CVE-2026-19025
- EPSS 0.12%
- Veröffentlicht 05.08.2026 22:35:11
- Zuletzt bearbeitet 06.08.2026 15:16:45
H5O__layout_decode in H5Olayout.c in HDF5 through 2.3.0 does not validate that a chunked dataset's stored chunk-layout dimensionality matches its dataspace rank when an existing dataset is opened, whereas this check is performed only at dataset-creat...
CVE-2026-17574
- EPSS 0.1%
- Veröffentlicht 27.07.2026 15:12:18
- Zuletzt bearbeitet 18.08.2026 18:56:04
HDF5 contains a NULL pointer dereference vulnerability. Processing a crafted HDF5 file containing an attribute with an invalid variable-length datatype type field may cause the application to crash when the attribute is read.
CVE-2026-17573
- EPSS 0.1%
- Veröffentlicht 27.07.2026 15:11:54
- Zuletzt bearbeitet 18.08.2026 18:56:16
A double free vulnerability was discovered in the HDF5 library. Processing a crafted HDF5 file containing an oversized chunk size field via h5repack may cause the application to abort due to a double free.
CVE-2026-17572
- EPSS 0.1%
- Veröffentlicht 27.07.2026 15:11:36
- Zuletzt bearbeitet 18.08.2026 18:56:24
Heap-based buffer overflow in the SOHM list-index deserialization code in HDF5 through 2.1.1 on all platforms allows attackers to cause a denial of service (crash) via a crafted HDF5 file whose shared-message list index declares a num_messages count ...
CVE-2026-26199
- EPSS 0.26%
- Veröffentlicht 20.07.2026 14:59:35
- Zuletzt bearbeitet 29.07.2026 15:38:17
HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If `H5Iget_name` is invoked on a group id with `0` for the size parameter, it will underflow when trying to place a null terminator in the buffer....
CVE-2026-26197
- EPSS 0.27%
- Veröffentlicht 20.07.2026 14:55:50
- Zuletzt bearbeitet 29.07.2026 15:42:12
HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If a file is corrupted such that an array datatype's size, the number of elements, and the element size are not in agreement it can trigger an ou...
CVE-2026-29043
- EPSS 0.21%
- Veröffentlicht 10.04.2026 15:35:51
- Zuletzt bearbeitet 16.04.2026 19:40:13
HDF5 is software for managing data. In 1.14.1-2 and earlier, an attacker who can control an h5 file parsed by HDF5 can trigger a write-based heap buffer overflow condition in the H5T__ref_mem_setnull method. This can lead to a denial-of-service condi...
CVE-2026-34734
- EPSS 0.19%
- Veröffentlicht 09.04.2026 20:16:25
- Zuletzt bearbeitet 15.07.2026 02:20:34
HDF5 is software for managing data. In 1.14.1-2 and earlier, a heap-use-after-free was found in the h5dump helper utility. An attacker who can supply a malicious h5 file can trigger a heap use-after-free. The freed object is referenced in a memmove c...
CVE-2026-26200
- EPSS 0.36%
- Veröffentlicht 19.02.2026 19:19:10
- Zuletzt bearbeitet 15.07.2026 02:19:00
HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` file parsed by HDF5 can trigger a write-based heap buffer overflow condition. This can lead to a denial-of-service condition, and potentially further i...
CVE-2025-7069
- EPSS 0.22%
- Veröffentlicht 04.07.2025 21:02:06
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5FS__sect_link_size of the file src/H5FSsection.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on ...