Hdfgroup Hdf5 vulnerabilities
133 known vulnerabilities affecting hdfgroup/hdf5.
Total CVEs
133
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL19HIGH55MEDIUM54LOW5
Vulnerabilities
Page 6 of 7
CVE-2019-8398P4MEDIUMCVSS 6.5v1.10.42019-02-17
CVE-2019-8398 [MEDIUM] CWE-125 CVE-2019-8398: An issue was discovered in the HDF HDF5 1.10.4 library. There is an out of bounds read in the functi
An issue was discovered in the HDF HDF5 1.10.4 library. There is an out of bounds read in the function H5T_get_size in H5T.c.
nvdosv
CVE-2019-8397P4MEDIUMCVSS 6.5v1.10.42019-02-17
CVE-2019-8397 [MEDIUM] CWE-125 CVE-2019-8397: An issue was discovered in the HDF HDF5 1.10.4 library. There is an out of bounds read in the functi
An issue was discovered in the HDF HDF5 1.10.4 library. There is an out of bounds read in the function H5T_close_real in H5T.c.
nvd
CVE-2017-17507P4MEDIUMCVSS 6.5v1.10.12017-12-11
CVE-2017-17507 [MEDIUM] CWE-125 CVE-2017-17507: In HDF5 1.10.1, there is an out of bounds read vulnerability in the function H5T_conv_struct_opt in
In HDF5 1.10.1, there is an out of bounds read vulnerability in the function H5T_conv_struct_opt in H5Tconv.c in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file.
nvdosv
CVE-2024-33875P4MEDIUMCVSS 5.7fixed in 1.14.42024-05-14
CVE-2024-33875 [MEDIUM] CWE-120 CVE-2024-33875: HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5O__layout_encode in H5Olayout.c, r
HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5O__layout_encode in H5Olayout.c, resulting in the corruption of the instruction pointer.
nvdosv
CVE-2024-33876P4MEDIUMCVSS 5.7fixed in 1.14.42024-05-14
CVE-2024-33876 [MEDIUM] CWE-120 CVE-2024-33876: HDF5 Library through 1.14.3 has a heap buffer overflow in H5S__point_deserialize in H5Spoint.c.
HDF5 Library through 1.14.3 has a heap buffer overflow in H5S__point_deserialize in H5Spoint.c.
nvdosv
CVE-2024-29166P4MEDIUMCVSS 5.7fixed in 1.14.42024-05-14
CVE-2024-29166 [MEDIUM] CWE-120 CVE-2024-29166: HDF5 through 1.14.3 contains a buffer overflow in H5O__linfo_decode, resulting in the corruption of
HDF5 through 1.14.3 contains a buffer overflow in H5O__linfo_decode, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
nvdosv
CVE-2019-8396P4MEDIUMCVSS 6.5≤ 1.10.42019-02-17
CVE-2019-8396 [MEDIUM] CWE-119 CVE-2019-8396: A buffer overflow in H5O__layout_encode in H5Olayout.c in the HDF HDF5 through 1.10.4 library allows
A buffer overflow in H5O__layout_encode in H5Olayout.c in the HDF HDF5 through 1.10.4 library allows attackers to cause a denial of service via a crafted HDF5 file. This issue was triggered while repacking an HDF5 file, aka "Invalid write of size 2."
nvdosv
CVE-2018-17435P4MEDIUMCVSS 6.5≤ 1.10.32018-09-24
CVE-2018-17435 [MEDIUM] CWE-125 CVE-2018-17435: A heap-based buffer over-read in H5O_attr_decode() in H5Oattr.c in the HDF HDF5 through 1.10.3 libra
A heap-based buffer over-read in H5O_attr_decode() in H5Oattr.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service via a crafted HDF5 file. This issue was triggered while converting an HDF file to GIF file.
nvdosv
CVE-2018-15671P4MEDIUMCVSS 6.5v1.10.22018-08-21
CVE-2018-15671 [MEDIUM] CWE-400 CVE-2018-15671: An issue was discovered in the HDF HDF5 1.10.2 library. Excessive stack consumption has been detecte
An issue was discovered in the HDF HDF5 1.10.2 library. Excessive stack consumption has been detected in the function H5P__get_cb() in H5Pint.c during an attempted parse of a crafted HDF file. This results in denial of service.
nvd
CVE-2021-46243P4MEDIUMCVSS 6.5v1.13.1-12022-01-21
CVE-2021-46243 [MEDIUM] CWE-476 CVE-2021-46243: An untrusted pointer dereference vulnerability exists in HDF5 v1.13.1-1 via the function H5O__dtype_
An untrusted pointer dereference vulnerability exists in HDF5 v1.13.1-1 via the function H5O__dtype_decode_helper () at hdf5/src/H5Odtype.c. This vulnerability can lead to a Denial of Service (DoS).
