VYPR

Vendor CVEs

Hdfgroup

All CVEs

141 total · sorted by risk
  • CVE-2024-32608CriOct 9, 2024
    risk 0.64cvss 9.8epss 0.01

    HDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

  • CVE-2024-33874CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    HDF5 Library through 1.14.3 has a heap buffer overflow in H5O__mtime_new_encode in H5Omtime.c.

  • CVE-2024-32621CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5HG_read in H5HG.c (called from H5VL__native_blob_get in H5VLnative_blob.c), resulting in the corruption of the instruction pointer.

  • CVE-2024-32611CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    HDF5 Library through 1.14.3 may use an uninitialized value in H5A__attr_release_table in H5Aint.c.

  • CVE-2024-29164CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    HDF5 through 1.14.3 contains a stack buffer overflow in H5R__decode_heap, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

  • CVE-2024-29159CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_scaleoffset, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

  • CVE-2024-29157CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    HDF5 through 1.14.3 contains a heap buffer overflow in H5HG_read, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

  • CVE-2018-13876CriJul 10, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in the HDF HDF5 1.8.20 library. There is a stack-based buffer overflow in the function H5FD_sec2_read in H5FDsec2.c, related to HDread.

  • CVE-2018-13874CriJul 10, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in the HDF HDF5 1.8.20 library. There is a stack-based buffer overflow in the function H5FD_sec2_read in H5FDsec2.c, related to HDmemset.

  • CVE-2018-13873CriJul 10, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in the HDF HDF5 1.8.20 library. There is a buffer over-read in H5O_chunk_deserialize in H5Ocache.c.

  • CVE-2018-13872CriJul 10, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer overflow in the function H5G_ent_decode in H5Gent.c.

  • CVE-2018-13871CriJul 10, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer overflow in the function H5FL_blk_malloc in H5FL.c.

  • CVE-2018-13870CriJul 10, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5O_link_decode in H5Olink.c.

  • CVE-2018-13869CriJul 10, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in the HDF HDF5 1.8.20 library. There is a memcpy parameter overlap in the function H5O_link_decode in H5Olink.c.

  • CVE-2018-13868CriJul 10, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5O_fill_old_decode in H5Ofill.c.

  • CVE-2018-13867CriJul 10, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in the HDF HDF5 1.8.20 library. There is an out of bounds read in the function H5F__accum_read in H5Faccum.c.

  • CVE-2018-13866CriJul 10, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in the HDF HDF5 1.8.20 library. There is a stack-based buffer over-read in the function H5F_addr_decode_len in H5Fint.c.

  • CVE-2024-32622CriMay 14, 2024
    risk 0.59cvss 9.1epss 0.01

    HDF5 Library through 1.14.3 contains a out-of-bounds read operation in H5FL_arr_malloc in H5FL.c (called from H5S_set_extent_simple in H5S.c).

  • CVE-2025-44905HigMay 30, 2025
    risk 0.57cvss 8.8epss 0.00

    hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5Z__filter_scaleoffset function.

  • CVE-2025-44904HigMay 30, 2025
    risk 0.57cvss 8.8epss 0.00

    hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5VM_memcpyvv function.

  • CVE-2024-33877HigMay 14, 2024
    risk 0.57cvss 8.8epss 0.01

    HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5T__conv_struct_opt in H5Tconv.c.

  • CVE-2024-33873HigMay 14, 2024
    risk 0.57cvss 8.8epss 0.01

    HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5D__scatter_mem in H5Dscatgath.c.

  • CVE-2024-32623HigMay 14, 2024
    risk 0.57cvss 8.8epss 0.01

    HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5VM_array_fill in H5VM.c (called from H5S_select_elements in H5Spoint.c).

  • CVE-2024-32617HigMay 14, 2024
    risk 0.57cvss 8.8epss 0.01

    HDF5 Library through 1.14.3 contains a heap-based buffer over-read caused by the unsafe use of strdup in H5MM_xstrdup in H5MM.c (called from H5G__ent_to_link in H5Glink.c).

  • CVE-2024-32615CriMay 14, 2024
    risk 0.57cvss 9.8epss 0.01

    HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5Z__nbit_decompress_one_byte in H5Znbit.c, caused by the earlier use of an initialized pointer.

  • CVE-2024-32614HigMay 14, 2024
    risk 0.57cvss 8.8epss 0.01

    HDF5 Library through 1.14.3 has a SEGV in H5VM_memcpyvv in H5VM.c.

  • CVE-2024-32605HigMay 14, 2024
    risk 0.57cvss 8.8epss 0.01

    HDF5 Library through 1.14.3 has a heap-based buffer over-read in H5VM_memcpyvv in H5VM.c (called from H5D__compact_readvv in H5Dcompact.c).

