cbcvebase.

Hdfgroup Hdf5 vulnerabilities

133 known vulnerabilities affecting hdfgroup/hdf5.

Total CVEs
133
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL19HIGH55MEDIUM54LOW5

Vulnerabilities

Page 5 of 7
CVE-2018-17434P4MEDIUMCVSS 6.5≤ 1.10.32018-09-24
CVE-2018-17434 [MEDIUM] CWE-369 CVE-2018-17434: A SIGFPE signal is raised in the function apply_filters() of h5repack_filters.c in the HDF HDF5 thro A SIGFPE signal is raised in the function apply_filters() of h5repack_filters.c in the HDF HDF5 through 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. It could allow a remote denial of service attack.
nvdosv
CVE-2018-17233P4MEDIUMCVSS 6.5≤ 1.10.32018-09-20
CVE-2018-17233 [MEDIUM] CWE-369 CVE-2018-17233: A SIGFPE signal is raised in the function H5D__create_chunk_file_map_hyper() of H5Dchunk.c in the HD A SIGFPE signal is raised in the function H5D__create_chunk_file_map_hyper() of H5Dchunk.c in the HDF HDF5 through 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. It could allow a remote denial of service attack.
nvdosv
CVE-2018-17438P4MEDIUMCVSS 6.5≤ 1.10.32018-09-24
CVE-2018-17438 [MEDIUM] CWE-369 CVE-2018-17438: A SIGFPE signal is raised in the function H5D__select_io() of H5Dselect.c in the HDF HDF5 through 1. A SIGFPE signal is raised in the function H5D__select_io() of H5Dselect.c in the HDF HDF5 through 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. It could allow a remote denial of service attack.
nvdosv
CVE-2017-17508P4MEDIUMCVSS 6.5v1.10.12017-12-11
CVE-2017-17508 [MEDIUM] CWE-369 CVE-2017-17508: In HDF5 1.10.1, there is a divide-by-zero vulnerability in the function H5T_set_loc in the H5T.c fil In HDF5 1.10.1, there is a divide-by-zero vulnerability in the function H5T_set_loc in the H5T.c file in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file.
nvdosv
CVE-2021-46244P4MEDIUMCVSS 6.5v1.13.1-12022-01-21
CVE-2021-46244 [MEDIUM] CWE-369 CVE-2021-46244: A Divide By Zero vulnerability exists in HDF5 v1.13.1-1 vis the function H5T__complete_copy () at /h A Divide By Zero vulnerability exists in HDF5 v1.13.1-1 vis the function H5T__complete_copy () at /hdf5/src/H5T.c. This vulnerability causes an aritmetic exception, leading to a Denial of Service (DoS).
nvdosv
CVE-2025-2924P4MEDIUMCVSS 5.5≤ 1.14.6v1.14.0+6 more2025-03-28
CVE-2025-2924 [MEDIUM] CWE-119 CVE-2025-2924: A vulnerability, which was classified as problematic, was found in HDF5 up to 1.14.6. This affects t A vulnerability, which was classified as problematic, was found in HDF5 up to 1.14.6. This affects the function H5HL__fl_deserialize of the file src/H5HLcache.c. The manipulation of the argument free_block leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be
nvd
CVE-2025-2915P4MEDIUMCVSS 5.5≤ 1.14.6v1.14.0+6 more2025-03-28
CVE-2025-2915 [MEDIUM] CWE-119 CVE-2025-2915: A vulnerability classified as problematic was found in HDF5 up to 1.14.6. This vulnerability affects A vulnerability classified as problematic was found in HDF5 up to 1.14.6. This vulnerability affects the function H5F__accum_free of the file src/H5Faccum.c. The manipulation of the argument overlap_size leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-7067P4MEDIUMCVSS 5.5v1.14.62025-07-04
CVE-2025-7067 [MEDIUM] CWE-119 CVE-2025-7067: A vulnerability classified as problematic was found in HDF5 1.14.6. This vulnerability affects the f A vulnerability classified as problematic was found in HDF5 1.14.6. This vulnerability affects the function H5FS__sinfo_serialize_node_cb of the file src/H5FScache.c. The manipulation leads to heap-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
nvd
CVE-2026-29043P4MEDIUMCVSS 5.5≤ 1.14.1-22026-04-10
CVE-2026-29043 [MEDIUM] CWE-122 CVE-2026-29043: HDF5 is software for managing data. In 1.14.1-2 and earlier, an attacker who can control an h5 file HDF5 is software for managing data. In 1.14.1-2 and earlier, an attacker who can control an h5 file parsed by HDF5 can trigger a write-based heap buffer overflow condition in the H5T__ref_mem_setnull method. This can lead to a denial-of-service condition, and potentially further issues such as remote code execution depending on the practical exploita
