Hdfgroup Hdf5 vulnerabilities
133 known vulnerabilities affecting hdfgroup/hdf5.
Total CVEs
133
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL19HIGH55MEDIUM54LOW5
Vulnerabilities
Page 4 of 7
CVE-2024-32616P3HIGHCVSS 7.4fixed in 1.14.42024-05-14
CVE-2024-32616 [HIGH] CWE-122 CVE-2024-32616: HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5O__dtype_encode_helper in H5
HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5O__dtype_encode_helper in H5Odtype.c.
nvdosv
CVE-2024-29163P3HIGHCVSS 7.4fixed in 1.14.42024-05-14
CVE-2024-29163 [HIGH] CWE-122 CVE-2024-29163: HDF5 through 1.14.3 contains a heap buffer overflow in H5T__bit_find, resulting in the corruption of
HDF5 through 1.14.3 contains a heap buffer overflow in H5T__bit_find, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
nvdosv
CVE-2024-29160P3HIGHCVSS 7.4fixed in 1.14.42024-05-14
CVE-2024-29160 [HIGH] CWE-122 CVE-2024-29160: HDF5 through 1.14.3 contains a heap buffer overflow in H5HG__cache_heap_deserialize, resulting in th
HDF5 through 1.14.3 contains a heap buffer overflow in H5HG__cache_heap_deserialize, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
nvdosv
CVE-2016-4333P4HIGHCVSS 8.6v1.8.162016-11-18
CVE-2016-4333 [HIGH] CWE-119 CVE-2016-4333: The HDF5 1.8.16 library allocating space for the array using a value from the file has an impact wit
The HDF5 1.8.16 library allocating space for the array using a value from the file has an impact within the loop for initializing said array allowing a value within the file to modify the loop's terminator. Due to this, an aggressor can cause the loop's index to point outside the bounds of the array when initializing it.
nvdosv
CVE-2018-13870P4CRITICALCVSS 9.8v1.8.202018-07-10
CVE-2018-13870 [CRITICAL] CWE-125 CVE-2018-13870: An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in th
An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5O_link_decode in H5Olink.c.
nvdosv
CVE-2022-26061P4HIGHCVSS 7.8v1.10.42022-08-22
CVE-2022-26061 [HIGH] CWE-122 CVE-2022-26061: A heap-based buffer overflow vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5
A heap-based buffer overflow vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
nvdosv
CVE-2024-32620P4HIGHCVSS 7.4fixed in 1.14.42024-05-14
CVE-2024-32620 [HIGH] CWE-122 CVE-2024-32620: HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5F_addr_decode_len in H5Fint.
HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5F_addr_decode_len in H5Fint.c, resulting in the corruption of the instruction pointer.
nvdosv
CVE-2024-32613P4HIGHCVSS 7.4fixed in 1.14.42024-05-14
CVE-2024-32613 [HIGH] CVE-2024-32613: HDF5 Library through 1.14.3 contains a heap-based buffer over-read in the function H5HL__fl_deserial
HDF5 Library through 1.14.3 contains a heap-based buffer over-read in the function H5HL__fl_deserialize in H5HLcache.c, a different vulnerability than CVE-2024-32612.
nvdosv
CVE-2018-14033P4HIGHCVSS 8.8v1.8.202018-07-13
CVE-2018-14033 [HIGH] CWE-125 CVE-2018-14033: An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in th
An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5O_layout_decode in H5Olayout.c, related to HDmemcpy.
nvdosv
CVE-2026-26199P4MEDIUMCVSS 5.9≤ 1.14.62026-07-20
CVE-2026-26199 [MEDIUM] CWE-124 CVE-2026-26199: HDF5 is a high-performance library and a file format specification that implements the HDF5 data mod
HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If `H5Iget_name` is invoked on a group id with `0` for the size parameter, it will underflow when trying to place a null terminator in the buffer. This can occur if `H5Iget_name` is invoked in a way where `size` can be forced to zero, and there is
nvd
CVE-2018-14031P4HIGHCVSS 8.8v1.8.202018-07-13
CVE-2018-14031 [HIGH] CWE-125 CVE-2018-14031: An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in th
An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5T_copy in H5T.c.