nvd
CVE-2024-32607P4MEDIUMCVSS 5.7fixed in 1.14.42024-05-14
CVE-2024-32607 [MEDIUM] CWE-125 CVE-2024-32607: HDF5 Library through 1.14.3 has a SEGV in H5A__close in H5Aint.c, resulting in the corruption of the
HDF5 Library through 1.14.3 has a SEGV in H5A__close in H5Aint.c, resulting in the corruption of the instruction pointer.
nvdosv
CVE-2025-2926P4MEDIUMCVSS 5.5≤ 1.14.6v1.14.0+6 more2025-03-28
CVE-2025-2926 [MEDIUM] CWE-404 CVE-2025-2926: A vulnerability was found in HDF5 up to 1.14.6 and classified as problematic. This issue affects the
A vulnerability was found in HDF5 up to 1.14.6 and classified as problematic. This issue affects the function H5O__cache_chk_serialize of the file src/H5Ocache.c. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-6858P4MEDIUMCVSS 5.5v1.14.62025-06-29
CVE-2025-6858 [MEDIUM] CWE-404 CVE-2025-6858: A vulnerability was found in HDF5 1.14.6 and classified as problematic. Affected by this issue is th
A vulnerability was found in HDF5 1.14.6 and classified as problematic. Affected by this issue is the function H5C__flush_single_entry of the file src/H5Centry.c. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.
nvd
CVE-2018-17437P4MEDIUMCVSS 6.5≤ 1.10.32018-09-24
CVE-2018-17437 [MEDIUM] CWE-772 CVE-2018-17437: Memory leak in the H5O_dtype_decode_helper() function in H5Odtype.c in the HDF HDF5 through 1.10.3 l
Memory leak in the H5O_dtype_decode_helper() function in H5Odtype.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service (memory consumption) via a crafted HDF5 file.
nvdosv
CVE-2018-17234P4MEDIUMCVSS 6.5≤ 1.10.32018-09-20
CVE-2018-17234 [MEDIUM] CWE-772 CVE-2018-17234: Memory leak in the H5O__chunk_deserialize() function in H5Ocache.c in the HDF HDF5 through 1.10.3 li
Memory leak in the H5O__chunk_deserialize() function in H5Ocache.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service (memory consumption) via a crafted HDF5 file.
nvdosv
CVE-2018-17432P4MEDIUMCVSS 6.5≤ 1.10.32018-09-24
CVE-2018-17432 [MEDIUM] CWE-476 CVE-2018-17432: A NULL pointer dereference in H5O_sdspace_encode() in H5Osdspace.c in the HDF HDF5 through 1.10.3 li
A NULL pointer dereference in H5O_sdspace_encode() in H5Osdspace.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service via a crafted HDF5 file.
nvdosv
CVE-2018-17436P4MEDIUMCVSS 6.5≤ 1.10.32018-09-24
CVE-2018-17436 [MEDIUM] CWE-787 CVE-2018-17436: ReadCode() in decompress.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial
ReadCode() in decompress.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service (invalid write access) via a crafted HDF5 file. This issue was triggered while converting a GIF file to an HDF file.
nvd
CVE-2024-32610P4MEDIUMCVSS 5.7fixed in 1.14.42024-05-14
CVE-2024-32610 [MEDIUM] CWE-416 CVE-2024-32610: HDF5 Library through 1.14.3 has a SEGV in H5T_close_real in H5T.c, resulting in a corrupted instruct
HDF5 Library through 1.14.3 has a SEGV in H5T_close_real in H5T.c, resulting in a corrupted instruction pointer.
nvdosv
CVE-2024-32606P4MEDIUMCVSS 5.7fixed in 1.14.42024-05-14
CVE-2024-32606 [MEDIUM] CWE-908 CVE-2024-32606: HDF5 Library through 1.14.3 may attempt to dereference uninitialized values in h5tools_str_sprint in
HDF5 Library through 1.14.3 may attempt to dereference uninitialized values in h5tools_str_sprint in tools/lib/h5tools_str.c (called from h5tools_dump_simple_data in tools/lib/h5tools_dump.c).
nvdosv
CVE-2021-45832P4MEDIUMCVSS 5.5v1.13.1-12022-01-05
CVE-2021-45832 [MEDIUM] CWE-674 CVE-2021-45832: A Stack-based Buffer Overflow Vulnerability exists in HDF5 1.13.1-1 at at hdf5/src/H5Eint.c, which c
A Stack-based Buffer Overflow Vulnerability exists in HDF5 1.13.1-1 at at hdf5/src/H5Eint.c, which causes a Denial of Service (context-dependent).
nvd