CVE-2026-26199
HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If `H5Iget_name` is invoked on a gro
CVSS
—
No CVSS
EPSS
0.3%
p20
KEV
—
Exploit Today
6
0-100
Published: Jul 20, 2026 · Last modified: Jul 20, 2026 · CWE-124
Not enough EPSS history yet.
HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If `H5Iget_name` is invoked on a group id with `0` for the size parameter, it will underflow when trying to place a null terminator in the buffer. This can occur if `H5Iget_name` is invoked in a way where `size` can be forced to zero, and there is important data before the `name` buffer.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-16439——
——0In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer underflow.8hCVE-2026-342538.2 HIG40.5%
——12A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing malformed input, leading to a stack buffer underflow that can cause application crashes and potentially allow code execution.7dCVE-2025-43734.8 MED37.5%
——11A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function. When the position at which to insert the character is large, the position will overflow, leading to a buffer underwrite.2d