VYPR
Vendor

ClamAV

ClamAV is a free software, cross-platform antimalware toolkit able to detect many types of malware, including viruses. It was developed for Unix and has third party versions available for AIX, BSD, HP-UX, Linux, macOS, OpenVMS, OSF (Tru64), Solaris and Haiku. As of version 0.97.5, ClamAV builds and runs on Microsoft Windows. Both ClamAV and its updates are made available free of charge. One of its main uses is on mail servers as a server-side email virus scanner.

Founded 2001
Products
9
CVEs
176
Across products
205
Status
Private

Products

9

Recent CVEs

176
View all 176 CVEs →
  • CVE-2023-20032CriMar 1, 2023
    risk 0.66cvss 9.8epss 0.29

    On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to…

  • CVE-2017-12379CriJan 26, 2018
    risk 0.65cvss 9.8epss 0.13

    ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or potentially execute arbitrary code on an affected device. The vulnerability is due to improper input…

  • CVE-2017-12377CriJan 26, 2018
    risk 0.65cvss 9.8epss 0.12

    ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or potentially execute arbitrary code on an affected device. The vulnerability is due to improper input…

  • CVE-2025-20260CriJun 18, 2025
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in the PDF scanning processes of ClamAV could allow an unauthenticated, remote attacker to cause a buffer overflow condition, cause a denial of service (DoS) condition, or execute arbitrary code on an affected device. This vulnerability exists because memory…

  • CVE-2007-6745CriNov 7, 2019
    risk 0.64cvss 9.8epss 0.02

    clamav 0.91.2 suffers from a floating point exception when using ScanOLE2.

  • CVE-2007-0899CriNov 6, 2019
    risk 0.64cvss 9.8epss 0.02

    There is a possible heap overflow in libclamav/fsg.c before 0.100.0.

  • CVE-2013-7088CriNov 15, 2019
    risk 0.57cvss 9.8epss 0.03

    ClamAV before 0.97.7 has buffer overflow in the libclamav component

  • CVE-2013-7087CriNov 15, 2019
    risk 0.57cvss 9.8epss 0.03

    ClamAV before 0.97.7 has WWPack corrupt heap memory

  • CVE-2022-20803HigFeb 17, 2023
    risk 0.56cvss 8.6epss 0.01

    A vulnerability in the OLE2 file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device.The vulnerability is due to incorrect use of the realloc function that…

  • CVE-2022-20770HigMay 4, 2022
    risk 0.56cvss 8.6epss 0.07

    On April 20, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in CHM file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior…

  • CVE-2024-20290HigFeb 7, 2024
    risk 0.51cvss 7.5epss 0.34

    A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for end-of-string values during scanning, which may…

  • CVE-2022-20792HigAug 10, 2022
    risk 0.51cvss 7.8epss 0.01

    A vulnerability in the regex module used by the signature database load module of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior versions could allow an authenticated, local attacker to crash ClamAV at database load time, and possibly…

  • CVE-2020-26893HigOct 16, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in ClamXAV 3 before 3.1.1. A malicious actor could use a properly signed copy of ClamXAV 2 (running with an injected malicious dylib) to communicate with ClamXAV 3's helper tool and perform privileged operations. This occurs because of inadequate client…

  • CVE-2019-1785HigApr 8, 2019
    risk 0.51cvss 7.8epss 0.02

    A vulnerability in the RAR file scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and 0.101.0 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a lack of proper…

  • CVE-2017-12376HigJan 26, 2018
    risk 0.51cvss 7.8epss 0.07

    ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or potentially execute arbitrary code on an affected device. The vulnerability is due to improper input…

  • CVE-2026-20348HigAug 7, 2026
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary…

  • CVE-2026-20347HigAug 7, 2026
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary…

  • CVE-2026-20346HigAug 7, 2026
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary…

  • CVE-2026-20345HigAug 7, 2026
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper handling of…

  • CVE-2026-20337HigAug 7, 2026
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files during scanning, which may result in an…