Hdfgroup
Hdfgroup Hdf5: vulnerabilidades y CVE
Hdfgroup Hdf5 tiene 144 vulnerabilidades publicadas, 16 de ellas en los últimos 12 meses. 19 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE144
Últimos 12 meses16
Críticas19
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-92627 | Media (4.6) | 0.23% | — | 16 sept 2026 | A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H5Tconv.c in HDF5 before 1.14.2. When converting a compound datatype containing floating-point members during a dataset read, a temporary buffer… |
| CVE-2026-19028 | Media (6.8) | 0.18% | — | 6 ago 2026 | H5Z__filter_fletcher32 in H5Zfletcher32.c in HDF5 through 2.3.0 computes the data length to checksum by subtracting the 4-byte trailing checksum size from the input buffer size without checking that the buffer is at… |
| CVE-2026-19027 | Media (6.9) | 0.18% | — | 6 ago 2026 | The H5Z__nbit_decompress_one_byte, H5Z__nbit_decompress_one_nooptype, and H5Z__nbit_decompress_one_atomic functions in H5Znbit.c in HDF5 through 2.3.0 advance a read index into the compressed chunk buffer without… |
| CVE-2026-19026 | Media (6.8) | 0.18% | — | 5 ago 2026 | H5Z__filter_nbit in H5Znbit.c in HDF5 through 2.3.0 dereferences cd_values[0] through cd_values[4] without validating that cd_values is non-NULL or that cd_nelmts is at least 5, the fixed size of the filter's header.… |
| CVE-2026-19025 | Media (6.8) | 0.17% | — | 5 ago 2026 | H5O__layout_decode in H5Olayout.c in HDF5 through 2.3.0 does not validate that a chunked dataset's stored chunk-layout dimensionality matches its dataspace rank when an existing dataset is opened, whereas this check is… |
| CVE-2026-19024 | Alta (8.2) | 0.17% | — | 5 ago 2026 | NULL pointer dereference in H5Pget_fill_value in HDF5 before 2.3.0 allows attackers to cause a denial of service via a dataset whose version 1 or 2 fill value message has the "defined" flag set together with a negative… |
| CVE-2026-19023 | Media (6.8) | 0.17% | — | 5 ago 2026 | Untrusted pointer dereference in the render_bin_output function in the h5dump tool in HDF5 before 2.3.0 allows attackers to cause a denial of service via a variable-length string dataset with more than one element… |
| CVE-2026-17574 | Media (5.2) | 0.15% | — | 27 jul 2026 | HDF5 contains a NULL pointer dereference vulnerability. Processing a crafted HDF5 file containing an attribute with an invalid variable-length datatype type field may cause the application to crash when the attribute is… |
| CVE-2026-17573 | Media (4) | 0.15% | — | 27 jul 2026 | A double free vulnerability was discovered in the HDF5 library. Processing a crafted HDF5 file containing an oversized chunk size field via h5repack may cause the application to abort due to a double free. |
| CVE-2026-17572 | Media (5.5) | 0.14% | — | 27 jul 2026 | Heap-based buffer overflow in the SOHM list-index deserialization code in HDF5 through 2.1.1 on all platforms allows attackers to cause a denial of service (crash) via a crafted HDF5 file whose shared-message list index… |
| CVE-2026-26199 | Media (5.9) | 0.35% | — | 20 jul 2026 | HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If `H5Iget_name` is invoked on a group id with `0` for the size parameter, it will underflow when trying to place a… |
| CVE-2026-26197 | Media (5.9) | 0.37% | — | 20 jul 2026 | HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If a file is corrupted such that an array datatype's size, the number of elements, and the element size are not in… |
| CVE-2026-29043 | Media (5.5) | 0.20% | — | 10 abr 2026 | HDF5 is software for managing data. In 1.14.1-2 and earlier, an attacker who can control an h5 file parsed by HDF5 can trigger a write-based heap buffer overflow condition in the H5T__ref_mem_setnull method. This can… |
| CVE-2026-34734 | Alta (7.8) | 0.19% | — | 9 abr 2026 | HDF5 is software for managing data. In 1.14.1-2 and earlier, a heap-use-after-free was found in the h5dump helper utility. An attacker who can supply a malicious h5 file can trigger a heap use-after-free. The freed… |
