hdfgroup CVE Vulnerabilities & Metrics

Focus on hdfgroup vulnerabilities and metrics.

Last updated: 08 May 2025, 22:25 UTC

About hdfgroup Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with hdfgroup. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total hdfgroup CVEs: 106
Earliest CVE date: 18 Nov 2016, 20:59 UTC
Latest CVE date: 28 Mar 2025, 20:15 UTC

Latest CVE reference: CVE-2025-2926

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 40

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): -100.0%
Year Variation (Calendar): 1900.0%

Month Growth Rate (30-day Rolling): -100.0%
Year Growth Rate (365-day Rolling): 1900.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical hdfgroup CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 3.23

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 45
4.0-6.9 51
7.0-8.9 10
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS hdfgroup CVEs

These are the five CVEs with the highest CVSS scores for hdfgroup, sorted by severity first and recency.

All CVEs for hdfgroup

CVE-2025-2926 hdfgroup vulnerability CVSS: 1.7 28 Mar 2025, 20:15 UTC

A vulnerability was found in HDF5 up to 1.14.6 and classified as problematic. This issue affects the function H5O__cache_chk_serialize of the file src/H5Ocache.c. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.

CVE-2025-2925 hdfgroup vulnerability CVSS: 1.7 28 Mar 2025, 20:15 UTC

A vulnerability has been found in HDF5 up to 1.14.6 and classified as problematic. This vulnerability affects the function H5MM_realloc of the file src/H5MM.c. The manipulation of the argument mem leads to double free. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.

CVE-2025-2924 hdfgroup vulnerability CVSS: 1.7 28 Mar 2025, 20:15 UTC

A vulnerability, which was classified as problematic, was found in HDF5 up to 1.14.6. This affects the function H5HL__fl_deserialize of the file src/H5HLcache.c. The manipulation of the argument free_block leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.

CVE-2025-2915 hdfgroup vulnerability CVSS: 1.7 28 Mar 2025, 17:15 UTC

A vulnerability classified as problematic was found in HDF5 up to 1.14.6. This vulnerability affects the function H5F__accum_free of the file src/H5Faccum.c. The manipulation of the argument overlap_size leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

CVE-2025-2153 hdfgroup vulnerability CVSS: 5.1 10 Mar 2025, 14:15 UTC

A vulnerability, which was classified as critical, was found in HDF5 1.14.6. Affected is the function H5SM_delete of the file H5SM.c of the component h5 File Handler. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.

CVE-2024-32608 hdfgroup vulnerability CVSS: 0 09 Oct 2024, 05:15 UTC

HDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

CVE-2024-33877 hdfgroup vulnerability CVSS: 0 14 May 2024, 15:38 UTC

HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5T__conv_struct_opt in H5Tconv.c.

CVE-2024-33876 hdfgroup vulnerability CVSS: 0 14 May 2024, 15:38 UTC

HDF5 Library through 1.14.3 has a heap buffer overflow in H5S__point_deserialize in H5Spoint.c.

CVE-2024-33875 hdfgroup vulnerability CVSS: 0 14 May 2024, 15:38 UTC

HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5O__layout_encode in H5Olayout.c, resulting in the corruption of the instruction pointer.

CVE-2024-33874 hdfgroup vulnerability CVSS: 0 14 May 2024, 15:38 UTC

HDF5 Library through 1.14.3 has a heap buffer overflow in H5O__mtime_new_encode in H5Omtime.c.

CVE-2024-33873 hdfgroup vulnerability CVSS: 0 14 May 2024, 15:38 UTC

HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5D__scatter_mem in H5Dscatgath.c.

CVE-2024-32624 hdfgroup vulnerability CVSS: 0 14 May 2024, 15:36 UTC

HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__ref_mem_setnull in H5Tref.c (called from H5T__conv_ref in H5Tconv.c), resulting in the corruption of the instruction pointer.

CVE-2024-32623 hdfgroup vulnerability CVSS: 0 14 May 2024, 15:36 UTC

HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5VM_array_fill in H5VM.c (called from H5S_select_elements in H5Spoint.c).

