Hdfgroup Hdf5 vulnerabilities
133 known vulnerabilities affecting hdfgroup/hdf5.
Total CVEs
133
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL19HIGH55MEDIUM54LOW5
Vulnerabilities
Page 3 of 7
CVE-2019-9151P3HIGHCVSS 8.8v1.10.42019-02-25
CVE-2019-9151 [HIGH] CWE-125 CVE-2019-9151: An issue was discovered in the HDF HDF5 1.10.4 library. There is an out of bounds read in the functi
An issue was discovered in the HDF HDF5 1.10.4 library. There is an out of bounds read in the function H5VM_memcpyvv in H5VM.c when called from H5D__compact_readvv in H5Dcompact.c.
nvd
CVE-2024-32619P3HIGHCVSS 7.4fixed in 1.14.42024-05-14
CVE-2024-32619 [HIGH] CWE-122 CVE-2024-32619: HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T_copy_reopen in H5T.c, resul
HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T_copy_reopen in H5T.c, resulting in the corruption of the instruction pointer.
nvdosv
CVE-2024-32618P3HIGHCVSS 7.4fixed in 1.14.42024-05-14
CVE-2024-32618 [HIGH] CWE-122 CVE-2024-32618: HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__get_native_type in H5Tnati
HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__get_native_type in H5Tnative.c, resulting in the corruption of the instruction pointer.
nvdosv
CVE-2018-16438P3HIGHCVSS 8.8v1.8.202018-09-04
CVE-2018-16438 [HIGH] CWE-125 CVE-2018-16438: An issue was discovered in the HDF HDF5 1.8.20 library. There is an out of bounds read in H5L_extern
An issue was discovered in the HDF HDF5 1.8.20 library. There is an out of bounds read in H5L_extern_query at H5Lexternal.c.
nvdosv
CVE-2019-9152P3HIGHCVSS 8.8v1.10.42019-02-25
CVE-2019-9152 [HIGH] CWE-125 CVE-2019-9152: An issue was discovered in the HDF HDF5 1.10.4 library. There is an out of bounds read in the functi
An issue was discovered in the HDF HDF5 1.10.4 library. There is an out of bounds read in the function H5MM_xstrdup in H5MM.c when called from H5O_dtype_decode_helper in H5Odtype.c.
nvd
CVE-2018-11206P3HIGHCVSS 8.1v1.10.22018-05-16
CVE-2018-11206 [HIGH] CWE-125 CVE-2018-11206: An out of bounds read was discovered in H5O_fill_new_decode and H5O_fill_old_decode in H5Ofill.c in
An out of bounds read was discovered in H5O_fill_new_decode and H5O_fill_old_decode in H5Ofill.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service or information disclosure attack.
nvdosv
CVE-2024-32617P3HIGHCVSS 8.8fixed in 1.14.42024-05-14
CVE-2024-32617 [HIGH] CWE-122 CVE-2024-32617: HDF5 Library through 1.14.3 contains a heap-based buffer over-read caused by the unsafe use of strdu
HDF5 Library through 1.14.3 contains a heap-based buffer over-read caused by the unsafe use of strdup in H5MM_xstrdup in H5MM.c (called from H5G__ent_to_link in H5Glink.c).
nvdosv
CVE-2016-4332P3HIGHCVSS 8.6v1.8.162016-11-18
CVE-2016-4332 [HIGH] CWE-20 CVE-2016-4332: The library's failure to check if certain message types support a particular flag, the HDF5 1.8.16 l
The library's failure to check if certain message types support a particular flag, the HDF5 1.8.16 library will cast the structure to an alternative structure and then assign to fields that aren't supported by the message type and the library will write outside the bounds of the heap buffer. This can lead to code execution under the context of the librar
nvdosv
CVE-2021-37501P3HIGHCVSS 7.5≥ 1.12.0, ≤ 1.13.02023-02-03
CVE-2021-37501 [HIGH] CWE-787 CVE-2021-37501: Buffer Overflow vulnerability in HDFGroup hdf5-h5dump 1.12.0 through 1.13.0 allows attackers to caus
Buffer Overflow vulnerability in HDFGroup hdf5-h5dump 1.12.0 through 1.13.0 allows attackers to cause a denial of service via h5tools_str_sprint in /hdf5/tools/lib/h5tools_str.c.