| CVE-2026-2492 | Alta (7.8) | 0.26% | — | 20 feb 2026 | TensorFlow HDF5 Library Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of TensorFlow. An attacker… |
| CVE-2026-26200 | Alta (7.8) | 0.36% | — | 19 feb 2026 | HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` file parsed by HDF5 can trigger a write-based heap buffer overflow condition. This can lead to a denial-of-service… |
| CVE-2025-7069 | Baja (1.9) | 0.25% | — | 4 jul 2025 | A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5FS__sect_link_size of the file src/H5FSsection.c. The manipulation leads to heap-based buffer overflow. It is… |
| CVE-2025-7068 | Baja (1.9) | 0.22% | — | 4 jul 2025 | A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. This issue affects the function H5FL__malloc of the file src/H5FL.c. The manipulation leads to memory leak. Attacking locally is a… |
| CVE-2025-7067 | Baja (1.9) | 0.25% | — | 4 jul 2025 | A vulnerability classified as problematic was found in HDF5 1.14.6. This vulnerability affects the function H5FS__sinfo_serialize_node_cb of the file src/H5FScache.c. The manipulation leads to heap-based buffer… |
| CVE-2025-6858 | Baja (1.9) | 0.24% | — | 29 jun 2025 | A vulnerability was found in HDF5 1.14.6 and classified as problematic. Affected by this issue is the function H5C__flush_single_entry of the file src/H5Centry.c. The manipulation leads to null pointer dereference. The… |
| CVE-2025-6857 | Baja (1.9) | 0.28% | — | 29 jun 2025 | A vulnerability has been found in HDF5 1.14.6 and classified as problematic. Affected by this vulnerability is the function H5G__node_cmp3 of the file src/H5Gnode.c. The manipulation leads to stack-based buffer… |
| CVE-2025-6856 | Baja (1.9) | 0.25% | — | 29 jun 2025 | A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5FL__reg_gc_list of the file src/H5FL.c. The manipulation leads to use after free. Attacking locally is a… |
| CVE-2025-6818 | Baja (1.9) | 0.30% | — | 28 jun 2025 | A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5O__chunk_protect of the file /src/H5Ochunk.c. The manipulation leads to heap-based buffer overflow. An attack… |
| CVE-2025-6817 | Baja (1.9) | 0.23% | — | 28 jun 2025 | A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. This issue affects the function H5C__load_entry of the file /src/H5Centry.c. The manipulation leads to resource consumption. The… |
| CVE-2025-6816 | Baja (1.9) | 0.25% | — | 28 jun 2025 | A vulnerability classified as problematic was found in HDF5 1.14.6. This vulnerability affects the function H5O__fsinfo_encode of the file /src/H5Ofsinfo.c. The manipulation leads to heap-based buffer overflow. It is… |
| CVE-2025-6750 | Baja (1.9) | 0.25% | — | 27 jun 2025 | A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. Affected by this issue is the function H5O__mtime_new_encode of the file src/H5Omtime.c. The manipulation leads to heap-based buffer… |
| CVE-2025-6516 | Baja (1.9) | 0.38% | — | 23 jun 2025 | A vulnerability has been found in HDF5 up to 1.14.6 and classified as critical. This vulnerability affects the function H5F_addr_decode_len of the file /hdf5/src/H5Fint.c. The manipulation leads to heap-based buffer… |
| CVE-2025-6270 | Baja (1.9) | 0.26% | — | 19 jun 2025 | A vulnerability, which was classified as critical, has been found in HDF5 up to 1.14.6. Affected by this issue is the function H5FS__sect_find_node of the file H5FSsection.c. The manipulation leads to heap-based buffer… |
| CVE-2025-6269 | Baja (1.9) | 0.26% | — | 19 jun 2025 | A vulnerability classified as critical was found in HDF5 up to 1.14.6. Affected by this vulnerability is the function H5C__reconstruct_cache_entry of the file H5Cimage.c. The manipulation leads to heap-based buffer… |
| CVE-2025-44905 | Alta (8.8) | 0.45% | — | 30 may 2025 | hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5Z__filter_scaleoffset function. |