VendorsHdfgrouphdf5any version
Vulnerabilities

Hdfgroup The HDF Group HDF5 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

72CVEs
CVE-2018-13873
An issue was discovered in the HDF HDF5 1.8.20 library. There is a buffer over-read in H5O_chunk_deserialize in H5Ocache.c.
Published 2018-07-10 · Analyzed
9.8EPSS 0.019
CVE-2024-32615
HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5Z__nbit_decompress_one_byte in H5Znbit.c, caused by the earlier use of an initialized pointer.
Published 2024-05-09 · Analyzed
9.8EPSS 0.011
CVE-2024-32611
HDF5 Library through 1.14.3 may use an uninitialized value in H5A__attr_release_table in H5Aint.c.
Published 2024-05-09 · Analyzed
9.8EPSS 0.010
CVE-2024-33874
HDF5 Library through 1.14.3 has a heap buffer overflow in H5O__mtime_new_encode in H5Omtime.c.
Published 2024-05-09 · Analyzed
9.8EPSS 0.009
CVE-2024-32621
HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5HG_read in H5HG.c (called from H5VL__native_blob_get in H5VLnative_blob.c), resulting in the corruption of the instruction pointer.
Published 2024-05-09 · Analyzed
9.8EPSS 0.009
CVE-2024-29159
HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_scaleoffset, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
Published 2024-05-09 · Analyzed
9.8EPSS 0.009
CVE-2024-29157
HDF5 through 1.14.3 contains a heap buffer overflow in H5HG_read, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
Published 2024-05-09 · Analyzed
9.8EPSS 0.009
CVE-2024-29164
HDF5 through 1.14.3 contains a stack buffer overflow in H5R__decode_heap, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
Published 2024-05-09 · Analyzed
9.8EPSS 0.009
CVE-2024-32608
HDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
Published 2024-10-09 · Modified
9.8EPSS 0.007
CVE-2024-32622
HDF5 Library through 1.14.3 contains a out-of-bounds read operation in H5FL_arr_malloc in H5FL.c (called from H5S_set_extent_simple in H5S.c).
Published 2024-05-09 · Analyzed
9.1EPSS 0.010
CVE-2024-32614
HDF5 Library through 1.14.3 has a SEGV in H5VM_memcpyvv in H5VM.c.
Published 2024-05-09 · Analyzed
8.8EPSS 0.009
CVE-2024-32605
HDF5 Library through 1.14.3 has a heap-based buffer over-read in H5VM_memcpyvv in H5VM.c (called from H5D__compact_readvv in H5Dcompact.c).
Published 2024-05-09 · Analyzed
8.8EPSS 0.009
CVE-2024-33877
HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5T__conv_struct_opt in H5Tconv.c.
Published 2024-05-09 · Analyzed
8.8EPSS 0.009
CVE-2024-33873
HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5D__scatter_mem in H5Dscatgath.c.
Published 2024-05-09 · Analyzed
8.8EPSS 0.009
CVE-2024-32623
HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5VM_array_fill in H5VM.c (called from H5S_select_elements in H5Spoint.c).
Published 2024-05-09 · Analyzed
8.8EPSS 0.009
CVE-2024-29161
HDF5 through 1.14.3 contains a heap buffer overflow in H5A__attr_release_table, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
Published 2024-05-09 · Analyzed
8.8EPSS 0.009
CVE-2024-32617
HDF5 Library through 1.14.3 contains a heap-based buffer over-read caused by the unsafe use of strdup in H5MM_xstrdup in H5MM.c (called from H5G__ent_to_link in H5Glink.c).
Published 2024-05-09 · Analyzed
8.8EPSS 0.008
CVE-2025-6516
HDF5 H5Fint.c H5F_addr_decode_len heap-based overflow
Published 2025-06-23 · Analyzed
7.8EPSS 0.004
CVE-2026-26200
HDF5 Affected by H5T__conv_struct_opt Heap Buffer Overflow
Published 2026-02-19 · Modified
7.8EPSS 0.004
CVE-2026-34734
HDF5: H5T__conv_struct Use After Free
Published 2026-04-09 · Modified
7.8EPSS 0.002
CVE-2021-37501
Buffer Overflow vulnerability in HDFGroup hdf5-h5dump 1.12.0 through 1.13.0 allows attackers to cause a denial of service via h5tools_str_sprint in /hdf5/tools/lib/h5tools_str.c.
