VendorsHdfgrouphdf5any version
Vulnerabilities

Hdfgroup The HDF Group HDF5 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

72CVEs
CVE-2018-17234
Memory leak in the H5O__chunk_deserialize() function in H5Ocache.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service (memory consumption) via a crafted HDF5 file.
Published 2018-09-20 · Modified
6.5EPSS 0.013
CVE-2018-17237
A SIGFPE signal is raised in the function H5D__chunk_set_info_real() of H5Dchunk.c in the HDF HDF5 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. This issue is different from CVE-2018-11207.
Published 2018-09-20 · Modified
6.5EPSS 0.013
CVE-2018-17432
A NULL pointer dereference in H5O_sdspace_encode() in H5Osdspace.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service via a crafted HDF5 file.
Published 2018-09-24 · Modified
6.5EPSS 0.013
CVE-2018-17436
ReadCode() in decompress.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service (invalid write access) via a crafted HDF5 file. This issue was triggered while converting a GIF file to an HDF file.
Published 2018-09-24 · Modified
6.5EPSS 0.013
CVE-2018-17435
A heap-based buffer over-read in H5O_attr_decode() in H5Oattr.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service via a crafted HDF5 file. This issue was triggered while converting an HDF file to GIF file.
Published 2018-09-24 · Modified
6.5EPSS 0.013
CVE-2018-17433
A heap-based buffer overflow in ReadGifImageDesc() in gifread.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service via a crafted HDF5 file. This issue was triggered while converting a GIF file to an HDF file.
Published 2018-09-24 · Modified
6.5EPSS 0.013
CVE-2017-17506
In HDF5 1.10.1, there is an out of bounds read vulnerability in the function H5Opline_pline_decode in H5Opline.c in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file.
Published 2017-12-11 · Modified
6.5EPSS 0.013
CVE-2026-26199
Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero
Published 2026-07-20 · Analyzed
6.5EPSS 0.004
CVE-2024-32607
HDF5 Library through 1.14.3 has a SEGV in H5A__close in H5Aint.c, resulting in the corruption of the instruction pointer.
Published 2024-05-09 · Analyzed
5.7EPSS 0.002
CVE-2024-32610
HDF5 Library through 1.14.3 has a SEGV in H5T_close_real in H5T.c, resulting in a corrupted instruction pointer.
Published 2024-05-09 · Analyzed
5.7EPSS 0.002
CVE-2024-32606
HDF5 Library through 1.14.3 may attempt to dereference uninitialized values in h5tools_str_sprint in tools/lib/h5tools_str.c (called from h5tools_dump_simple_data in tools/lib/h5tools_dump.c).
Published 2024-05-09 · Analyzed
5.7EPSS 0.002
CVE-2024-33875
HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5O__layout_encode in H5Olayout.c, resulting in the corruption of the instruction pointer.
Published 2024-05-09 · Analyzed
5.7EPSS 0.002
CVE-2024-33876
HDF5 Library through 1.14.3 has a heap buffer overflow in H5S__point_deserialize in H5Spoint.c.
Published 2024-05-09 · Analyzed
5.7EPSS 0.002
CVE-2024-29166
HDF5 through 1.14.3 contains a buffer overflow in H5O__linfo_decode, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
Published 2024-05-09 · Analyzed
5.7EPSS 0.002
CVE-2020-10809
An issue was discovered in HDF5 through 1.12.0. A heap-based buffer overflow exists in the function Decompress() located in decompress.c. It can be triggered by sending a crafted file to the gif2h5 binary. It allows an attacker to cause Denial of Service.
Published 2020-03-22 · Modified
5.5EPSS 0.015
CVE-2020-10812
An issue was discovered in HDF5 through 1.12.0. A NULL pointer dereference exists in the function H5F_get_nrefs() located in H5Fquery.c. It allows an attacker to cause Denial of Service.
Published 2020-03-22 · Modified
5.5EPSS 0.015
CVE-2020-10811
An issue was discovered in HDF5 through 1.12.0. A heap-based buffer over-read exists in the function H5O__layout_decode() located in H5Olayout.c. It allows an attacker to cause Denial of Service.
Published 2020-03-22 · Modified
5.5EPSS 0.015
CVE-2020-10810
An issue was discovered in HDF5 through 1.12.0. A NULL pointer dereference exists in the function H5AC_unpin_entry() located in H5AC.c. It allows an attacker to cause Denial of Service.
Published 2020-03-22 · Modified
5.5EPSS 0.015
CVE-2025-2915
HDF5 H5Faccum.c H5F__accum_free heap-based overflow
Published 2025-03-28 · Analyzed
5.5EPSS 0.003
CVE-2025-2924
HDF5 H5HLcache.c H5HL__fl_deserialize heap-based overflow
Published 2025-03-28 · Modified
5.5EPSS 0.003
CVE-2025-2925
HDF5 H5MM.c H5MM_realloc double free
Published 2025-03-28 · Modified
5.5EPSS 0.003
CVE-2025-2926
HDF5 H5Ocache.c H5O__cache_chk_serialize null pointer dereference
Published 2025-03-28 · Modified
5.5EPSS 0.003
CVE-2026-29043
HDF5 H5T__ref_mem_setnull Heap Buffer Overflow
Published 2026-04-10 · Analyzed
5.5EPSS 0.002
CVE-2026-17573
Double Free in H5D__chunk_copy() in HDF5 via a Crafted Chunk-Index Size Field
Published 2026-07-27 · Analyzed
5.5EPSS 0.002
CVE-2026-17574
NULL Pointer Dereference in HDF5 via Invalid Variable-Length Datatype Type Tag
Published 2026-07-27 · Analyzed
5.5EPSS 0.001
CVE-2026-17572
HDF5 SOHM List Index Heap Buffer Overflow
Published 2026-07-27 · Analyzed
5.5EPSS 0.001
CVE-2025-2912
HDF5 H5Omessage.c H5O_msg_flush heap-based overflow
Published 2025-03-28 · Analyzed
5.3EPSS 0.003
CVE-2025-6269
HDF5 H5Cimage.c H5C__reconstruct_cache_entry heap-based overflow
Published 2025-06-19 · Analyzed
5.3EPSS 0.003
CVE-2025-6270
HDF5 H5FSsection.c H5FS__sect_find_node heap-based overflow
Published 2025-06-19 · Analyzed
5.3EPSS 0.003
CVE-2025-2913
HDF5 H5FL.c H5FL__blk_gc_list use after free
Published 2025-03-28 · Analyzed
5.3EPSS 0.002
CVE-2025-2923
HDF5 H5Fint.c H5F_addr_encode_len heap-based overflow
Published 2025-03-28 · Modified
3.3EPSS 0.003
CVE-2025-2914
HDF5 H5FScache.c H5FS__sinfo_Srialize_Sct_cb heap-based overflow
Published 2025-03-28 · Modified
3.3EPSS 0.003
← Prev2 / 2