rpm package
opensuse/clamav&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/clamav&distro=openSUSE%20Tumbleweed
Vulnerabilities (107)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-20348 | Hig | 7.5 | < 1.5.4-1.1 | 1.5.4-1.1 | Aug 7, 2026 | A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary check | |
| CVE-2026-20347 | Hig | 7.5 | < 1.5.4-1.1 | 1.5.4-1.1 | Aug 7, 2026 | A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary ch | |
| CVE-2026-20346 | Hig | 7.5 | < 1.5.4-1.1 | 1.5.4-1.1 | Aug 7, 2026 | A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary check | |
| CVE-2026-20345 | Hig | 7.5 | < 1.5.4-1.1 | 1.5.4-1.1 | Aug 7, 2026 | A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper handling of an | |
| CVE-2026-20339 | Hig | 7.5 | < 1.5.4-1.1 | 1.5.4-1.1 | Aug 7, 2026 | A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary ch | |
| CVE-2026-20338 | Hig | 7.5 | < 1.5.4-1.1 | 1.5.4-1.1 | Aug 7, 2026 | A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exp | |
| CVE-2026-20337 | Hig | 7.5 | < 1.5.4-1.1 | 1.5.4-1.1 | Aug 7, 2026 | A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files during scanning, which may result in an out-of-bou | |
| CVE-2026-46671 | Med | 4.4 | < 1.5.4-1.1 | 1.5.4-1.1 | Jul 20, 2026 | Rust OneNote File Parser is a parser for Microsoft OneNote files implemented in Rust. Prior to version 1.1.1, a maliciously crafted `.onetoc2` table-of-contents file can cause `Parser::parse_notebook` to open arbitrary files on the host filesystem outside the notebook's directory | |
| CVE-2026-20244 | Hig | 7.5 | < 1.5.3-1.1 | 1.5.3-1.1 | Jul 1, 2026 | A vulnerability in the DMG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks f | |
| CVE-2026-20243 | Hig | 7.5 | < 1.5.3-1.1 | 1.5.3-1.1 | Jul 1, 2026 | A vulnerability in the ALZ file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks f | |
| CVE-2026-20217 | Hig | 7.5 | < 1.5.3-1.1 | 1.5.3-1.1 | Jul 1, 2026 | A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary check | |
| CVE-2026-20216 | Hig | 7.5 | < 1.5.3-1.1 | 1.5.3-1.1 | Jul 1, 2026 | A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper handling of temporary resources during file scanning. An attacker could explo | |
| CVE-2026-20215 | Hig | 7.5 | < 1.5.3-1.1 | 1.5.3-1.1 | Jul 1, 2026 | A vulnerability in the 7z file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks fo | |
| CVE-2026-20214 | Hig | 7.5 | < 1.5.3-1.1 | 1.5.3-1.1 | Jul 1, 2026 | A vulnerability in the FSG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks f | |
| CVE-2026-20213 | Hig | 7.5 | < 1.5.3-1.1 | 1.5.3-1.1 | Jul 1, 2026 | A vulnerability in the PE file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks fo | |
| CVE-2026-41676 | Hig | 7.5 | < 1.5.3-1.1 | 1.5.3-1.1 | Apr 24, 2026 | rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.27 to before 0.10.78, Deriver::derive (and PkeyCtxRef::derive) sets len = buf.len() and passes it as the in/out length to EVP_PKEY_derive, relying on OpenSSL to honor it. On OpenSSL 1.1.x, X25519, | |
| CVE-2026-20031 | Med | 5.3 | < 1.5.2-1.1 | 1.5.2-1.1 | Mar 4, 2026 | A vulnerability in the HTML Cascading Style Sheets (CSS) module of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error handling when splitting UTF-8 strings. An a | |
| CVE-2025-8088 | Hig | 8.8 | KEV | < 1.5.4-1.1 | 1.5.4-1.1 | Aug 8, 2025 | A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček fr |
| CVE-2025-20260 | Cri | 9.8 | < 1.4.3-1.1 | 1.4.3-1.1 | Jun 18, 2025 | A vulnerability in the PDF scanning processes of ClamAV could allow an unauthenticated, remote attacker to cause a buffer overflow condition, cause a denial of service (DoS) condition, or execute arbitrary code on an affected device. This vulnerability exists because memory bu | |
| CVE-2025-20234 | Med | 5.3 | < 1.4.3-1.1 | 1.4.3-1.1 | Jun 18, 2025 | A vulnerability in Universal Disk Format (UDF) processing of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a memory overread during UDF file scanning. An attacker could ex |
- affected < 1.5.4-1.1fixed 1.5.4-1.1
A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary check
- affected < 1.5.4-1.1fixed 1.5.4-1.1
A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary ch
- affected < 1.5.4-1.1fixed 1.5.4-1.1
A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary check
- affected < 1.5.4-1.1fixed 1.5.4-1.1
A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper handling of an
- affected < 1.5.4-1.1fixed 1.5.4-1.1
A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary ch
- affected < 1.5.4-1.1fixed 1.5.4-1.1
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exp
- affected < 1.5.4-1.1fixed 1.5.4-1.1
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files during scanning, which may result in an out-of-bou
- affected < 1.5.4-1.1fixed 1.5.4-1.1
Rust OneNote File Parser is a parser for Microsoft OneNote files implemented in Rust. Prior to version 1.1.1, a maliciously crafted `.onetoc2` table-of-contents file can cause `Parser::parse_notebook` to open arbitrary files on the host filesystem outside the notebook's directory
- affected < 1.5.3-1.1fixed 1.5.3-1.1
A vulnerability in the DMG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks f
- affected < 1.5.3-1.1fixed 1.5.3-1.1
A vulnerability in the ALZ file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks f
- affected < 1.5.3-1.1fixed 1.5.3-1.1
A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary check
- affected < 1.5.3-1.1fixed 1.5.3-1.1
A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper handling of temporary resources during file scanning. An attacker could explo
- affected < 1.5.3-1.1fixed 1.5.3-1.1
A vulnerability in the 7z file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks fo
- affected < 1.5.3-1.1fixed 1.5.3-1.1
A vulnerability in the FSG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks f
- affected < 1.5.3-1.1fixed 1.5.3-1.1
A vulnerability in the PE file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks fo
- affected < 1.5.3-1.1fixed 1.5.3-1.1
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.27 to before 0.10.78, Deriver::derive (and PkeyCtxRef::derive) sets len = buf.len() and passes it as the in/out length to EVP_PKEY_derive, relying on OpenSSL to honor it. On OpenSSL 1.1.x, X25519,
- affected < 1.5.2-1.1fixed 1.5.2-1.1
A vulnerability in the HTML Cascading Style Sheets (CSS) module of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error handling when splitting UTF-8 strings. An a
- affected < 1.5.4-1.1fixed 1.5.4-1.1
A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček fr
- affected < 1.4.3-1.1fixed 1.4.3-1.1
A vulnerability in the PDF scanning processes of ClamAV could allow an unauthenticated, remote attacker to cause a buffer overflow condition, cause a denial of service (DoS) condition, or execute arbitrary code on an affected device. This vulnerability exists because memory bu
- affected < 1.4.3-1.1fixed 1.4.3-1.1
A vulnerability in Universal Disk Format (UDF) processing of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a memory overread during UDF file scanning. An attacker could ex
Page 1 of 6