Search CVE reports


Toggle filters

121 – 130 of 130 results


CVE-2018-11202

Medium priority
Needs evaluation

A NULL pointer dereference was discovered in H5S_hyper_make_spans in H5Shyper.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.

1 affected package

hdf5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
hdf5 Not affected Not affected Not affected Needs evaluation
Show less packages

CVE-2017-17509

Medium priority
Vulnerable

In HDF5 1.10.1, there is an out of bounds write vulnerability in the function H5G__ent_decode_vec in H5Gcache.c in libhdf5.a. For example, h5dump would crash or possibly have unspecified other impact someone opens a crafted hdf5 file.

1 affected package

hdf5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
hdf5 Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2017-17508

Medium priority

Some fixes available 3 of 6

In HDF5 1.10.1, there is a divide-by-zero vulnerability in the function H5T_set_loc in the H5T.c file in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file.

1 affected package

hdf5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
hdf5 Not affected Not affected Fixed
Show less packages

CVE-2017-17507

Medium priority
Vulnerable

In HDF5 1.10.1, there is an out of bounds read vulnerability in the function H5T_conv_struct_opt in H5Tconv.c in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file.

1 affected package

hdf5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
hdf5 Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2017-17506

Medium priority

Some fixes available 3 of 6

In HDF5 1.10.1, there is an out of bounds read vulnerability in the function H5Opline_pline_decode in H5Opline.c in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file.

1 affected package

hdf5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
hdf5 Not affected Not affected Fixed
Show less packages

CVE-2017-17505

Medium priority

Some fixes available 3 of 6

In HDF5 1.10.1, there is a NULL pointer dereference in the function H5O_pline_decode in the H5Opline.c file in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file.

1 affected package

hdf5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
hdf5 Not affected Not affected Fixed
Show less packages

CVE-2016-4333

Low priority

Some fixes available 2 of 6

The HDF5 1.8.16 library allocating space for the array using a value from the file has an impact within the loop for initializing said array allowing a value within the file to modify the loop's terminator. Due to this,...

1 affected package

hdf5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
hdf5 Not affected
Show less packages

CVE-2016-4332

Medium priority

Some fixes available 2 of 6

The library's failure to check if certain message types support a particular flag, the HDF5 1.8.16 library will cast the structure to an alternative structure and then assign to fields that aren't supported by the message type and...

1 affected package

hdf5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
hdf5 Not affected
Show less packages

CVE-2016-4331

Medium priority

Some fixes available 2 of 6

When decoding data out of a dataset encoded with the H5Z_NBIT decoding, the HDF5 1.8.16 library will fail to ensure that the precision is within the bounds of the size leading to arbitrary code execution.

1 affected package

hdf5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
hdf5 Not affected
Show less packages

CVE-2016-4330

Medium priority

Some fixes available 2 of 6

In the HDF5 1.8.16 library's failure to check if the number of dimensions for an array read from the file is within the bounds of the space allocated for it, a heap-based buffer overflow will occur, potentially leading...

1 affected package

hdf5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
hdf5 Not affected
Show less packages