Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2554▼ 405 respecto a la semana anterior
Críticas / altas1317▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
144 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.6) | 0.23% | — | Hdfgroup Hdf5AI | 16/9/2026 | 18/9/2026 | A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H5Tconv.c in HDF5 before 1.14.2. When converting a compound datatype containing floating-point members during a dataset read, a temporary buffer allocated with calloc() is freed and subsequently read from within the same conversion routine. An… | |
| Pendiente de análisis | Media (6.8) | 0.18% | — | Hdfgroup Hdf5AI | 6/8/2026 | 31/8/2026 | H5Z__filter_fletcher32 in H5Zfletcher32.c in HDF5 through 2.3.0 computes the data length to checksum by subtracting the 4-byte trailing checksum size from the input buffer size without checking that the buffer is at least 4 bytes, allowing a size_t underflow. This allows attackers to cause a denial of service… | |
| Pendiente de análisis | Media (6.9) | 0.18% | — | Hdfgroup Hdf5AI | 6/8/2026 | 31/8/2026 | The H5Z__nbit_decompress_one_byte, H5Z__nbit_decompress_one_nooptype, and H5Z__nbit_decompress_one_atomic functions in H5Znbit.c in HDF5 through 2.3.0 advance a read index into the compressed chunk buffer without bounding it against the buffer's actual size. This allows attackers to cause an out-of-bounds heap read,… | |
| Pendiente de análisis | Media (6.8) | 0.18% | — | Hdfgroup Hdf5AI | 5/8/2026 | 31/8/2026 | H5Z__filter_nbit in H5Znbit.c in HDF5 through 2.3.0 dereferences cd_values[0] through cd_values[4] without validating that cd_values is non-NULL or that cd_nelmts is at least 5, the fixed size of the filter's header. This allows attackers to cause a denial of service via a crafted HDF5 file that stores the N-Bit… | |
| Pendiente de análisis | Media (6.8) | 0.17% | — | Hdfgroup Hdf5AI | 5/8/2026 | 31/8/2026 | H5O__layout_decode in H5Olayout.c in HDF5 through 2.3.0 does not validate that a chunked dataset's stored chunk-layout dimensionality matches its dataspace rank when an existing dataset is opened, whereas this check is performed only at dataset-creation time. This allows attackers to cause a denial of service… | |
| Pendiente de análisis | Alta (8.2) | 0.17% | — | Hdfgroup Hdf5AI | 5/8/2026 | 31/8/2026 | NULL pointer dereference in H5Pget_fill_value in HDF5 before 2.3.0 allows attackers to cause a denial of service via a dataset whose version 1 or 2 fill value message has the "defined" flag set together with a negative size field, which is not normalized to the library's "undefined" sentinel and reaches H5T_path_find… | |
| Pendiente de análisis | Media (6.8) | 0.17% | — | Hdfgroup Hdf5AI | 5/8/2026 | 31/8/2026 | Untrusted pointer dereference in the render_bin_output function in the h5dump tool in HDF5 before 2.3.0 allows attackers to cause a denial of service via a variable-length string dataset with more than one element dumped in binary mode, which corrupts the per-element stride calculation and causes subsequent elements… | |
| Analizada | Media (5.2) | 0.15% | — | Hdfgroup Hdf5 | 27/7/2026 | 18/8/2026 | HDF5 contains a NULL pointer dereference vulnerability. Processing a crafted HDF5 file containing an attribute with an invalid variable-length datatype type field may cause the application to crash when the attribute is read. | |
| Analizada | Media (4) | 0.15% | — | Hdfgroup Hdf5 | 27/7/2026 | 18/8/2026 | A double free vulnerability was discovered in the HDF5 library. Processing a crafted HDF5 file containing an oversized chunk size field via h5repack may cause the application to abort due to a double free. | |
| Analizada | Media (5.5) | 0.14% | — | Hdfgroup Hdf5 | 27/7/2026 | 18/8/2026 | Heap-based buffer overflow in the SOHM list-index deserialization code in HDF5 through 2.1.1 on all platforms allows attackers to cause a denial of service (crash) via a crafted HDF5 file whose shared-message list index declares a num_messages count exceeding list_max, triggering out-of-bounds heap reads and writes in… | |
| Analizada | Media (5.9) | 0.35% | — | Hdfgroup Hdf5 | 20/7/2026 | 29/7/2026 | HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If `H5Iget_name` is invoked on a group id with `0` for the size parameter, it will underflow when trying to place a null terminator in the buffer. This can occur if `H5Iget_name` is invoked in a way where `size` can… | |
