10.2-0.11.1 - Remote Code Execution via Malicious Prompt Embedding Tensors
CVSS 8.8
vLLM 0.5.5-0.11.1 - Denial of Service via Multimodal Embedding Input Shape Mismatch
CVSS 6.5
Asterisk 1.8.x < 1.8.10.1 and 10.x < 10.2.1 - Stack-Based Buffer Overflow via HTTP Digest Authentication Header