VYPR

Clamav

by ClamAV

Source repositories

CVEs (174)

  • CVE-2015-1462Feb 3, 2015
    risk 0.00cvss —epss 0.03

    ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted upx packer file, related to a "heap out of bounds condition."

  • CVE-2015-1461Feb 3, 2015
    risk 0.00cvss —epss 0.03

    ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted (1) Yoda's crypter or (2) mew packer file, related to a "heap out of bounds condition."

  • CVE-2014-9328Feb 3, 2015
    risk 0.00cvss —epss 0.03

    ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted upack packer file, related to a "heap out of bounds condition."

  • CVE-2014-9050Dec 1, 2014
    risk 0.00cvss —epss 0.05

    Heap-based buffer overflow in the cli_scanpe function in libclamav/pe.c in ClamAV before 0.98.5 allows remote attackers to cause a denial of service (crash) via a crafted y0da Crypter PE file.

  • CVE-2013-6497Dec 1, 2014
    risk 0.00cvss —epss 0.01

    clamscan in ClamAV before 0.98.5, when using -a option, allows remote attackers to cause a denial of service (crash) as demonstrated by the jwplayer.js file.

  • CVE-2013-2021May 13, 2013
    risk 0.00cvss —epss 0.04

    pdf.c in ClamAV 0.97.1 through 0.97.7 allows remote attackers to cause a denial of service (out-of-bounds-read) via a crafted length value in an encrypted PDF file.

  • CVE-2013-2020May 13, 2013
    risk 0.00cvss —epss 0.04

    Integer underflow in the cli_scanpe function in pe.c in ClamAV before 0.97.8 allows remote attackers to cause a denial of service (crash) via a skewed offset larger than the size of the PE section in a UPX packed executable, which triggers an out-of-bounds read.

  • CVE-2011-3627Nov 17, 2011
    risk 0.00cvss —epss 0.03

    The bytecode engine in ClamAV before 0.97.3 allows remote attackers to cause a denial of service (crash) via vectors related to "recursion level" and (1) libclamav/bytecode.c and (2) libclamav/bytecode_api.c.

  • CVE-2011-2721Aug 5, 2011
    risk 0.00cvss —epss 0.03

    Off-by-one error in the cli_hm_scan function in matcher-hash.c in libclamav in ClamAV before 0.97.2 allows remote attackers to cause a denial of service (daemon crash) via an e-mail message that is not properly handled during certain hash calculations.

  • CVE-2011-1003Feb 23, 2011
    risk 0.00cvss —epss 0.04

    Double free vulnerability in the vba_read_project_strings function in vba_extract.c in libclamav in ClamAV before 0.97 might allow remote attackers to execute arbitrary code via crafted Visual Basic for Applications (VBA) data in a Microsoft Office document. NOTE: some of these…

  • CVE-2010-4479Dec 7, 2010
    risk 0.00cvss —epss 0.05

    Unspecified vulnerability in pdf.c in libclamav in ClamAV before 0.96.5 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document, aka "bb #2380," a different vulnerability than CVE-2010-4260.

  • CVE-2010-4261Dec 7, 2010
    risk 0.00cvss —epss 0.05

    Off-by-one error in the icon_cb function in pe_icons.c in libclamav in ClamAV before 0.96.5 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors. NOTE: some of these details are…

  • CVE-2010-4260Dec 7, 2010
    risk 0.00cvss —epss 0.05

    Multiple unspecified vulnerabilities in pdf.c in libclamav in ClamAV before 0.96.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document, aka (1) "bb #2358" and (2) "bb #2396."

  • CVE-2010-1640May 26, 2010
    risk 0.00cvss —epss 0.03

    Off-by-one error in the parseicon function in libclamav/pe_icons.c in ClamAV 0.96 allows remote attackers to cause a denial of service (crash) via a crafted PE icon that triggers an out-of-bounds read, related to improper rounding during scaling.

  • CVE-2010-1639May 26, 2010
    risk 0.00cvss —epss 0.03

    The cli_pdf function in libclamav/pdf.c in ClamAV before 0.96.1 allows remote attackers to cause a denial of service (crash) via a malformed PDF file, related to an inconsistency in the calculated stream length and the real stream length.

  • CVE-2010-1311Apr 8, 2010
    risk 0.00cvss —epss 0.03

    The qtm_decompress function in libclamav/mspack.c in ClamAV before 0.96 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted CAB archive that uses the Quantum (aka .Q) compression format. NOTE: some of these details are…

  • CVE-2010-0098Apr 8, 2010
    risk 0.00cvss —epss 0.05

    ClamAV before 0.96 does not properly handle the (1) CAB and (2) 7z file formats, which allows remote attackers to bypass virus detection via a crafted archive that is compatible with standard archive utilities.

  • CVE-2008-6845Jul 2, 2009
    risk 0.00cvss —epss 0.02

    The unpack feature in ClamAV 0.93.3 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a corrupted LZH file.

  • CVE-2009-1371Apr 23, 2009
    risk 0.00cvss —epss 0.03

    The CLI_ISCONTAINED macro in libclamav/others.h in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) via a malformed file with UPack encoding.

  • CVE-2009-1270Apr 8, 2009
    risk 0.00cvss —epss 0.05

    libclamav/untar.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (infinite loop) via a crafted TAR file that causes (1) clamd and (2) clamscan to hang.

Page 6 of 9