| Analizada | Media (5.9) | 0.37% | — | Hdfgroup Hdf5 | 20/7/2026 | 29/7/2026 | HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If a file is corrupted such that an array datatype's size, the number of elements, and the element size are not in agreement it can trigger an out of bounds read. The array datatype stores the full size of the… | |
| Analizada | Media (5.5) | 0.20% | — | Hdfgroup Hdf5 | 10/4/2026 | 17/6/2026 | HDF5 is software for managing data. In 1.14.1-2 and earlier, an attacker who can control an h5 file parsed by HDF5 can trigger a write-based heap buffer overflow condition in the H5T__ref_mem_setnull method. This can lead to a denial-of-service condition, and potentially further issues such as remote code execution… | |
| Modificada | Alta (7.8) | 0.19% | — | Hdfgroup Hdf5 | 9/4/2026 | 15/7/2026 | HDF5 is software for managing data. In 1.14.1-2 and earlier, a heap-use-after-free was found in the h5dump helper utility. An attacker who can supply a malicious h5 file can trigger a heap use-after-free. The freed object is referenced in a memmove call from H5T__conv_struct. The original object was allocated by… | |
| Aplazada | Alta (7.8) | 0.26% | — | Google TensorflowAIHdfgroup Hdf5AI | 20/2/2026 | 15/7/2026 | TensorFlow HDF5 Library Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of TensorFlow. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit… | |
| Modificada | Alta (7.8) | 0.36% | — | Hdfgroup Hdf5 | 19/2/2026 | 15/7/2026 | HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` file parsed by HDF5 can trigger a write-based heap buffer overflow condition. This can lead to a denial-of-service condition, and potentially further issues such as remote code execution depending on the practical… | |
| Analizada | Baja (1.9) | 0.25% | — | Hdfgroup Hdf5 | 4/7/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5FS__sect_link_size of the file src/H5FSsection.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may… | |
| Analizada | Baja (1.9) | 0.22% | — | Hdfgroup Hdf5 | 4/7/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. This issue affects the function H5FL__malloc of the file src/H5FL.c. The manipulation leads to memory leak. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. | |
| Analizada | Baja (1.9) | 0.25% | — | Hdfgroup Hdf5 | 4/7/2025 | 17/6/2026 | A vulnerability classified as problematic was found in HDF5 1.14.6. This vulnerability affects the function H5FS__sinfo_serialize_node_cb of the file src/H5FScache.c. The manipulation leads to heap-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and… | |
| Analizada | Baja (1.9) | 0.24% | — | Hdfgroup Hdf5 | 29/6/2025 | 17/6/2026 | A vulnerability was found in HDF5 1.14.6 and classified as problematic. Affected by this issue is the function H5C__flush_single_entry of the file src/H5Centry.c. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. | |
| Analizada | Baja (1.9) | 0.28% | — | Hdfgroup Hdf5 | 29/6/2025 | 17/6/2026 | A vulnerability has been found in HDF5 1.14.6 and classified as problematic. Affected by this vulnerability is the function H5G__node_cmp3 of the file src/H5Gnode.c. The manipulation leads to stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the… | |
| Analizada | Baja (1.9) | 0.25% | — | Hdfgroup Hdf5 | 29/6/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5FL__reg_gc_list of the file src/H5FL.c. The manipulation leads to use after free. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. | |
| Analizada | Baja (1.9) | 0.30% | — | Hdfgroup Hdf5 | 28/6/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5O__chunk_protect of the file /src/H5Ochunk.c. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. | |
| Analizada | Baja (1.9) | 0.23% | — | Hdfgroup Hdf5 | 28/6/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. This issue affects the function H5C__load_entry of the file /src/H5Centry.c. The manipulation leads to resource consumption. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. | |
| Analizada | Baja (1.9) | 0.25% | — | Hdfgroup Hdf5 | 28/6/2025 | 17/6/2026 | A vulnerability classified as problematic was found in HDF5 1.14.6. This vulnerability affects the function H5O__fsinfo_encode of the file /src/H5Ofsinfo.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may… |