CVE-2024-32622 hdfgroup vulnerability CVSS: 0 14 May 2024, 15:36 UTC

HDF5 Library through 1.14.3 contains a out-of-bounds read operation in H5FL_arr_malloc in H5FL.c (called from H5S_set_extent_simple in H5S.c).

CVE-2024-32621 hdfgroup vulnerability CVSS: 0 14 May 2024, 15:36 UTC

HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5HG_read in H5HG.c (called from H5VL__native_blob_get in H5VLnative_blob.c), resulting in the corruption of the instruction pointer.

CVE-2024-32620 hdfgroup vulnerability CVSS: 0 14 May 2024, 15:36 UTC

HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5F_addr_decode_len in H5Fint.c, resulting in the corruption of the instruction pointer.

CVE-2024-32619 hdfgroup vulnerability CVSS: 0 14 May 2024, 15:36 UTC

HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T_copy_reopen in H5T.c, resulting in the corruption of the instruction pointer.

CVE-2024-32618 hdfgroup vulnerability CVSS: 0 14 May 2024, 15:36 UTC

HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__get_native_type in H5Tnative.c, resulting in the corruption of the instruction pointer.

CVE-2024-32617 hdfgroup vulnerability CVSS: 0 14 May 2024, 15:36 UTC

HDF5 Library through 1.14.3 contains a heap-based buffer over-read caused by the unsafe use of strdup in H5MM_xstrdup in H5MM.c (called from H5G__ent_to_link in H5Glink.c).

CVE-2024-32616 hdfgroup vulnerability CVSS: 0 14 May 2024, 15:36 UTC

HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5O__dtype_encode_helper in H5Odtype.c.

CVE-2024-32615 hdfgroup vulnerability CVSS: 0 14 May 2024, 15:36 UTC

HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5Z__nbit_decompress_one_byte in H5Znbit.c, caused by the earlier use of an initialized pointer.

CVE-2024-32614 hdfgroup vulnerability CVSS: 0 14 May 2024, 15:36 UTC

HDF5 Library through 1.14.3 has a SEGV in H5VM_memcpyvv in H5VM.c.

CVE-2024-32613 hdfgroup vulnerability CVSS: 0 14 May 2024, 15:36 UTC

HDF5 Library through 1.14.3 contains a heap-based buffer over-read in the function H5HL__fl_deserialize in H5HLcache.c, a different vulnerability than CVE-2024-32612.

CVE-2024-32612 hdfgroup vulnerability CVSS: 0 14 May 2024, 15:36 UTC

HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5HL__fl_deserialize in H5HLcache.c, resulting in the corruption of the instruction pointer, a different vulnerability than CVE-2024-32613.

CVE-2024-32611 hdfgroup vulnerability CVSS: 0 14 May 2024, 15:36 UTC

HDF5 Library through 1.14.3 may use an uninitialized value in H5A__attr_release_table in H5Aint.c.

CVE-2024-32610 hdfgroup vulnerability CVSS: 0 14 May 2024, 15:36 UTC

HDF5 Library through 1.14.3 has a SEGV in H5T_close_real in H5T.c, resulting in a corrupted instruction pointer.

CVE-2024-32609 hdfgroup vulnerability CVSS: 0 14 May 2024, 15:36 UTC

HDF5 Library through 1.14.3 allows stack consumption in the function H5E_printf_stack in H5Eint.c.

CVE-2024-32607 hdfgroup vulnerability CVSS: 0 14 May 2024, 15:36 UTC

HDF5 Library through 1.14.3 has a SEGV in H5A__close in H5Aint.c, resulting in the corruption of the instruction pointer.

CVE-2024-32606 hdfgroup vulnerability CVSS: 0 14 May 2024, 15:36 UTC

HDF5 Library through 1.14.3 may attempt to dereference uninitialized values in h5tools_str_sprint in tools/lib/h5tools_str.c (called from h5tools_dump_simple_data in tools/lib/h5tools_dump.c).

