CVE-2024-29158
- EPSS 0.22%
- Veröffentlicht 14.05.2024 15:15:31
- Zuletzt bearbeitet 18.04.2025 14:28:33
HDF5 through 1.14.3 contains a stack buffer overflow in H5FL_arr_malloc, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
CVE-2020-18494
- EPSS 0.83%
- Veröffentlicht 22.08.2023 19:15:55
- Zuletzt bearbeitet 21.11.2024 05:08:38
Buffer Overflow vulnerability in function H5S_close in H5S.c in HDF5 1.10.4 allows remote attackers to run arbitrary code via creation of crafted file.
CVE-2020-18232
- EPSS 0.88%
- Veröffentlicht 22.08.2023 19:15:54
- Zuletzt bearbeitet 21.11.2024 05:08:30
Buffer Overflow vulnerability in function H5S_close in H5S.c in HDF5 1.10.4 allows remote attackers to run arbitrary code via creation of crafted file.
CVE-2021-37501
- EPSS 1.55%
- Veröffentlicht 03.02.2023 18:15:13
- Zuletzt bearbeitet 26.03.2025 19:15:16
Buffer Overflow vulnerability in HDFGroup hdf5-h5dump 1.12.0 through 1.13.0 allows attackers to cause a denial of service via h5tools_str_sprint in /hdf5/tools/lib/h5tools_str.c.
CVE-2022-25942
- EPSS 0.61%
- Veröffentlicht 22.08.2022 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:53:15
An out-of-bounds read vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
CVE-2022-25972
- EPSS 0.62%
- Veröffentlicht 22.08.2022 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:53:16
An out-of-bounds write vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
CVE-2022-26061
- EPSS 0.65%
- Veröffentlicht 22.08.2022 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:53:21
A heap-based buffer overflow vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
CVE-2021-46242
- EPSS 1.16%
- Veröffentlicht 21.01.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 06:33:48
HDF5 v1.13.1-1 was discovered to contain a heap-use-after free via the component H5AC_unpin_entry.
CVE-2021-46243
- EPSS 0.95%
- Veröffentlicht 21.01.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 06:33:48
An untrusted pointer dereference vulnerability exists in HDF5 v1.13.1-1 via the function H5O__dtype_decode_helper () at hdf5/src/H5Odtype.c. This vulnerability can lead to a Denial of Service (DoS).
CVE-2021-46244
- EPSS 0.96%
- Veröffentlicht 21.01.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 06:33:48
A Divide By Zero vulnerability exists in HDF5 v1.13.1-1 vis the function H5T__complete_copy () at /hdf5/src/H5T.c. This vulnerability causes an aritmetic exception, leading to a Denial of Service (DoS).