nvdosv
CVE-2018-14460P4HIGHCVSS 8.8v1.8.202018-07-20
CVE-2018-14460 [HIGH] CWE-125 CVE-2018-14460: An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in th
An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5O_sdspace_decode in H5Osdspace.c.
nvdosv
CVE-2026-26197P4MEDIUMCVSS 5.9fixed in 2.0.02026-07-20
CVE-2026-26197 [MEDIUM] CWE-125 CVE-2026-26197: HDF5 is a high-performance library and a file format specification that implements the HDF5 data mod
HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If a file is corrupted such that an array datatype's size, the number of elements, and the element size are not in agreement it can trigger an out of bounds read. The array datatype stores the full size of the datatype (`dt->shared->size`) separat
nvd
CVE-2018-13875P4HIGHCVSS 7.8v1.8.202018-07-10
CVE-2018-13875 [HIGH] CWE-125 CVE-2018-13875: An issue was discovered in the HDF HDF5 1.8.20 library. There is an out-of-bounds read in the functi
An issue was discovered in the HDF HDF5 1.8.20 library. There is an out-of-bounds read in the function H5VM_memcpyvv in H5VM.c.
nvd
CVE-2018-13868P4CRITICALCVSS 9.8v1.8.202018-07-10
CVE-2018-13868 [CRITICAL] CWE-125 CVE-2018-13868: An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in th
An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5O_fill_old_decode in H5Ofill.c.
nvd
CVE-2018-14035P4HIGHCVSS 8.8v1.8.202018-07-13
CVE-2018-14035 [HIGH] CWE-125 CVE-2018-14035: An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in th
An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5VM_memcpyvv in H5VM.c.
nvd
CVE-2025-6270P4MEDIUMCVSS 5.3fixed in 2.0.0v1.14.0+6 more2025-06-19
CVE-2025-6270 [MEDIUM] CWE-119 CVE-2025-6270: A vulnerability, which was classified as critical, has been found in HDF5 up to 1.14.6. Affected by
A vulnerability, which was classified as critical, has been found in HDF5 up to 1.14.6. Affected by this issue is the function H5FS__sect_find_node of the file H5FSsection.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-6269P4MEDIUMCVSS 5.3≤ 1.14.6v1.14.0+6 more2025-06-19
CVE-2025-6269 [MEDIUM] CWE-119 CVE-2025-6269: A vulnerability classified as critical was found in HDF5 up to 1.14.6. Affected by this vulnerabilit
A vulnerability classified as critical was found in HDF5 up to 1.14.6. Affected by this vulnerability is the function H5C__reconstruct_cache_entry of the file H5Cimage.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-2912P4MEDIUMCVSS 5.3fixed in 2.0.0v1.14.0+6 more2025-03-28
CVE-2025-2912 [MEDIUM] CWE-119 CVE-2025-2912: A vulnerability was found in HDF5 up to 1.14.6. It has been declared as problematic. Affected by thi
A vulnerability was found in HDF5 up to 1.14.6. It has been declared as problematic. Affected by this vulnerability is the function H5O_msg_flush of the file src/H5Omessage.c. The manipulation of the argument oh leads to heap-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-2913P4MEDIUMCVSS 5.3fixed in 2.0.0v1.14.0+6 more2025-03-28
CVE-2025-2913 [MEDIUM] CWE-119 CVE-2025-2913: A vulnerability was found in HDF5 up to 1.14.6. It has been rated as critical. Affected by this issu
A vulnerability was found in HDF5 up to 1.14.6. It has been rated as critical. Affected by this issue is the function H5FL__blk_gc_list of the file src/H5FL.c. The manipulation of the argument H5FL_blk_head_t leads to use after free. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
nvd