CVE-2024-32605 hdfgroup vulnerability CVSS: 0 14 May 2024, 15:36 UTC

HDF5 Library through 1.14.3 has a heap-based buffer over-read in H5VM_memcpyvv in H5VM.c (called from H5D__compact_readvv in H5Dcompact.c).

CVE-2024-29166 hdfgroup vulnerability CVSS: 0 14 May 2024, 15:15 UTC

HDF5 through 1.14.3 contains a buffer overflow in H5O__linfo_decode, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

CVE-2024-29165 hdfgroup vulnerability CVSS: 0 14 May 2024, 15:15 UTC

HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_fletcher32, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

CVE-2024-29164 hdfgroup vulnerability CVSS: 0 14 May 2024, 15:15 UTC

HDF5 through 1.14.3 contains a stack buffer overflow in H5R__decode_heap, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

CVE-2024-29163 hdfgroup vulnerability CVSS: 0 14 May 2024, 15:15 UTC

HDF5 through 1.14.3 contains a heap buffer overflow in H5T__bit_find, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

CVE-2024-29162 hdfgroup vulnerability CVSS: 0 14 May 2024, 15:15 UTC

HDF5 through 1.13.3 and/or 1.14.2 contains a stack buffer overflow in H5HG_read, resulting in denial of service or potential code execution.

CVE-2024-29161 hdfgroup vulnerability CVSS: 0 14 May 2024, 15:15 UTC

HDF5 through 1.14.3 contains a heap buffer overflow in H5A__attr_release_table, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

CVE-2024-29160 hdfgroup vulnerability CVSS: 0 14 May 2024, 15:15 UTC

HDF5 through 1.14.3 contains a heap buffer overflow in H5HG__cache_heap_deserialize, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

CVE-2024-29159 hdfgroup vulnerability CVSS: 0 14 May 2024, 15:15 UTC

HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_scaleoffset, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

CVE-2024-29158 hdfgroup vulnerability CVSS: 0 14 May 2024, 15:15 UTC

HDF5 through 1.14.3 contains a stack buffer overflow in H5FL_arr_malloc, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

CVE-2024-29157 hdfgroup vulnerability CVSS: 0 14 May 2024, 15:15 UTC

HDF5 through 1.14.3 contains a heap buffer overflow in H5HG_read, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

CVE-2020-18494 hdfgroup vulnerability CVSS: 0 22 Aug 2023, 19:15 UTC

Buffer Overflow vulnerability in function H5S_close in H5S.c in HDF5 1.10.4 allows remote attackers to run arbitrary code via creation of crafted file.

CVE-2020-18232 hdfgroup vulnerability CVSS: 0 22 Aug 2023, 19:15 UTC

Buffer Overflow vulnerability in function H5S_close in H5S.c in HDF5 1.10.4 allows remote attackers to run arbitrary code via creation of crafted file.

CVE-2021-37501 hdfgroup vulnerability CVSS: 0 03 Feb 2023, 18:15 UTC

Buffer Overflow vulnerability in HDFGroup hdf5-h5dump 1.12.0 through 1.13.0 allows attackers to cause a denial of service via h5tools_str_sprint in /hdf5/tools/lib/h5tools_str.c.

CVE-2022-26061 hdfgroup vulnerability CVSS: 0 22 Aug 2022, 19:15 UTC

A heap-based buffer overflow vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-25972 hdfgroup vulnerability CVSS: 0 22 Aug 2022, 19:15 UTC

An out-of-bounds write vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-25942 hdfgroup vulnerability CVSS: 0 22 Aug 2022, 19:15 UTC

An out-of-bounds read vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-46244 hdfgroup vulnerability CVSS: 4.3 21 Jan 2022, 21:15 UTC

A Divide By Zero vulnerability exists in HDF5 v1.13.1-1 vis the function H5T__complete_copy () at /hdf5/src/H5T.c. This vulnerability causes an aritmetic exception, leading to a Denial of Service (DoS).

