CVE-2016-4332 is a heap buffer overflow vulnerability in the HDF5 1.8.16 library, caused by improper handling of message types and flags, leading to out-of-bounds writes. This flaw affects products utilizing the hdfgroup hdf5 library. It carries a high CVSS score of 8.6, indicating a critical risk due to potential code execution with high impact on confidentiality, integrity, and availability, requiring user interaction. While no active exploits, Metasploit modules, or ExploitDB entries are publicly available, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.8.16CPE matchmatch criteria | cpe:2.3:a:hdfgroup:hdf5:1.8.16:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.