nvd
CVE-2018-11203P4MEDIUMCVSS 6.5v1.10.22018-05-16
CVE-2018-11203 [MEDIUM] CWE-369 CVE-2018-11203: A division by zero was discovered in H5D__btree_decode_key in H5Dbtree.c in the HDF HDF5 1.10.2 libr A division by zero was discovered in H5D__btree_decode_key in H5Dbtree.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.
nvdosv
CVE-2018-17237P4MEDIUMCVSS 6.5≤ 1.10.32018-09-20
CVE-2018-17237 [MEDIUM] CVE-2018-17237: A SIGFPE signal is raised in the function H5D__chunk_set_info_real() of H5Dchunk.c in the HDF HDF5 1 A SIGFPE signal is raised in the function H5D__chunk_set_info_real() of H5Dchunk.c in the HDF HDF5 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. This issue is different from CVE-2018-11207.
nvdosv
CVE-2018-17439P4MEDIUMCVSS 6.5v1.10.32018-09-24
CVE-2018-17439 [MEDIUM] CWE-787 CVE-2018-17439: An issue was discovered in the HDF HDF5 1.10.3 library. There is a stack-based buffer overflow in th An issue was discovered in the HDF HDF5 1.10.3 library. There is a stack-based buffer overflow in the function H5S_extent_get_dims() in H5S.c. Specifically, this issue occurs while converting an HDF5 file to a GIF file.
nvdosv
CVE-2017-17506P4MEDIUMCVSS 6.5≥ 1.8.0, ≤ 1.10.12017-12-11
CVE-2017-17506 [MEDIUM] CWE-125 CVE-2017-17506: In HDF5 1.10.1, there is an out of bounds read vulnerability in the function H5Opline_pline_decode i In HDF5 1.10.1, there is an out of bounds read vulnerability in the function H5Opline_pline_decode in H5Opline.c in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file.
nvdosv
CVE-2017-17505P4MEDIUMCVSS 6.5v1.10.12017-12-11
CVE-2017-17505 [MEDIUM] CWE-476 CVE-2017-17505: In HDF5 1.10.1, there is a NULL pointer dereference in the function H5O_pline_decode in the H5Opline In HDF5 1.10.1, there is a NULL pointer dereference in the function H5O_pline_decode in the H5Opline.c file in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file.
nvdosv
CVE-2025-2925P4MEDIUMCVSS 5.5≤ 1.14.6v1.14.0+6 more2025-03-28
CVE-2025-2925 [MEDIUM] CWE-119 CVE-2025-2925: A vulnerability has been found in HDF5 up to 1.14.6 and classified as problematic. This vulnerabilit A vulnerability has been found in HDF5 up to 1.14.6 and classified as problematic. This vulnerability affects the function H5MM_realloc of the file src/H5MM.c. The manipulation of the argument mem leads to double free. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-7069P4MEDIUMCVSS 5.5v1.14.62025-07-04
CVE-2025-7069 [MEDIUM] CWE-119 CVE-2025-7069: A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the func A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5FS__sect_link_size of the file src/H5FSsection.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
nvd
CVE-2018-11207P4MEDIUMCVSS 6.5v1.10.22018-05-16
CVE-2018-11207 [MEDIUM] CWE-369 CVE-2018-11207: A division by zero was discovered in H5D__chunk_init in H5Dchunk.c in the HDF HDF5 1.10.2 library. I A division by zero was discovered in H5D__chunk_init in H5Dchunk.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.
nvdosv
CVE-2018-11202P4MEDIUMCVSS 6.5v1.10.22018-05-16
CVE-2018-11202 [MEDIUM] CWE-476 CVE-2018-11202: A NULL pointer dereference was discovered in H5S_hyper_make_spans in H5Shyper.c in the HDF HDF5 1.10 A NULL pointer dereference was discovered in H5S_hyper_make_spans in H5Shyper.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.
nvdosv
CVE-2018-11204P4MEDIUMCVSS 6.5v1.10.22018-05-16
CVE-2018-11204 [MEDIUM] CWE-476 CVE-2018-11204: A NULL pointer dereference was discovered in H5O__chunk_deserialize in H5Ocache.c in the HDF HDF5 1. A NULL pointer dereference was discovered in H5O__chunk_deserialize in H5Ocache.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.
nvdosv
CVE-2018-17433P4MEDIUMCVSS 6.5≤ 1.10.32018-09-24
CVE-2018-17433 [MEDIUM] CWE-787 CVE-2018-17433: A heap-based buffer overflow in ReadGifImageDesc() in gifread.c in the HDF HDF5 through 1.10.3 libra A heap-based buffer overflow in ReadGifImageDesc() in gifread.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service via a crafted HDF5 file. This issue was triggered while converting a GIF file to an HDF file.
nvd