CVE-2024-29163
- EPSS 0.08%
- Veröffentlicht 14.05.2024 15:15:32
- Zuletzt bearbeitet 18.04.2025 14:27:15
HDF5 through 1.14.3 contains a heap buffer overflow in H5T__bit_find, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
CVE-2024-29157
- EPSS 0.15%
- Veröffentlicht 14.05.2024 15:15:31
- Zuletzt bearbeitet 18.04.2025 12:23:04
HDF5 through 1.14.3 contains a heap buffer overflow in H5HG_read, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
CVE-2024-29158
- EPSS 0.07%
- Veröffentlicht 14.05.2024 15:15:31
- Zuletzt bearbeitet 18.04.2025 14:28:33
HDF5 through 1.14.3 contains a stack buffer overflow in H5FL_arr_malloc, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
CVE-2020-18494
- EPSS 0.89%
- Veröffentlicht 22.08.2023 19:15:55
- Zuletzt bearbeitet 21.11.2024 05:08:38
Buffer Overflow vulnerability in function H5S_close in H5S.c in HDF5 1.10.4 allows remote attackers to run arbitrary code via creation of crafted file.
CVE-2020-18232
- EPSS 1.25%
- Veröffentlicht 22.08.2023 19:15:54
- Zuletzt bearbeitet 21.11.2024 05:08:30
Buffer Overflow vulnerability in function H5S_close in H5S.c in HDF5 1.10.4 allows remote attackers to run arbitrary code via creation of crafted file.
CVE-2021-37501
- EPSS 0.09%
- Veröffentlicht 03.02.2023 18:15:13
- Zuletzt bearbeitet 26.03.2025 19:15:16
Buffer Overflow vulnerability in HDFGroup hdf5-h5dump 1.12.0 through 1.13.0 allows attackers to cause a denial of service via h5tools_str_sprint in /hdf5/tools/lib/h5tools_str.c.
CVE-2022-25942
- EPSS 0.1%
- Veröffentlicht 22.08.2022 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:53:15
An out-of-bounds read vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
CVE-2022-25972
- EPSS 0.08%
- Veröffentlicht 22.08.2022 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:53:16
An out-of-bounds write vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
CVE-2022-26061
- EPSS 0.11%
- Veröffentlicht 22.08.2022 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:53:21
A heap-based buffer overflow vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
CVE-2021-46242
- EPSS 0.29%
- Veröffentlicht 21.01.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 06:33:48
HDF5 v1.13.1-1 was discovered to contain a heap-use-after free via the component H5AC_unpin_entry.