cbcvebase.

Hdfgroup Hdf5 vulnerabilities

133 known vulnerabilities affecting hdfgroup/hdf5.

Total CVEs
133
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL19HIGH55MEDIUM54LOW5

Vulnerabilities

Page 1 of 7
CVE-2024-32621P3CRITICALCVSS 9.8fixed in 1.14.42024-05-14
CVE-2024-32621 [CRITICAL] CWE-122 CVE-2024-32621: HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5HG_read in H5HG.c (called fro HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5HG_read in H5HG.c (called from H5VL__native_blob_get in H5VLnative_blob.c), resulting in the corruption of the instruction pointer.
nvdosv
CVE-2024-29159P3CRITICALCVSS 9.8fixed in 1.14.42024-05-14
CVE-2024-29159 [CRITICAL] CWE-120 CVE-2024-29159: HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_scaleoffset, resulting in the corrupti HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_scaleoffset, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
nvdosv
CVE-2024-29164P3CRITICALCVSS 9.8fixed in 1.14.42024-05-14
CVE-2024-29164 [CRITICAL] CWE-121 CVE-2024-29164: HDF5 through 1.14.3 contains a stack buffer overflow in H5R__decode_heap, resulting in the corruptio HDF5 through 1.14.3 contains a stack buffer overflow in H5R__decode_heap, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
nvdosv
CVE-2024-33877P3HIGHCVSS 8.8fixed in 1.14.42024-05-14
CVE-2024-33877 [HIGH] CWE-122 CVE-2024-33877: HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5T__conv_struct_opt in H5Tconv.c. HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5T__conv_struct_opt in H5Tconv.c.
nvdosv
CVE-2024-33873P3HIGHCVSS 8.8fixed in 1.14.42024-05-14
CVE-2024-33873 [HIGH] CWE-122 CVE-2024-33873: HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5D__scatter_mem in H5Dscatgath.c. HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5D__scatter_mem in H5Dscatgath.c.
nvdosv
CVE-2025-2153P3HIGHCVSS 8.1v1.14.62025-03-10
CVE-2025-2153 [HIGH] CWE-119 CVE-2025-2153: A vulnerability, which was classified as critical, was found in HDF5 1.14.6. Affected is the functio A vulnerability, which was classified as critical, was found in HDF5 1.14.6. Affected is the function H5SM_delete of the file H5SM.c of the component h5 File Handler. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult.
nvd
CVE-2024-32615P3CRITICALCVSS 9.8fixed in 1.14.42024-05-14
CVE-2024-32615 [CRITICAL] CWE-787 CVE-2024-32615: HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5Z__nbit_decompress_one_byte i HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5Z__nbit_decompress_one_byte in H5Znbit.c, caused by the earlier use of an initialized pointer.
nvdosv
CVE-2024-32623P3HIGHCVSS 8.8fixed in 1.14.42024-05-14
CVE-2024-32623 [HIGH] CWE-122 CVE-2024-32623: HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5VM_array_fill in H5VM.c (call HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5VM_array_fill in H5VM.c (called from H5S_select_elements in H5Spoint.c).
nvdosv
CVE-2018-13876P3CRITICALCVSS 9.8v1.8.202018-07-10
CVE-2018-13876 [CRITICAL] CWE-787 CVE-2018-13876: An issue was discovered in the HDF HDF5 1.8.20 library. There is a stack-based buffer overflow in th An issue was discovered in the HDF HDF5 1.8.20 library. There is a stack-based buffer overflow in the function H5FD_sec2_read in H5FDsec2.c, related to HDread.
nvd
CVE-2024-33874P3CRITICALCVSS 9.8fixed in 1.14.42024-05-14
CVE-2024-33874 [CRITICAL] CWE-120 CVE-2024-33874: HDF5 Library through 1.14.3 has a heap buffer overflow in H5O__mtime_new_encode in H5Omtime.c. HDF5 Library through 1.14.3 has a heap buffer overflow in H5O__mtime_new_encode in H5Omtime.c.
nvdosv
CVE-2024-29157P3CRITICALCVSS 9.8≤ 1.14.32024-05-14