CVE-2021-46243 hdfgroup vulnerability CVSS: 4.3 21 Jan 2022, 21:15 UTC

An untrusted pointer dereference vulnerability exists in HDF5 v1.13.1-1 via the function H5O__dtype_decode_helper () at hdf5/src/H5Odtype.c. This vulnerability can lead to a Denial of Service (DoS).

CVE-2021-46242 hdfgroup vulnerability CVSS: 6.8 21 Jan 2022, 21:15 UTC

HDF5 v1.13.1-1 was discovered to contain a heap-use-after free via the component H5AC_unpin_entry.

CVE-2021-45833 hdfgroup vulnerability CVSS: 4.3 05 Jan 2022, 21:15 UTC

A Stack-based Buffer Overflow Vulnerability exists in HDF5 1.13.1-1 via the H5D__create_chunk_file_map_hyper function in /hdf5/src/H5Dchunk.c, which causes a Denial of Service (context-dependent).

CVE-2021-45832 hdfgroup vulnerability CVSS: 4.3 05 Jan 2022, 21:15 UTC

A Stack-based Buffer Overflow Vulnerability exists in HDF5 1.13.1-1 at at hdf5/src/H5Eint.c, which causes a Denial of Service (context-dependent).

CVE-2021-45830 hdfgroup vulnerability CVSS: 4.3 05 Jan 2022, 20:15 UTC

A heap-based buffer overflow vulnerability exists in HDF5 1.13.1-1 via H5F_addr_decode_len in /hdf5/src/H5Fint.c, which could cause a Denial of Service.

CVE-2021-45829 hdfgroup vulnerability CVSS: 4.3 03 Jan 2022, 22:15 UTC

HDF5 1.13.1-1 is affected by: segmentation fault, which causes a Denial of Service.

CVE-2020-10812 hdfgroup vulnerability CVSS: 4.3 22 Mar 2020, 18:15 UTC

An issue was discovered in HDF5 through 1.12.0. A NULL pointer dereference exists in the function H5F_get_nrefs() located in H5Fquery.c. It allows an attacker to cause Denial of Service.

CVE-2020-10811 hdfgroup vulnerability CVSS: 4.3 22 Mar 2020, 18:15 UTC

An issue was discovered in HDF5 through 1.12.0. A heap-based buffer over-read exists in the function H5O__layout_decode() located in H5Olayout.c. It allows an attacker to cause Denial of Service.

CVE-2020-10810 hdfgroup vulnerability CVSS: 4.3 22 Mar 2020, 18:15 UTC

An issue was discovered in HDF5 through 1.12.0. A NULL pointer dereference exists in the function H5AC_unpin_entry() located in H5AC.c. It allows an attacker to cause Denial of Service.

CVE-2020-10809 hdfgroup vulnerability CVSS: 4.3 22 Mar 2020, 18:15 UTC

An issue was discovered in HDF5 through 1.12.0. A heap-based buffer overflow exists in the function Decompress() located in decompress.c. It can be triggered by sending a crafted file to the gif2h5 binary. It allows an attacker to cause Denial of Service.

CVE-2019-9152 hdfgroup vulnerability CVSS: 6.8 25 Feb 2019, 19:29 UTC

An issue was discovered in the HDF HDF5 1.10.4 library. There is an out of bounds read in the function H5MM_xstrdup in H5MM.c when called from H5O_dtype_decode_helper in H5Odtype.c.

CVE-2019-9151 hdfgroup vulnerability CVSS: 6.8 25 Feb 2019, 19:29 UTC

An issue was discovered in the HDF HDF5 1.10.4 library. There is an out of bounds read in the function H5VM_memcpyvv in H5VM.c when called from H5D__compact_readvv in H5Dcompact.c.

CVE-2019-8398 hdfgroup vulnerability CVSS: 4.3 17 Feb 2019, 06:29 UTC

An issue was discovered in the HDF HDF5 1.10.4 library. There is an out of bounds read in the function H5T_get_size in H5T.c.

