VYPR
Vendor

Hdfgroup

Products
2
CVEs
75
Across products
75
Status
Private

Products

2

Recent CVEs

75
View all 75 CVEs →
  • CVE-2018-13876CriJul 10, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in the HDF HDF5 1.8.20 library. There is a stack-based buffer overflow in the function H5FD_sec2_read in H5FDsec2.c, related to HDread.

  • CVE-2018-13874CriJul 10, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in the HDF HDF5 1.8.20 library. There is a stack-based buffer overflow in the function H5FD_sec2_read in H5FDsec2.c, related to HDmemset.

  • CVE-2018-13873CriJul 10, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in the HDF HDF5 1.8.20 library. There is a buffer over-read in H5O_chunk_deserialize in H5Ocache.c.

  • CVE-2018-13872CriJul 10, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer overflow in the function H5G_ent_decode in H5Gent.c.

  • CVE-2018-13871CriJul 10, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer overflow in the function H5FL_blk_malloc in H5FL.c.

  • CVE-2018-13868CriJul 10, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5O_fill_old_decode in H5Ofill.c.

  • CVE-2018-13866CriJul 10, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in the HDF HDF5 1.8.20 library. There is a stack-based buffer over-read in the function H5F_addr_decode_len in H5Fint.c.

  • CVE-2018-14035HigJul 13, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5VM_memcpyvv in H5VM.c.

  • CVE-2018-14034HigJul 13, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in the HDF HDF5 1.8.20 library. There is an out of bounds read in the function H5O_pline_reset in H5Opline.c.

  • CVE-2017-17509HigDec 11, 2017
    risk 0.57cvss 8.8epss 0.02

    In HDF5 1.10.1, there is an out of bounds write vulnerability in the function H5G__ent_decode_vec in H5Gcache.c in libhdf5.a. For example, h5dump would crash or possibly have unspecified other impact someone opens a crafted hdf5 file.

  • CVE-2016-4333HigNov 18, 2016
    risk 0.56cvss 8.6epss 0.01

    The HDF5 1.8.16 library allocating space for the array using a value from the file has an impact within the loop for initializing said array allowing a value within the file to modify the loop's terminator. Due to this, an aggressor can cause the loop's index to point outside…

  • CVE-2016-4332HigNov 18, 2016
    risk 0.56cvss 8.6epss 0.01

    The library's failure to check if certain message types support a particular flag, the HDF5 1.8.16 library will cast the structure to an alternative structure and then assign to fields that aren't supported by the message type and the library will write outside the bounds of the…

  • CVE-2016-4331HigNov 18, 2016
    risk 0.56cvss 8.6epss 0.01

    When decoding data out of a dataset encoded with the H5Z_NBIT decoding, the HDF5 1.8.16 library will fail to ensure that the precision is within the bounds of the size leading to arbitrary code execution.

  • CVE-2016-4330HigNov 18, 2016
    risk 0.56cvss 8.6epss 0.01

    In the HDF5 1.8.16 library's failure to check if the number of dimensions for an array read from the file is within the bounds of the space allocated for it, a heap-based buffer overflow will occur, potentially leading to arbitrary code execution.

  • CVE-2018-11206HigMay 16, 2018
    risk 0.53cvss 8.1epss 0.03

    An out of bounds read was discovered in H5O_fill_new_decode and H5O_fill_old_decode in H5Ofill.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service or information disclosure attack.

  • CVE-2018-13875HigJul 10, 2018
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in the HDF HDF5 1.8.20 library. There is an out-of-bounds read in the function H5VM_memcpyvv in H5VM.c.

  • CVE-2026-34734HigApr 9, 2026
    risk 0.44cvss 7.8epss 0.00

    HDF5 is software for managing data. In 1.14.1-2 and earlier, a heap-use-after-free was found in the h5dump helper utility. An attacker who can supply a malicious h5 file can trigger a heap use-after-free. The freed object is referenced in a memmove call from H5T__conv_struct.…

  • CVE-2018-17439MedSep 24, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in the HDF HDF5 1.10.3 library. There is a stack-based buffer overflow in the function H5S_extent_get_dims() in H5S.c. Specifically, this issue occurs while converting an HDF5 file to a GIF file.

  • CVE-2018-17432MedSep 24, 2018
    risk 0.42cvss 6.5epss 0.01

    A NULL pointer dereference in H5O_sdspace_encode() in H5Osdspace.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service via a crafted HDF5 file.

  • CVE-2018-15671MedAug 21, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in the HDF HDF5 1.10.2 library. Excessive stack consumption has been detected in the function H5P__get_cb() in H5Pint.c during an attempted parse of a crafted HDF file. This results in denial of service.