VYPR

Clamav

by ClamAV

Source repositories

CVEs (174)

  • CVE-2012-1419Mar 21, 2012
    risk 0.03cvss —epss 0.41

    The TAR file parser in ClamAV 0.96.4 and Quick Heal (aka Cat QuickHeal) 11.00 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial [aliases] character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is…

  • CVE-2005-1800May 28, 2005
    risk 0.03cvss —epss 0.03

    Cross-site scripting (XSS) vulnerability in Jaws Glossary gadget 0.4 to 0.5.1 allows remote attackers to inject arbitrary web script or HTML via the term parameter in a view or ViewTerm action to index.php.

  • CVE-2010-3434Sep 30, 2010
    risk 0.01cvss —epss 0.07

    Buffer overflow in the find_stream_bounds function in pdf.c in libclamav in ClamAV before 0.96.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document. NOTE: some of these details are obtained from…

  • CVE-2009-1372Apr 23, 2009
    risk 0.01cvss —epss 0.08

    Stack-based buffer overflow in the cli_url_canon function in libclamav/phishcheck.c in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted URL.

  • CVE-2008-5050Nov 13, 2008
    risk 0.01cvss —epss 0.08

    Off-by-one error in the get_unicode_name function (libclamav/vba_extract.c) in Clam Anti-Virus (ClamAV) before 0.94.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted VBA project file, which triggers a heap-based…

  • CVE-2008-1833Apr 16, 2008
    risk 0.01cvss —epss 0.09

    Heap-based buffer overflow in pe.c in libclamav in ClamAV 0.92.1 allows remote attackers to execute arbitrary code via a crafted WWPack compressed PE binary.

  • CVE-2008-0314Apr 16, 2008
    risk 0.01cvss —epss 0.09

    Heap-based buffer overflow in spin.c in libclamav in ClamAV 0.92.1 allows remote attackers to execute arbitrary code via a crafted PeSpin packed PE binary with a modified length value.

  • CVE-2008-1100Apr 14, 2008
    risk 0.01cvss —epss 0.11

    Buffer overflow in the cli_scanpe function in libclamav (libclamav/pe.c) for ClamAV 0.92 and 0.92.1 allows remote attackers to execute arbitrary code via a crafted Upack PE file.

  • CVE-2008-0318Feb 12, 2008
    risk 0.01cvss —epss 0.08

    Integer overflow in the cli_scanpe function in libclamav in ClamAV before 0.92.1, as used in clamd, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Petite packed PE file, which triggers a heap-based buffer overflow.

  • CVE-2006-1615Apr 6, 2006
    risk 0.01cvss —epss 0.11

    Multiple format string vulnerabilities in the logging code in Clam AntiVirus (ClamAV) before 0.88.1 might allow remote attackers to execute arbitrary code. NOTE: as of 20060410, it is unclear whether this is a vulnerability, as there is some evidence that the arguments are…

  • CVE-2006-1614Apr 6, 2006
    risk 0.01cvss —epss 0.08

    Integer overflow in the cli_scanpe function in the PE header parser (libclamav/pe.c) in Clam AntiVirus (ClamAV) before 0.88.1, when ArchiveMaxFileSize is disabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code.

  • CVE-2006-0162Jan 10, 2006
    risk 0.01cvss —epss 0.10

    Heap-based buffer overflow in libclamav/upx.c in Clam Antivirus (ClamAV) before 0.88 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted UPX files.

  • CVE-2005-3303Nov 5, 2005
    risk 0.01cvss —epss 0.07

    The FSG unpacker (fsg.c) in Clam AntiVirus (ClamAV) 0.80 through 0.87 allows remote attackers to cause "memory corruption" and execute arbitrary code via a crafted FSG 1.33 file.

  • CVE-2005-2920Sep 20, 2005
    risk 0.01cvss —epss 0.08

    Buffer overflow in libclamav/upx.c in Clam AntiVirus (ClamAV) before 0.87 allows remote attackers to execute arbitrary code via a crafted UPX packed executable.

  • CVE-2018-1000085MedMar 13, 2018
    risk 0.00cvss 5.5epss 0.03

    ClamAV version version 0.99.3 contains a Out of bounds heap memory read vulnerability in XAR parser, function xar_hash_check() that can result in Leaking of memory, may help in developing exploit chains.. This attack appear to be exploitable via The victim must scan a crafted…

  • CVE-2015-2668May 12, 2015
    risk 0.00cvss —epss 0.03

    ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infinite loop) via a crafted xz archive file.

  • CVE-2015-2222May 12, 2015
    risk 0.00cvss —epss 0.03

    ClamAV before 0.98.7 allows remote attackers to cause a denial of service (crash) via a crafted petite packed file.

  • CVE-2015-2221May 12, 2015
    risk 0.00cvss —epss 0.03

    ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infinite loop) via a crafted y0da cryptor file.

  • CVE-2015-2170May 12, 2015
    risk 0.00cvss —epss 0.03

    The upx decoder in ClamAV before 0.98.7 allows remote attackers to cause a denial of service (crash) via a crafted file.

  • CVE-2015-1463Feb 3, 2015
    risk 0.00cvss —epss 0.03

    ClamAV before 0.98.6 allows remote attackers to cause a denial of service (crash) via a crafted petite packer file, related to an "incorrect compiler optimization."

Page 5 of 9