CVE-2019-8397 hdfgroup vulnerability CVSS: 4.3 17 Feb 2019, 06:29 UTC

An issue was discovered in the HDF HDF5 1.10.4 library. There is an out of bounds read in the function H5T_close_real in H5T.c.

CVE-2019-8396 hdfgroup vulnerability CVSS: 4.3 17 Feb 2019, 06:29 UTC

A buffer overflow in H5O__layout_encode in H5Olayout.c in the HDF HDF5 through 1.10.4 library allows attackers to cause a denial of service via a crafted HDF5 file. This issue was triggered while repacking an HDF5 file, aka "Invalid write of size 2."

CVE-2018-17439 hdfgroup vulnerability CVSS: 4.3 24 Sep 2018, 14:29 UTC

An issue was discovered in the HDF HDF5 1.10.3 library. There is a stack-based buffer overflow in the function H5S_extent_get_dims() in H5S.c. Specifically, this issue occurs while converting an HDF5 file to a GIF file.

CVE-2018-17438 hdfgroup vulnerability CVSS: 4.3 24 Sep 2018, 14:29 UTC

A SIGFPE signal is raised in the function H5D__select_io() of H5Dselect.c in the HDF HDF5 through 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. It could allow a remote denial of service attack.

CVE-2018-17437 hdfgroup vulnerability CVSS: 4.3 24 Sep 2018, 14:29 UTC

Memory leak in the H5O_dtype_decode_helper() function in H5Odtype.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service (memory consumption) via a crafted HDF5 file.

CVE-2018-17436 hdfgroup vulnerability CVSS: 4.3 24 Sep 2018, 14:29 UTC

ReadCode() in decompress.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service (invalid write access) via a crafted HDF5 file. This issue was triggered while converting a GIF file to an HDF file.

CVE-2018-17435 hdfgroup vulnerability CVSS: 4.3 24 Sep 2018, 14:29 UTC

A heap-based buffer over-read in H5O_attr_decode() in H5Oattr.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service via a crafted HDF5 file. This issue was triggered while converting an HDF file to GIF file.

CVE-2018-17434 hdfgroup vulnerability CVSS: 4.3 24 Sep 2018, 14:29 UTC

A SIGFPE signal is raised in the function apply_filters() of h5repack_filters.c in the HDF HDF5 through 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. It could allow a remote denial of service attack.

CVE-2018-17433 hdfgroup vulnerability CVSS: 4.3 24 Sep 2018, 14:29 UTC

A heap-based buffer overflow in ReadGifImageDesc() in gifread.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service via a crafted HDF5 file. This issue was triggered while converting a GIF file to an HDF file.

CVE-2018-17432 hdfgroup vulnerability CVSS: 4.3 24 Sep 2018, 14:29 UTC

A NULL pointer dereference in H5O_sdspace_encode() in H5Osdspace.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service via a crafted HDF5 file.

CVE-2018-17237 hdfgroup vulnerability CVSS: 4.3 20 Sep 2018, 06:29 UTC

A SIGFPE signal is raised in the function H5D__chunk_set_info_real() of H5Dchunk.c in the HDF HDF5 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. This issue is different from CVE-2018-11207.

CVE-2018-17234 hdfgroup vulnerability CVSS: 4.3 20 Sep 2018, 06:29 UTC

Memory leak in the H5O__chunk_deserialize() function in H5Ocache.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service (memory consumption) via a crafted HDF5 file.

CVE-2018-17233 hdfgroup vulnerability CVSS: 4.3 20 Sep 2018, 06:29 UTC

A SIGFPE signal is raised in the function H5D__create_chunk_file_map_hyper() of H5Dchunk.c in the HDF HDF5 through 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. It could allow a remote denial of service attack.

CVE-2018-16438 hdfgroup vulnerability CVSS: 6.8 04 Sep 2018, 00:29 UTC

An issue was discovered in the HDF HDF5 1.8.20 library. There is an out of bounds read in H5L_extern_query at H5Lexternal.c.

