cbcvebase.
CVE-2016-4333
published 2016-11-18

CVE-2016-4333: The HDF5 1.8.16 library allocating space for the array using a value from the file has an impact within the loop for initializing said array allowing a value…

PriorityP434high8.6CVSS 3.0
AVLACLPRNUIRSCCHIHAH
EPSS
0.61%
45.3th percentile
The HDF5 1.8.16 library allocating space for the array using a value from the file has an impact within the loop for initializing said array allowing a value within the file to modify the loop's terminator. Due to this, an aggressor can cause the loop's index to point outside the bounds of the array when initializing it.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianhdf5< hdf5 1.10.0-patch1+docs-1 (bookworm)hdf5 1.10.0-patch1+docs-1 (bookworm)
hdfgrouphdf5
hdfgrouphdf5>= 0 < 1.10.0-patch1+docs-11.10.0-patch1+docs-1
hdfgrouphdf5>= 0 < 1.10.0-patch1+docs-11.10.0-patch1+docs-1
hdfgrouphdf5>= 0 < 1.10.0-patch1+docs-11.10.0-patch1+docs-1
hdfgrouphdf5>= 0 < 1.10.0-patch1+docs-11.10.0-patch1+docs-1

CVSS provenance

nvdv3.08.6HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv8.6HIGH
vendor_debian8.6HIGH
vendor_redhat8.6HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.