nvdosv
CVE-2017-17509P3HIGHCVSS 8.8v1.10.12017-12-11
CVE-2017-17509 [HIGH] CWE-787 CVE-2017-17509: In HDF5 1.10.1, there is an out of bounds write vulnerability in the function H5G__ent_decode_vec in
In HDF5 1.10.1, there is an out of bounds write vulnerability in the function H5G__ent_decode_vec in H5Gcache.c in libhdf5.a. For example, h5dump would crash or possibly have unspecified other impact someone opens a crafted hdf5 file.
nvdosv
CVE-2016-4330P3HIGHCVSS 8.6v1.8.162016-11-18
CVE-2016-4330 [HIGH] CWE-119 CVE-2016-4330: In the HDF5 1.8.16 library's failure to check if the number of dimensions for an array read from the
In the HDF5 1.8.16 library's failure to check if the number of dimensions for an array read from the file is within the bounds of the space allocated for it, a heap-based buffer overflow will occur, potentially leading to arbitrary code execution.
nvdosv
CVE-2022-25972P3HIGHCVSS 7.8v1.10.42022-08-22
CVE-2022-25972 [HIGH] CWE-787 CVE-2022-25972: An out-of-bounds write vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4
An out-of-bounds write vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
nvdosv
CVE-2022-25942P3HIGHCVSS 7.8v1.10.42022-08-22
CVE-2022-25942 [HIGH] CWE-125 CVE-2022-25942: An out-of-bounds read vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4.
An out-of-bounds read vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
nvdosv
CVE-2024-29165P3HIGHCVSS 7.4fixed in 1.14.42024-05-14
CVE-2024-29165 [HIGH] CWE-122 CVE-2024-29165: HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_fletcher32, resulting in the corruptio
HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_fletcher32, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
nvdosv
CVE-2024-29158P3HIGHCVSS 7.4≤ 1.14.32024-05-14
CVE-2024-29158 [HIGH] CWE-122 CVE-2024-29158: HDF5 through 1.14.3 contains a stack buffer overflow in H5FL_arr_malloc, resulting in the corruption
HDF5 through 1.14.3 contains a stack buffer overflow in H5FL_arr_malloc, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
nvdosv
CVE-2024-29162P3HIGHCVSS 7.4≤ 1.14.32024-05-14
CVE-2024-29162 [HIGH] CWE-122 CVE-2024-29162: HDF5 through 1.13.3 and/or 1.14.2 contains a stack buffer overflow in H5HG_read, resulting in denial
HDF5 through 1.13.3 and/or 1.14.2 contains a stack buffer overflow in H5HG_read, resulting in denial of service or potential code execution.
nvdosv
CVE-2018-14034P3HIGHCVSS 8.8v1.8.202018-07-13
CVE-2018-14034 [HIGH] CWE-125 CVE-2018-14034: An issue was discovered in the HDF HDF5 1.8.20 library. There is an out of bounds read in the functi
An issue was discovered in the HDF HDF5 1.8.20 library. There is an out of bounds read in the function H5O_pline_reset in H5Opline.c.
nvd
CVE-2018-11205P3HIGHCVSS 8.1v1.10.22018-05-16
CVE-2018-11205 [HIGH] CWE-125 CVE-2018-11205: A out of bounds read was discovered in H5VM_memcpyvv in H5VM.c in the HDF HDF5 1.10.2 library. It co
A out of bounds read was discovered in H5VM_memcpyvv in H5VM.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service or information disclosure attack.
nvdosv
CVE-2018-13866P4CRITICALCVSS 9.8v1.8.202018-07-10
CVE-2018-13866 [CRITICAL] CWE-125 CVE-2018-13866: An issue was discovered in the HDF HDF5 1.8.20 library. There is a stack-based buffer over-read in t
An issue was discovered in the HDF HDF5 1.8.20 library. There is a stack-based buffer over-read in the function H5F_addr_decode_len in H5Fint.c.
nvd
CVE-2024-32612P3HIGHCVSS 7.4fixed in 1.14.42024-05-14
CVE-2024-32612 [HIGH] CWE-122 CVE-2024-32612: HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5HL__fl_deserialize in H5HLca
HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5HL__fl_deserialize in H5HLcache.c, resulting in the corruption of the instruction pointer, a different vulnerability than CVE-2024-32613.
nvdosv