CVE-2016-4330
Estado: ModificadaAlta (8.6)—
In the HDF5 1.8.16 library's failure to check if the number of dimensions for an array read from the file is within the bounds of the space allocated for it, a heap-based buffer overflow will occur, potentially leading to arbitrary code execution.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- Puntuación base: 8.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.80%
- Percentil entre todas las CVEs puntuadas: 55
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-119
Referencias
- http://www.debian.org/security/2016/dsa-3727
- http://www.securityfocus.com/bid/94414
- http://www.talosintelligence.com/reports/TALOS-2016-0176/
- https://security.gentoo.org/glsa/201701-13
- http://www.debian.org/security/2016/dsa-3727
- http://www.securityfocus.com/bid/94414
- http://www.talosintelligence.com/reports/TALOS-2016-0176/
- https://security.gentoo.org/glsa/201701-13
JSON original (NVD)
Mostrar
{
"id": "CVE-2016-4330",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.9,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:M/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.4,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.0",
"baseScore": 8.6,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "cret@cert.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2016-11-18T20:59:00.317",
"references": [
{
"url": "http://www.debian.org/security/2016/dsa-3727",
"source": "cret@cert.org"
},
{
"url": "http://www.securityfocus.com/bid/94414",
"source": "cret@cert.org"
},
{
"url": "http://www.talosintelligence.com/reports/TALOS-2016-0176/",
"tags": [
"Exploit",
"Technical Description",
"Third Party Advisory"
],
"source": "cret@cert.org"
},
{
"url": "https://security.gentoo.org/glsa/201701-13",
"source": "cret@cert.org"
},
{
"url": "http://www.debian.org/security/2016/dsa-3727",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/94414",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.talosintelligence.com/reports/TALOS-2016-0176/",
"tags": [
"Exploit",
"Technical Description",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://security.gentoo.org/glsa/201701-13",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-119"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the HDF5 1.8.16 library's failure to check if the number of dimensions for an array read from the file is within the bounds of the space allocated for it, a heap-based buffer overflow will occur, potentially leading to arbitrary code execution."
},
{
"lang": "es",
"value": "En el fallo de la librería HDF5 1.8.16 para comprobar el número de dimensiones de una matriz leída del archivo está dentro de los límites de espacio asignado para ello, se producirá un desbordamiento de búfer basado en memoria dinámica, lo que podría conducir a la ejecución de código arbitrario."
}
],
"lastModified": "2026-06-17T00:47:21.587",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hdfgroup:hdf5:1.8.16:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "917A1D77-B6E2-48F6-B9FF-04A1D1646529"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cret@cert.org"
}