VYPR

HDF5

by HDF

Source repositories

CVEs (64)

  • CVE-2017-17509HigDec 11, 2017
    risk 0.57cvss 8.8epss 0.02

    In HDF5 1.10.1, there is an out of bounds write vulnerability in the function H5G__ent_decode_vec in H5Gcache.c in libhdf5.a. For example, h5dump would crash or possibly have unspecified other impact someone opens a crafted hdf5 file.

  • CVE-2016-4333HigNov 18, 2016
    risk 0.56cvss 8.6epss 0.01

    The HDF5 1.8.16 library allocating space for the array using a value from the file has an impact within the loop for initializing said array allowing a value within the file to modify the loop's terminator. Due to this, an aggressor can cause the loop's index to point outside…

  • CVE-2016-4332HigNov 18, 2016
    risk 0.56cvss 8.6epss 0.01

    The library's failure to check if certain message types support a particular flag, the HDF5 1.8.16 library will cast the structure to an alternative structure and then assign to fields that aren't supported by the message type and the library will write outside the bounds of the…

  • CVE-2016-4331HigNov 18, 2016
    risk 0.56cvss 8.6epss 0.01

    When decoding data out of a dataset encoded with the H5Z_NBIT decoding, the HDF5 1.8.16 library will fail to ensure that the precision is within the bounds of the size leading to arbitrary code execution.

  • CVE-2018-11205HigMay 16, 2018
    risk 0.53cvss 8.1epss 0.02

    A out of bounds read was discovered in H5VM_memcpyvv in H5VM.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service or information disclosure attack.

  • CVE-2018-13875HigJul 10, 2018
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in the HDF HDF5 1.8.20 library. There is an out-of-bounds read in the function H5VM_memcpyvv in H5VM.c.

  • CVE-2026-19025MedAug 5, 2026
    risk 0.44cvss epss 0.00

    H5O__layout_decode in H5Olayout.c in HDF5 through 2.3.0 does not validate that a chunked dataset's stored chunk-layout dimensionality matches its dataspace rank when an existing dataset is opened, whereas this check is performed only at dataset-creation time. This allows…

  • CVE-2019-8398MedFeb 17, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in the HDF HDF5 1.10.4 library. There is an out of bounds read in the function H5T_get_size in H5T.c.

  • CVE-2019-8397MedFeb 17, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in the HDF HDF5 1.10.4 library. There is an out of bounds read in the function H5T_close_real in H5T.c.

  • CVE-2019-8396MedFeb 17, 2019
    risk 0.42cvss 6.5epss 0.01

    A buffer overflow in H5O__layout_encode in H5Olayout.c in the HDF HDF5 through 1.10.4 library allows attackers to cause a denial of service via a crafted HDF5 file. This issue was triggered while repacking an HDF5 file, aka "Invalid write of size 2."

  • CVE-2018-17438MedSep 24, 2018
    risk 0.42cvss 6.5epss 0.02

    A SIGFPE signal is raised in the function H5D__select_io() of H5Dselect.c in the HDF HDF5 through 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. It could allow a remote denial of service attack.

  • CVE-2018-17437MedSep 24, 2018
    risk 0.42cvss 6.5epss 0.01

    Memory leak in the H5O_dtype_decode_helper() function in H5Odtype.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service (memory consumption) via a crafted HDF5 file.

  • CVE-2018-17436MedSep 24, 2018
    risk 0.42cvss 6.5epss 0.01

    ReadCode() in decompress.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service (invalid write access) via a crafted HDF5 file. This issue was triggered while converting a GIF file to an HDF file.

  • CVE-2018-17435MedSep 24, 2018
    risk 0.42cvss 6.5epss 0.01

    A heap-based buffer over-read in H5O_attr_decode() in H5Oattr.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service via a crafted HDF5 file. This issue was triggered while converting an HDF file to GIF file.

  • CVE-2018-17434MedSep 24, 2018
    risk 0.42cvss 6.5epss 0.02

    A SIGFPE signal is raised in the function apply_filters() of h5repack_filters.c in the HDF HDF5 through 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. It could allow a remote denial of service attack.

  • CVE-2018-17433MedSep 24, 2018
    risk 0.42cvss 6.5epss 0.01

    A heap-based buffer overflow in ReadGifImageDesc() in gifread.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service via a crafted HDF5 file. This issue was triggered while converting a GIF file to an HDF file.

  • CVE-2018-17234MedSep 20, 2018
    risk 0.42cvss 6.5epss 0.01

    Memory leak in the H5O__chunk_deserialize() function in H5Ocache.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service (memory consumption) via a crafted HDF5 file.

  • CVE-2018-17233MedSep 20, 2018
    risk 0.42cvss 6.5epss 0.02

    A SIGFPE signal is raised in the function H5D__create_chunk_file_map_hyper() of H5Dchunk.c in the HDF HDF5 through 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. It could allow a remote denial of service…

  • CVE-2018-15671MedAug 21, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in the HDF HDF5 1.10.2 library. Excessive stack consumption has been detected in the function H5P__get_cb() in H5Pint.c during an attempted parse of a crafted HDF file. This results in denial of service.

  • CVE-2018-11204MedMay 16, 2018
    risk 0.42cvss 6.5epss 0.02

    A NULL pointer dereference was discovered in H5O__chunk_deserialize in H5Ocache.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.