  • CVE-2024-29161HigMay 14, 2024
    risk 0.57cvss 8.8epss 0.01

    HDF5 through 1.14.3 contains a heap buffer overflow in H5A__attr_release_table, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

  • CVE-2020-18494HigAug 22, 2023
    risk 0.57cvss 8.8epss 0.01

    Buffer Overflow vulnerability in function H5S_close in H5S.c in HDF5 1.10.4 allows remote attackers to run arbitrary code via creation of crafted file.

  • CVE-2020-18232HigAug 22, 2023
    risk 0.57cvss 8.8epss 0.01

    Buffer Overflow vulnerability in function H5S_close in H5S.c in HDF5 1.10.4 allows remote attackers to run arbitrary code via creation of crafted file.

  • CVE-2021-46242HigJan 21, 2022
    risk 0.57cvss 8.8epss 0.01

    HDF5 v1.13.1-1 was discovered to contain a heap-use-after free via the component H5AC_unpin_entry.

  • CVE-2019-9152HigFeb 25, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in the HDF HDF5 1.10.4 library. There is an out of bounds read in the function H5MM_xstrdup in H5MM.c when called from H5O_dtype_decode_helper in H5Odtype.c.

  • CVE-2019-9151HigFeb 25, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in the HDF HDF5 1.10.4 library. There is an out of bounds read in the function H5VM_memcpyvv in H5VM.c when called from H5D__compact_readvv in H5Dcompact.c.

  • CVE-2018-16438HigSep 4, 2018
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in the HDF HDF5 1.8.20 library. There is an out of bounds read in H5L_extern_query at H5Lexternal.c.

  • CVE-2018-14460HigJul 20, 2018
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5O_sdspace_decode in H5Osdspace.c.

  • CVE-2018-14035HigJul 13, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5VM_memcpyvv in H5VM.c.

  • CVE-2018-14034HigJul 13, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in the HDF HDF5 1.8.20 library. There is an out of bounds read in the function H5O_pline_reset in H5Opline.c.

  • CVE-2018-14033HigJul 13, 2018
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5O_layout_decode in H5Olayout.c, related to HDmemcpy.

  • CVE-2018-14031HigJul 13, 2018
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5T_copy in H5T.c.

  • CVE-2017-17509HigDec 11, 2017
    risk 0.57cvss 8.8epss 0.02

    In HDF5 1.10.1, there is an out of bounds write vulnerability in the function H5G__ent_decode_vec in H5Gcache.c in libhdf5.a. For example, h5dump would crash or possibly have unspecified other impact someone opens a crafted hdf5 file.

  • CVE-2016-4333HigNov 18, 2016
    risk 0.56cvss 8.6epss 0.01

    The HDF5 1.8.16 library allocating space for the array using a value from the file has an impact within the loop for initializing said array allowing a value within the file to modify the loop's terminator. Due to this, an aggressor can cause the loop's index to point outside…

  • CVE-2016-4332HigNov 18, 2016
    risk 0.56cvss 8.6epss 0.01

    The library's failure to check if certain message types support a particular flag, the HDF5 1.8.16 library will cast the structure to an alternative structure and then assign to fields that aren't supported by the message type and the library will write outside the bounds of the…

  • CVE-2016-4331HigNov 18, 2016
    risk 0.56cvss 8.6epss 0.01

    When decoding data out of a dataset encoded with the H5Z_NBIT decoding, the HDF5 1.8.16 library will fail to ensure that the precision is within the bounds of the size leading to arbitrary code execution.

  • CVE-2016-4330HigNov 18, 2016
    risk 0.56cvss 8.6epss 0.01

    In the HDF5 1.8.16 library's failure to check if the number of dimensions for an array read from the file is within the bounds of the space allocated for it, a heap-based buffer overflow will occur, potentially leading to arbitrary code execution.

  • CVE-2026-19024HigAug 5, 2026
    risk 0.53cvss epss 0.00

    NULL pointer dereference in H5Pget_fill_value in HDF5 before 2.3.0 allows attackers to cause a denial of service via a dataset whose version 1 or 2 fill value message has the "defined" flag set together with a negative size field, which is not normalized to the library's…

  • CVE-2018-11206HigMay 16, 2018
    risk 0.53cvss 8.1epss 0.03

    An out of bounds read was discovered in H5O_fill_new_decode and H5O_fill_old_decode in H5Ofill.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service or information disclosure attack.

  • CVE-2018-11205HigMay 16, 2018
    risk 0.53cvss 8.1epss 0.02

    A out of bounds read was discovered in H5VM_memcpyvv in H5VM.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service or information disclosure attack.

  • CVE-2026-26200HigFeb 19, 2026
    risk 0.51cvss 7.8epss 0.00

    HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` file parsed by HDF5 can trigger a write-based heap buffer overflow condition. This can lead to a denial-of-service condition, and potentially further issues such as remote code…

  • CVE-2022-26061HigAug 22, 2022
    risk 0.51cvss 7.8epss 0.01

    A heap-based buffer overflow vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2022-25972HigAug 22, 2022
    risk 0.51cvss 7.8epss 0.01

    An out-of-bounds write vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

Page 1 of 3