CVE-2018-15671 hdfgroup vulnerability CVSS: 4.3 21 Aug 2018, 23:29 UTC

An issue was discovered in the HDF HDF5 1.10.2 library. Excessive stack consumption has been detected in the function H5P__get_cb() in H5Pint.c during an attempted parse of a crafted HDF file. This results in denial of service.

CVE-2018-14460 hdfgroup vulnerability CVSS: 6.8 20 Jul 2018, 15:29 UTC

An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5O_sdspace_decode in H5Osdspace.c.

CVE-2018-14035 hdfgroup vulnerability CVSS: 6.8 13 Jul 2018, 02:29 UTC

An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5VM_memcpyvv in H5VM.c.

CVE-2018-14034 hdfgroup vulnerability CVSS: 6.8 13 Jul 2018, 02:29 UTC

An issue was discovered in the HDF HDF5 1.8.20 library. There is an out of bounds read in the function H5O_pline_reset in H5Opline.c.

CVE-2018-14033 hdfgroup vulnerability CVSS: 6.8 13 Jul 2018, 02:29 UTC

An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5O_layout_decode in H5Olayout.c, related to HDmemcpy.

CVE-2018-14031 hdfgroup vulnerability CVSS: 6.8 13 Jul 2018, 02:29 UTC

An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5T_copy in H5T.c.

CVE-2018-13876 hdfgroup vulnerability CVSS: 7.5 10 Jul 2018, 21:29 UTC

An issue was discovered in the HDF HDF5 1.8.20 library. There is a stack-based buffer overflow in the function H5FD_sec2_read in H5FDsec2.c, related to HDread.

CVE-2018-13875 hdfgroup vulnerability CVSS: 6.8 10 Jul 2018, 21:29 UTC

An issue was discovered in the HDF HDF5 1.8.20 library. There is an out-of-bounds read in the function H5VM_memcpyvv in H5VM.c.

CVE-2018-13874 hdfgroup vulnerability CVSS: 7.5 10 Jul 2018, 21:29 UTC

An issue was discovered in the HDF HDF5 1.8.20 library. There is a stack-based buffer overflow in the function H5FD_sec2_read in H5FDsec2.c, related to HDmemset.

CVE-2018-13873 hdfgroup vulnerability CVSS: 7.5 10 Jul 2018, 21:29 UTC

An issue was discovered in the HDF HDF5 1.8.20 library. There is a buffer over-read in H5O_chunk_deserialize in H5Ocache.c.

CVE-2018-13872 hdfgroup vulnerability CVSS: 7.5 10 Jul 2018, 21:29 UTC

An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer overflow in the function H5G_ent_decode in H5Gent.c.

CVE-2018-13871 hdfgroup vulnerability CVSS: 7.5 10 Jul 2018, 21:29 UTC

An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer overflow in the function H5FL_blk_malloc in H5FL.c.

CVE-2018-13870 hdfgroup vulnerability CVSS: 7.5 10 Jul 2018, 21:29 UTC

An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5O_link_decode in H5Olink.c.

CVE-2018-13869 hdfgroup vulnerability CVSS: 7.5 10 Jul 2018, 21:29 UTC

An issue was discovered in the HDF HDF5 1.8.20 library. There is a memcpy parameter overlap in the function H5O_link_decode in H5Olink.c.

CVE-2018-13868 hdfgroup vulnerability CVSS: 7.5 10 Jul 2018, 21:29 UTC

An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5O_fill_old_decode in H5Ofill.c.

CVE-2018-13867 hdfgroup vulnerability CVSS: 7.5 10 Jul 2018, 21:29 UTC

An issue was discovered in the HDF HDF5 1.8.20 library. There is an out of bounds read in the function H5F__accum_read in H5Faccum.c.

CVE-2018-13866 hdfgroup vulnerability CVSS: 7.5 10 Jul 2018, 21:29 UTC

An issue was discovered in the HDF HDF5 1.8.20 library. There is a stack-based buffer over-read in the function H5F_addr_decode_len in H5Fint.c.