CVE-2024-29157 [CRITICAL] CWE-122 CVE-2024-29157: HDF5 through 1.14.3 contains a heap buffer overflow in H5HG_read, resulting in the corruption of the HDF5 through 1.14.3 contains a heap buffer overflow in H5HG_read, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
nvdosv
CVE-2024-32608P3CRITICALCVSS 9.8fixed in 1.14.42024-10-09
CVE-2024-32608 [CRITICAL] CWE-787 CVE-2024-32608: HDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the corruption of the i HDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
nvdosv
CVE-2018-13874P3CRITICALCVSS 9.8v1.8.202018-07-10
CVE-2018-13874 [CRITICAL] CWE-787 CVE-2018-13874: An issue was discovered in the HDF HDF5 1.8.20 library. There is a stack-based buffer overflow in th An issue was discovered in the HDF HDF5 1.8.20 library. There is a stack-based buffer overflow in the function H5FD_sec2_read in H5FDsec2.c, related to HDmemset.
nvd
CVE-2025-2308P3HIGHCVSS 7.8v1.14.62025-03-14
CVE-2025-2308 [HIGH] CWE-119 CVE-2025-2308: A vulnerability, which was classified as critical, was found in HDF5 1.14.6. This affects the functi A vulnerability, which was classified as critical, was found in HDF5 1.14.6. This affects the function H5Z__scaleoffset_decompress_one_byte of the component Scale-Offset Filter. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The vendor plans to f
nvd
CVE-2025-2310P3HIGHCVSS 7.8v1.14.62025-03-14
CVE-2025-2310 [HIGH] CWE-119 CVE-2025-2310: A vulnerability was found in HDF5 1.14.6 and classified as critical. This issue affects the function A vulnerability was found in HDF5 1.14.6 and classified as critical. This issue affects the function H5MM_strndup of the component Metadata Attribute Decoder. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The vendor plans to fix this issue in an upc
nvd
CVE-2025-6516P3HIGHCVSS 7.8≤ 1.14.6v1.14.0+6 more2025-06-23
CVE-2025-6516 [HIGH] CWE-119 CVE-2025-6516: A vulnerability has been found in HDF5 up to 1.14.6 and classified as critical. This vulnerability a A vulnerability has been found in HDF5 up to 1.14.6 and classified as critical. This vulnerability affects the function H5F_addr_decode_len of the file /hdf5/src/H5Fint.c. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
nvd
CVE-2024-29161P3HIGHCVSS 8.8fixed in 1.14.42024-05-14
CVE-2024-29161 [HIGH] CWE-122 CVE-2024-29161: HDF5 through 1.14.3 contains a heap buffer overflow in H5A__attr_release_table, resulting in the cor HDF5 through 1.14.3 contains a heap buffer overflow in H5A__attr_release_table, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
nvdosv
CVE-2025-2309P3HIGHCVSS 7.8v1.14.62025-03-14
CVE-2025-2309 [HIGH] CWE-119 CVE-2025-2309: A vulnerability has been found in HDF5 1.14.6 and classified as critical. This vulnerability affects A vulnerability has been found in HDF5 1.14.6 and classified as critical. This vulnerability affects the function H5T__bit_copy of the component Type Conversion Logic. The manipulation leads to heap-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor plans to f
nvd
CVE-2025-6857P3HIGHCVSS 7.8v1.14.62025-06-29
CVE-2025-6857 [HIGH] CWE-119 CVE-2025-6857: A vulnerability has been found in HDF5 1.14.6 and classified as problematic. Affected by this vulner A vulnerability has been found in HDF5 1.14.6 and classified as problematic. Affected by this vulnerability is the function H5G__node_cmp3 of the file src/H5Gnode.c. The manipulation leads to stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
nvd
CVE-2018-13869P3CRITICALCVSS 9.8v1.8.202018-07-10
CVE-2018-13869 [CRITICAL] CWE-119 CVE-2018-13869: An issue was discovered in the HDF HDF5 1.8.20 library. There is a memcpy parameter overlap in the f An issue was discovered in the HDF HDF5 1.8.20 library. There is a memcpy parameter overlap in the function H5O_link_decode in H5Olink.c.
nvdosv
Hdfgroup Hdf5 vulnerabilities | cvebase