CVE-2016-4330 is a heap-based buffer overflow vulnerability in the HDF5 1.8.16 library, stemming from insufficient bounds checking during array dimension processing, which could lead to arbitrary code execution. This vulnerability has a high CVSS score of 8.6, indicating a critical risk with local access, low attack complexity, and high impacts on confidentiality, integrity, and availability, requiring user interaction. Despite its severity, there is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion, though it did receive media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.8.16CPE matchmatch criteria | cpe:2.3:a:hdfgroup:hdf5:1.8.16:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.