← Vulnerability feed

Vulnerability record · CVE-2024-33874 · published 14 May 2024

CVE-2024-33874: Hdfgroup hdf5 classic buffer overflow vulnerability

Hdfgroup · Hdf5

HDF5 Library through 1.14.3 has a heap buffer overflow in H5O__mtime_new_encode in H5Omtime.c.

9.8 CVSS 3.1 Critical EPSS 0.93% · top 41.1% CWE-120 · Classic buffer overflow
9.8CVSS 3.1 base score
0.93%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

HDF5 Library through 1.14.3 has a heap buffer overflow in H5O__mtime_new_encode in H5Omtime.c.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-33874 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-32608Hdfgroup hdf5 out-of-bounds write vulnerabilityHDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the corruption of the instruction pointer and causing denial of service …EPSS 0.67%9.8CVE-2024-32621Hdfgroup hdf5 heap-based buffer overflow vulnerabilityHDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5HG_read in H5HG.c (called from H5VL__native_blob_get in H5VLnative_blob.c), re…EPSS 0.93%9.8CVE-2024-32611Hdfgroup hdf5 use of uninitialized resource vulnerabilityHDF5 Library through 1.14.3 may use an uninitialized value in H5A__attr_release_table in H5Aint.c.EPSS 0.95%9.8CVE-2024-32615Hdfgroup hdf5 out-of-bounds write vulnerabilityHDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5Z__nbit_decompress_one_byte in H5Znbit.c, caused by the earlier use of an init…EPSS 1.1%9.8CVE-2024-29164Hdfgroup hdf5 stack-based buffer overflow vulnerabilityHDF5 through 1.14.3 contains a stack buffer overflow in H5R__decode_heap, resulting in the corruption of the instruction pointer and causing denial o…EPSS 0.86%9.8CVE-2024-29159Hdfgroup hdf5 classic buffer overflow vulnerabilityHDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_scaleoffset, resulting in the corruption of the instruction pointer and causing denial …EPSS 0.92%9.8CVE-2024-29157Hdfgroup hdf5 heap-based buffer overflow vulnerabilityHDF5 through 1.14.3 contains a heap buffer overflow in H5HG_read, resulting in the corruption of the instruction pointer and causing denial of servic…EPSS 0.90%9.8CVE-2018-13866Hdfgroup hdf5 out-of-bounds read vulnerabilityAn issue was discovered in the HDF HDF5 1.8.20 library. There is a stack-based buffer over-read in the function H5F_addr_decode_len in H5Fint.c.EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2024-33874), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.