Published 2023-02-03 · Modified
7.5EPSS 0.015
CVE-2024-32609
HDF5 Library through 1.14.3 allows stack consumption in the function H5E_printf_stack in H5Eint.c.
Published 2024-05-09 · Analyzed
7.5EPSS 0.008
CVE-2026-26197
Array full size, element count, and element size are not checked to make sure they match in H5Odtype.c
Published 2026-07-20 · Analyzed
7.5EPSS 0.004
CVE-2024-32624
HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__ref_mem_setnull in H5Tref.c (called from H5T__conv_ref in H5Tconv.c), resulting in the corruption of the instruction pointer.
Published 2024-05-09 · Analyzed
7.4EPSS 0.006
CVE-2024-32616
HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5O__dtype_encode_helper in H5Odtype.c.
Published 2024-05-09 · Analyzed
7.4EPSS 0.003
CVE-2024-32612
HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5HL__fl_deserialize in H5HLcache.c, resulting in the corruption of the instruction pointer, a different vulnerability than CVE-2024-32613.
Published 2024-05-09 · Analyzed
7.4EPSS 0.003
CVE-2024-32613
HDF5 Library through 1.14.3 contains a heap-based buffer over-read in the function H5HL__fl_deserialize in H5HLcache.c, a different vulnerability than CVE-2024-32612.
Published 2024-05-09 · Analyzed
7.4EPSS 0.002
CVE-2024-32620
HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5F_addr_decode_len in H5Fint.c, resulting in the corruption of the instruction pointer.
Published 2024-05-09 · Analyzed
7.4EPSS 0.002
CVE-2024-32619
HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T_copy_reopen in H5T.c, resulting in the corruption of the instruction pointer.
Published 2024-05-09 · Analyzed
7.4EPSS 0.002
CVE-2024-32618
HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__get_native_type in H5Tnative.c, resulting in the corruption of the instruction pointer.
Published 2024-05-09 · Analyzed
7.4EPSS 0.002
CVE-2024-29165
HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_fletcher32, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
Published 2024-05-09 · Analyzed
7.4EPSS 0.002
CVE-2024-29158
HDF5 through 1.14.3 contains a stack buffer overflow in H5FL_arr_malloc, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
Published 2024-05-09 · Analyzed
7.4EPSS 0.002
CVE-2024-29160
HDF5 through 1.14.3 contains a heap buffer overflow in H5HG__cache_heap_deserialize, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
Published 2024-05-09 · Analyzed
7.4EPSS 0.002
CVE-2024-29162
HDF5 through 1.13.3 and/or 1.14.2 contains a stack buffer overflow in H5HG_read, resulting in denial of service or potential code execution.
Published 2024-05-09 · Analyzed
7.4EPSS 0.002
CVE-2024-29163
HDF5 through 1.14.3 contains a heap buffer overflow in H5T__bit_find, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
Published 2024-05-09 · Analyzed
7.4EPSS 0.002
CVE-2018-17434
A SIGFPE signal is raised in the function apply_filters() of h5repack_filters.c in the HDF HDF5 through 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. It could allow a remote denial of service attack.
Published 2018-09-24 · Modified
6.5EPSS 0.018
CVE-2018-17233
A SIGFPE signal is raised in the function H5D__create_chunk_file_map_hyper() of H5Dchunk.c in the HDF HDF5 through 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. It could allow a remote denial of service attack.
Published 2018-09-20 · Modified
6.5EPSS 0.018
CVE-2018-17438
A SIGFPE signal is raised in the function H5D__select_io() of H5Dselect.c in the HDF HDF5 through 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. It could allow a remote denial of service attack.
Published 2018-09-24 · Modified
6.5EPSS 0.017
CVE-2019-8396
A buffer overflow in H5O__layout_encode in H5Olayout.c in the HDF HDF5 through 1.10.4 library allows attackers to cause a denial of service via a crafted HDF5 file. This issue was triggered while repacking an HDF5 file, aka "Invalid write of size 2."
Published 2019-02-17 · Modified
6.5EPSS 0.013
CVE-2018-17234
Memory leak in the H5O__chunk_deserialize() function in H5Ocache.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service (memory consumption) via a crafted HDF5 file.
Published 2018-09-20 · Modified
6.5EPSS 0.013
1 / 2Next →