Количество 26 125
Количество 26 125
CVE-2024-32621
HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5HG_read in H5HG.c (called from H5VL__native_blob_get in H5VLnative_blob.c) resulting in the corruption of the instruction pointer.
CVE-2024-32620
HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5F_addr_decode_len in H5Fint.c resulting in the corruption of the instruction pointer.
CVE-2024-32619
HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T_copy_reopen in H5T.c resulting in the corruption of the instruction pointer.
CVE-2024-32618
HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__get_native_type in H5Tnative.c resulting in the corruption of the instruction pointer.
CVE-2024-32617
HDF5 Library through 1.14.3 contains a heap-based buffer over-read caused by the unsafe use of strdup in H5MM_xstrdup in H5MM.c (called from H5G__ent_to_link in H5Glink.c).
CVE-2024-32616
HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5O__dtype_encode_helper in H5Odtype.c.
CVE-2024-32615
HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5Z__nbit_decompress_one_byte in H5Znbit.c caused by the earlier use of an initialized pointer.
CVE-2024-32614
HDF5 Library through 1.14.3 has a SEGV in H5VM_memcpyvv in H5VM.c.
CVE-2024-32613
HDF5 Library through 1.14.3 contains a heap-based buffer over-read in the function H5HL__fl_deserialize in H5HLcache.c a different vulnerability than CVE-2024-32612.
CVE-2024-32612
HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5HL__fl_deserialize in H5HLcache.c resulting in the corruption of the instruction pointer a different vulnerability than CVE-2024-32613.
CVE-2024-32611
HDF5 Library through 1.14.3 may use an uninitialized value in H5A__attr_release_table in H5Aint.c.
CVE-2024-32610
HDF5 Library through 1.14.3 has a SEGV in H5T_close_real in H5T.c resulting in a corrupted instruction pointer.
CVE-2024-32609
HDF5 Library through 1.14.3 allows stack consumption in the function H5E_printf_stack in H5Eint.c.
CVE-2024-32607
CVE-2024-32605
HDF5 Library through 1.14.3 has a heap-based buffer over-read in H5VM_memcpyvv in H5VM.c (called from H5D__compact_readvv in H5Dcompact.c).
CVE-2024-32487
CVE-2024-32465
CVE-2024-3220
Default mimetype known files writeable on Windows
CVE-2024-3219
CVE-2024-3205
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The maintainer identified an error in the libyaml fuzzers. It is not possible to reproduce nor exploit the issue.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-32621 HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5HG_read in H5HG.c (called from H5VL__native_blob_get in H5VLnative_blob.c) resulting in the corruption of the instruction pointer. | CVSS3: 9.8 | 1% Низкий | 7 дней назад | |
CVE-2024-32620 HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5F_addr_decode_len in H5Fint.c resulting in the corruption of the instruction pointer. | CVSS3: 7.4 | 0% Низкий | 6 месяцев назад | |
CVE-2024-32619 HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T_copy_reopen in H5T.c resulting in the corruption of the instruction pointer. | CVSS3: 7.4 | 0% Низкий | больше 2 лет назад | |
CVE-2024-32618 HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__get_native_type in H5Tnative.c resulting in the corruption of the instruction pointer. | CVSS3: 7.4 | 0% Низкий | больше 2 лет назад | |
CVE-2024-32617 HDF5 Library through 1.14.3 contains a heap-based buffer over-read caused by the unsafe use of strdup in H5MM_xstrdup in H5MM.c (called from H5G__ent_to_link in H5Glink.c). | CVSS3: 8.8 | 1% Низкий | больше 2 лет назад | |
CVE-2024-32616 HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5O__dtype_encode_helper in H5Odtype.c. | CVSS3: 7.4 | 0% Низкий | 6 месяцев назад | |
CVE-2024-32615 HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5Z__nbit_decompress_one_byte in H5Znbit.c caused by the earlier use of an initialized pointer. | CVSS3: 9.8 | 1% Низкий | 6 месяцев назад | |
CVE-2024-32614 HDF5 Library through 1.14.3 has a SEGV in H5VM_memcpyvv in H5VM.c. | CVSS3: 8.8 | 1% Низкий | 6 месяцев назад | |
CVE-2024-32613 HDF5 Library through 1.14.3 contains a heap-based buffer over-read in the function H5HL__fl_deserialize in H5HLcache.c a different vulnerability than CVE-2024-32612. | CVSS3: 7.4 | 0% Низкий | больше 2 лет назад | |
CVE-2024-32612 HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5HL__fl_deserialize in H5HLcache.c resulting in the corruption of the instruction pointer a different vulnerability than CVE-2024-32613. | CVSS3: 7.4 | 0% Низкий | 6 месяцев назад | |
CVE-2024-32611 HDF5 Library through 1.14.3 may use an uninitialized value in H5A__attr_release_table in H5Aint.c. | CVSS3: 9.8 | 1% Низкий | 6 месяцев назад | |
CVE-2024-32610 HDF5 Library through 1.14.3 has a SEGV in H5T_close_real in H5T.c resulting in a corrupted instruction pointer. | CVSS3: 5.7 | 0% Низкий | 7 дней назад | |
CVE-2024-32609 HDF5 Library through 1.14.3 allows stack consumption in the function H5E_printf_stack in H5Eint.c. | CVSS3: 7.5 | 1% Низкий | 6 месяцев назад | |
CVSS3: 5.7 | 0% Низкий | больше 2 лет назад | ||
CVE-2024-32605 HDF5 Library through 1.14.3 has a heap-based buffer over-read in H5VM_memcpyvv in H5VM.c (called from H5D__compact_readvv in H5Dcompact.c). | CVSS3: 8.8 | 1% Низкий | 7 дней назад | |
CVSS3: 8.6 | 1% Низкий | больше 2 лет назад | ||
CVSS3: 7.3 | 1% Низкий | почти 2 года назад | ||
CVE-2024-3220 Default mimetype known files writeable on Windows | 1% Низкий | 7 дней назад | ||
0% Низкий | больше 1 года назад | |||
CVE-2024-3205 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The maintainer identified an error in the libyaml fuzzers. It is not possible to reproduce nor exploit the issue. | 12 дней назад |
Уязвимостей на страницу