CVE-2018-11207 hdfgroup vulnerability CVSS: 4.3 16 May 2018, 15:29 UTC

A division by zero was discovered in H5D__chunk_init in H5Dchunk.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.

CVE-2018-11206 hdfgroup vulnerability CVSS: 5.8 16 May 2018, 15:29 UTC

An out of bounds read was discovered in H5O_fill_new_decode and H5O_fill_old_decode in H5Ofill.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service or information disclosure attack.

CVE-2018-11205 hdfgroup vulnerability CVSS: 5.8 16 May 2018, 15:29 UTC

A out of bounds read was discovered in H5VM_memcpyvv in H5VM.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service or information disclosure attack.

CVE-2018-11204 hdfgroup vulnerability CVSS: 4.3 16 May 2018, 15:29 UTC

A NULL pointer dereference was discovered in H5O__chunk_deserialize in H5Ocache.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.

CVE-2018-11203 hdfgroup vulnerability CVSS: 4.3 16 May 2018, 15:29 UTC

A division by zero was discovered in H5D__btree_decode_key in H5Dbtree.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.

CVE-2018-11202 hdfgroup vulnerability CVSS: 4.3 16 May 2018, 15:29 UTC

A NULL pointer dereference was discovered in H5S_hyper_make_spans in H5Shyper.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.

CVE-2017-17509 hdfgroup vulnerability CVSS: 6.8 11 Dec 2017, 03:29 UTC

In HDF5 1.10.1, there is an out of bounds write vulnerability in the function H5G__ent_decode_vec in H5Gcache.c in libhdf5.a. For example, h5dump would crash or possibly have unspecified other impact someone opens a crafted hdf5 file.

CVE-2017-17508 hdfgroup vulnerability CVSS: 4.3 11 Dec 2017, 03:29 UTC

In HDF5 1.10.1, there is a divide-by-zero vulnerability in the function H5T_set_loc in the H5T.c file in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file.

CVE-2017-17507 hdfgroup vulnerability CVSS: 4.3 11 Dec 2017, 03:29 UTC

In HDF5 1.10.1, there is an out of bounds read vulnerability in the function H5T_conv_struct_opt in H5Tconv.c in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file.

CVE-2017-17506 hdfgroup vulnerability CVSS: 4.3 11 Dec 2017, 03:29 UTC

In HDF5 1.10.1, there is an out of bounds read vulnerability in the function H5Opline_pline_decode in H5Opline.c in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file.

CVE-2017-17505 hdfgroup vulnerability CVSS: 4.3 11 Dec 2017, 03:29 UTC

In HDF5 1.10.1, there is a NULL pointer dereference in the function H5O_pline_decode in the H5Opline.c file in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file.

CVE-2016-4333 hdfgroup vulnerability CVSS: 6.9 18 Nov 2016, 20:59 UTC

The HDF5 1.8.16 library allocating space for the array using a value from the file has an impact within the loop for initializing said array allowing a value within the file to modify the loop's terminator. Due to this, an aggressor can cause the loop's index to point outside the bounds of the array when initializing it.

CVE-2016-4332 hdfgroup vulnerability CVSS: 6.9 18 Nov 2016, 20:59 UTC

The library's failure to check if certain message types support a particular flag, the HDF5 1.8.16 library will cast the structure to an alternative structure and then assign to fields that aren't supported by the message type and the library will write outside the bounds of the heap buffer. This can lead to code execution under the context of the library.

CVE-2016-4331 hdfgroup vulnerability CVSS: 6.9 18 Nov 2016, 20:59 UTC

When decoding data out of a dataset encoded with the H5Z_NBIT decoding, the HDF5 1.8.16 library will fail to ensure that the precision is within the bounds of the size leading to arbitrary code execution.

CVE-2016-4330 hdfgroup vulnerability CVSS: 6.9 18 Nov 2016, 20:59 UTC

In the HDF5 1.8.16 library's failure to check if the number of dimensions for an array read from the file is within the bounds of the space allocated for it, a heap-based buffer overflow will occur, potentially leading to arbitrary code execution.