ZeroHour

CVE-2016-4331

PoC
CVSS 3.0
8.6 high
EPSS
<1%p53
Published
()
Modified
Description

When decoding data out of a dataset encoded with the H5Z_NBIT decoding, the HDF5 1.8.16 library will fail to ensure that the precision is within the bounds of the size leading to arbitrary code execution.

Vendors
hdfgroup
Products
hdf5
Weakness
CWE-787
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news