Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Hdfgroup

First CVE: Nov 18, 2016Active for: 10 yearsTotal CVEs: 131
34.9
VTI Score
Medium

The HDF Group maintains HDF5, a widely used scientific data format library and toolkit that, despite a minimal product footprint, sits deep in the data-processing pipelines of research institutions, high-performance computing centers, and enterprise analytics platforms. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes, concentrating in memory-safety and buffer-management weakness classes including heap-based buffer overflows, out-of-bounds writes and reads, and NULL-pointer dereferences that are inherent to the library's C-based parsing and storage engine. The exposure profile reflects HDF5's role as a foundational component in scientific computing: a single flaw in the library can propagate across diverse downstream applications and environments that depend on it for data interchange. Defenders should inventory products that embed or link HDF5, prioritize patch deployment for this library specifically, and treat disclosed vulnerabilities as potentially high-impact across their research and analytics infrastructure. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
131
Total CVEs
More Total CVEs than 99% of tracked vendors
13.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Hdfgroup over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 18, 2016
9 years ago
Most Recent CVE
Apr 10, 2026
105 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (131 CVEs).

131 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-13872CRITICAL
An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer overflow in the function H5G_ent_decode in H5Gent.c.
Jul 10, 20189.831NONO
CVE-2018-13870CRITICAL
An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5O_link_decode in H5Olink.c.
Jul 10, 20189.831NONO
CVE-2018-13869CRITICAL
An issue was discovered in the HDF HDF5 1.8.20 library. There is a memcpy parameter overlap in the function H5O_link_decode in H5Olink.c.
Jul 10, 20189.831NONO
CVE-2018-13868CRITICAL
An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5O_fill_old_decode in H5Ofill.c.
Jul 10, 20189.831NONO
CVE-2018-13874CRITICAL
An issue was discovered in the HDF HDF5 1.8.20 library. There is a stack-based buffer overflow in the function H5FD_sec2_read in H5FDsec2.c, related to HDmemset.
Jul 10, 20189.830NONO
CVE-2018-13873CRITICAL
An issue was discovered in the HDF HDF5 1.8.20 library. There is a buffer over-read in H5O_chunk_deserialize in H5Ocache.c.
Jul 10, 20189.830NONO
CVE-2018-13871CRITICAL
An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer overflow in the function H5FL_blk_malloc in H5FL.c.
Jul 10, 20189.830NONO
CVE-2026-34734HIGH
HDF5 is software for managing data. In 1.14.1-2 and earlier, a heap-use-after-free was found in the h5dump helper utility. An attacker who can supply a malicious h5 file can trigge
Apr 9, 20267.829NONO
CVE-2018-13867CRITICAL
An issue was discovered in the HDF HDF5 1.8.20 library. There is an out of bounds read in the function H5F__accum_read in H5Faccum.c.
Jul 10, 20189.829NONO
CVE-2021-46242HIGH
HDF5 v1.13.1-1 was discovered to contain a heap-use-after free via the component H5AC_unpin_entry.
Jan 21, 20228.828NONO
View all 131 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products131 CVEs
40%
42%
15%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local60 (45.8%)
Network71 (54.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low112 (85.5%)
High19 (14.5%)
Unknown0 (0.0%)
User Interaction
None70 (53.4%)
Unknown0 (0.0%)
Required61 (46.6%)
Privileges Required
Low30 (22.9%)
High0 (0.0%)
None101 (77.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (131 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Hdfgroup.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Hdfgroup — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Hdfgroup's Products

View all 5 CNAs →

Top CWEs