Hdfgroup Hdf5 vulnerabilities
133 known vulnerabilities affecting hdfgroup/hdf5.
Total CVEs
133
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL19HIGH55MEDIUM54LOW5
Vulnerabilities
Page 2 of 7
CVE-2025-6818P3HIGHCVSS 7.8v1.14.62025-06-28
CVE-2025-6818 [HIGH] CWE-119 CVE-2025-6818: A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the func
A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5O__chunk_protect of the file /src/H5Ochunk.c. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
nvd
CVE-2024-32605P3HIGHCVSS 8.8fixed in 1.14.42024-05-14
CVE-2024-32605 [HIGH] CWE-122 CVE-2024-32605: HDF5 Library through 1.14.3 has a heap-based buffer over-read in H5VM_memcpyvv in H5VM.c (called fro
HDF5 Library through 1.14.3 has a heap-based buffer over-read in H5VM_memcpyvv in H5VM.c (called from H5D__compact_readvv in H5Dcompact.c).
nvdosv
CVE-2024-32614P3HIGHCVSS 8.8fixed in 1.14.42024-05-14
CVE-2024-32614 [HIGH] CWE-125 CVE-2024-32614: HDF5 Library through 1.14.3 has a SEGV in H5VM_memcpyvv in H5VM.c.
HDF5 Library through 1.14.3 has a SEGV in H5VM_memcpyvv in H5VM.c.
nvdosv
CVE-2025-44905P3HIGHCVSS 8.8v1.14.62025-05-30
CVE-2025-44905 [HIGH] CWE-122 CVE-2025-44905: hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5Z__filter_scaleoffset functi
hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5Z__filter_scaleoffset function.
nvd
CVE-2025-44904P3HIGHCVSS 8.8v1.14.62025-05-30
CVE-2025-44904 [HIGH] CWE-122 CVE-2025-44904: hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5VM_memcpyvv function.
hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5VM_memcpyvv function.
nvd
CVE-2025-6856P3HIGHCVSS 7.8v1.14.62025-06-29
CVE-2025-6856 [HIGH] CWE-119 CVE-2025-6856: A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the func
A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5FL__reg_gc_list of the file src/H5FL.c. The manipulation leads to use after free. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
nvd
CVE-2024-32611P3CRITICALCVSS 9.8fixed in 1.14.42024-05-14
CVE-2024-32611 [CRITICAL] CWE-908 CVE-2024-32611: HDF5 Library through 1.14.3 may use an uninitialized value in H5A__attr_release_table in H5Aint.c.
HDF5 Library through 1.14.3 may use an uninitialized value in H5A__attr_release_table in H5Aint.c.
nvdosv
CVE-2020-18232P3HIGHCVSS 8.8v1.10.42023-08-22
CVE-2020-18232 [HIGH] CWE-787 CVE-2020-18232: Buffer Overflow vulnerability in function H5S_close in H5S.c in HDF5 1.10.4 allows remote attackers
Buffer Overflow vulnerability in function H5S_close in H5S.c in HDF5 1.10.4 allows remote attackers to run arbitrary code via creation of crafted file.
nvd
CVE-2020-18494P3HIGHCVSS 8.8v1.10.42023-08-22
CVE-2020-18494 [HIGH] CWE-787 CVE-2020-18494: Buffer Overflow vulnerability in function H5S_close in H5S.c in HDF5 1.10.4 allows remote attackers
Buffer Overflow vulnerability in function H5S_close in H5S.c in HDF5 1.10.4 allows remote attackers to run arbitrary code via creation of crafted file.
nvd
CVE-2018-13872P3CRITICALCVSS 9.8v1.8.202018-07-10
CVE-2018-13872 [CRITICAL] CWE-787 CVE-2018-13872: An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer overflow in the
An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer overflow in the function H5G_ent_decode in H5Gent.c.
nvd
CVE-2018-13871P3CRITICALCVSS 9.8v1.8.202018-07-10
CVE-2018-13871 [CRITICAL] CWE-787 CVE-2018-13871: An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer overflow in the
An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer overflow in the function H5FL_blk_malloc in H5FL.c.
nvd
CVE-2026-26200P3HIGHCVSS 7.8fixed in 1.14.4.2fixed in 1.14.4-22026-02-19
CVE-2026-26200 [HIGH] CWE-122 CVE-2026-26200: HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` f
HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` file parsed by HDF5 can trigger a write-based heap buffer overflow condition. This can lead to a denial-of-service condition, and potentially further issues such as remote code execution depending on the practical exploitability of the heap overflow agai
nvd
CVE-2024-32624P3HIGHCVSS 7.4fixed in 1.14.42024-05-14
CVE-2024-32624 [HIGH] CWE-122 CVE-2024-32624: HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__ref_mem_setnull in H5Tref.
HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__ref_mem_setnull in H5Tref.c (called from H5T__conv_ref in H5Tconv.c), resulting in the corruption of the instruction pointer.
nvdosv
CVE-2018-13867P3CRITICALCVSS 9.8v1.8.202018-07-10
CVE-2018-13867 [CRITICAL] CWE-125 CVE-2018-13867: An issue was discovered in the HDF HDF5 1.8.20 library. There is an out of bounds read in the functi
An issue was discovered in the HDF HDF5 1.8.20 library. There is an out of bounds read in the function H5F__accum_read in H5Faccum.c.
nvd
CVE-2018-13873P3CRITICALCVSS 9.8≥ 1.8.0, ≤ 1.8.202018-07-10
CVE-2018-13873 [CRITICAL] CWE-125 CVE-2018-13873: An issue was discovered in the HDF HDF5 1.8.20 library. There is a buffer over-read in H5O_chunk_des
An issue was discovered in the HDF HDF5 1.8.20 library. There is a buffer over-read in H5O_chunk_deserialize in H5Ocache.c.
nvd
CVE-2024-32609P3HIGHCVSS 7.5fixed in 1.14.42024-05-14
CVE-2024-32609 [HIGH] CWE-674 CVE-2024-32609: HDF5 Library through 1.14.3 allows stack consumption in the function H5E_printf_stack in H5Eint.c.
HDF5 Library through 1.14.3 allows stack consumption in the function H5E_printf_stack in H5Eint.c.
nvdosv
CVE-2026-34734P3HIGHCVSS 7.8fixed in 1.14.1-2≤ 1.14.1-22026-04-09
CVE-2026-34734 [HIGH] CWE-416 CVE-2026-34734: HDF5 is software for managing data. In 1.14.1-2 and earlier, a heap-use-after-free was found in the
HDF5 is software for managing data. In 1.14.1-2 and earlier, a heap-use-after-free was found in the h5dump helper utility. An attacker who can supply a malicious h5 file can trigger a heap use-after-free. The freed object is referenced in a memmove call from H5T__conv_struct. The original object was allocated by H5D__typeinfo_init_phase3 and freed by H
nvd
CVE-2024-32622P3CRITICALCVSS 9.1fixed in 1.14.42024-05-14
CVE-2024-32622 [CRITICAL] CWE-125 CVE-2024-32622: HDF5 Library through 1.14.3 contains a out-of-bounds read operation in H5FL_arr_malloc in H5FL.c (ca
HDF5 Library through 1.14.3 contains a out-of-bounds read operation in H5FL_arr_malloc in H5FL.c (called from H5S_set_extent_simple in H5S.c).
nvdosv
CVE-2021-46242P3HIGHCVSS 8.8v1.13.1-12022-01-21
CVE-2021-46242 [HIGH] CWE-416 CVE-2021-46242: HDF5 v1.13.1-1 was discovered to contain a heap-use-after free via the component H5AC_unpin_entry.
HDF5 v1.13.1-1 was discovered to contain a heap-use-after free via the component H5AC_unpin_entry.
nvdosv
CVE-2016-4331P3HIGHCVSS 8.6v1.8.162016-11-18
CVE-2016-4331 [HIGH] CWE-787 CVE-2016-4331: When decoding data out of a dataset encoded with the H5Z_NBIT decoding, the HDF5 1.8.16 library will
When decoding data out of a dataset encoded with the H5Z_NBIT decoding, the HDF5 1.8.16 library will fail to ensure that the precision is within the bounds of the size leading to arbitrary code execution.
nvdosv