HDF5 through 1.14.3 contains a stack buffer overflow in H5Rdecodeheap resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
HDF5 Library through 1.14.3 may use an uninitialized value in H5Aattrreleasetable in H5Aint.c.
HDF5 Library through 1.14.3 has a heap buffer overflow in H5Omtimenewencode in H5Omtime.c.
An issue was discovered in the HDF HDF5 1.8.20 library. There is a stack-based buffer overflow in the function H5FDsec2read in H5FDsec2.c, related to HDmemset.
An issue was discovered in the HDF HDF5 1.8.20 library. There is a memcpy parameter overlap in the function H5Olinkdecode in H5Olink.c.
HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5Dscattermem in H5Dscatgath.c.
HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5Tconvstructopt in H5Tconv.c.
hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5Zfilterscaleoffset function.
hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5VMmemcpyvv function.
An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5Tcopy in H5T.c.
In HDF5 1.10.1, there is an out of bounds write vulnerability in the function H5Gentdecodevec in H5Gcache.c in libhdf5.a. For example, h5dump would crash or possibly have unspecified other impact someone opens a crafted hdf5 file.
An issue was discovered in the HDF HDF5 1.10.4 library. There is an out of bounds read in the function H5MMxstrdup in H5MM.c when called from H5Odtypedecodehelper in H5Odtype.c.
An out of bounds read was discovered in H5Ofillnewdecode and H5Ofillolddecode in H5Ofill.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service or information disclosure attack.
HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an h5 file parsed by HDF5 can trigger a write-based heap buffer overflow condition. This can lead to a denial-of-service condition, and potentially further issues such as remote code execution depending on the practical exploitability of the heap overflow against modern operating systems. Real-world exploitability of this issue in terms of remote-code execution is currently unknown. Version 1.14.4-2 fixes the issue.
HDF5 is software for managing data. In 1.14.1-2 and earlier, a heap-use-after-free was found in the h5dump helper utility. An attacker who can supply a malicious h5 file can trigger a heap use-after-free. The freed object is referenced in a memmove call from H5Tconvstruct. The original object was allocated by H5Dtypeinfoinitphase3 and freed by H5Dtypeinfoterm.
An out-of-bounds write vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
HDF5 through 1.14.3 contains a heap buffer overflow in H5HGcacheheapdeserialize resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
HDF5 through 1.13.3 and/or 1.14.2 contains a stack buffer overflow in H5HGread resulting in denial of service or potential code execution.
HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5HLfldeserialize in H5HLcache.c resulting in the corruption of the instruction pointer a different vulnerability than CVE-2024-32613.
HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5Odtypeencodehelper in H5Odtype.c.
HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5Tcopyreopen in H5T.c resulting in the corruption of the instruction pointer.
HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5Faddrdecodelen in H5Fint.c resulting in the corruption of the instruction pointer.
HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5Tgetnativetype in H5Tnative.c resulting in the corruption of the instruction pointer.
HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5Trefmemsetnull in H5Tref.c (called from H5Tconvref in H5Tconv.c) resulting in the corruption of the instruction pointer.
A division by zero was discovered in H5Dchunkinit in H5Dchunk.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.
In HDF5 1.10.1, there is a NULL pointer dereference in the function H5Oplinedecode in the H5Opline.c file in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file.
Buffer underflow in H5Igetname /H5Ggetname if size is zero
Array full size, element count, and element size are not checked to make sure they match in H5Odtype.c
HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5Olayoutencode in H5Olayout.c resulting in the corruption of the instruction pointer.
A vulnerability has been found in HDF5 up to 1.14.6 and classified as problematic. This vulnerability affects the function H5MMrealloc of the file src/H5MM.c. The manipulation of the argument mem leads to double free. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.