Skip to main content

Vendor archive

clam_anti-virus CVEs

Beta · best-effort

61 CVEs tagged to vendor clam_anti-virus6 Critical, 18 High, 32 Medium, 5 Low, 0 Unrated.

CVE-2008-5314

Published Dec 3, 2008

Stack consumption vulnerability in libclamav/special.c in ClamAV before 0.94.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted JPEG file, related…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5050

Published Nov 13, 2008

Off-by-one error in the get_unicode_name function (libclamav/vba_extract.c) in Clam Anti-Virus (ClamAV) before 0.94.1 allows remote attackers to cause a denial of service (crash)…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-1389

Published Sep 4, 2008

libclamav/chmunpack.c in the chm-parser in ClamAV before 0.94 allows remote attackers to cause a denial of service (application crash) via a malformed CHM file, related to an "inv…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3215

Published Jul 18, 2008

libclamav/petite.c in ClamAV before 0.93.3 allows remote attackers to cause a denial of service via a malformed Petite file that triggers an out-of-bounds memory access. NOTE: th…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2713

Published Jun 16, 2008

libclamav/petite.c in ClamAV before 0.93.1 allows remote attackers to cause a denial of service via a crafted Petite file that triggers an out-of-bounds read.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1387

Published Apr 16, 2008

ClamAV before 0.93 allows remote attackers to cause a denial of service (CPU consumption) via a crafted ARJ archive, as demonstrated by the PROTOS GENOME test suite for Archive Fo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1835

Published Apr 16, 2008

ClamAV before 0.93 allows remote attackers to bypass the scanning enging via a RAR file with an invalid version number, which cannot be parsed by ClamAV but can be extracted by Wi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1836

Published Apr 16, 2008

The rfc2231 function in message.c in libclamav in ClamAV before 0.93 allows remote attackers to cause a denial of service (crash) via a crafted message that produces a string that…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1837

Published Apr 16, 2008

libclamunrar in ClamAV before 0.93 allows remote attackers to cause a denial of service (crash) via crafted RAR files that trigger "memory problems," as demonstrated by the PROTOS…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0314

Published Apr 16, 2008

Heap-based buffer overflow in spin.c in libclamav in ClamAV 0.92.1 allows remote attackers to execute arbitrary code via a crafted PeSpin packed PE binary with a modified length v…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-1833

Published Apr 16, 2008

Heap-based buffer overflow in pe.c in libclamav in ClamAV 0.92.1 allows remote attackers to execute arbitrary code via a crafted WWPack compressed PE binary.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-1100

Published Apr 14, 2008

Buffer overflow in the cli_scanpe function in libclamav (libclamav/pe.c) for ClamAV 0.92 and 0.92.1 allows remote attackers to execute arbitrary code via a crafted Upack PE file.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-0318

Published Feb 12, 2008

Integer overflow in the cli_scanpe function in libclamav in ClamAV before 0.92.1, as used in clamd, allows remote attackers to cause a denial of service and possibly execute arbit…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6337

Published Dec 31, 2007

Unspecified vulnerability in the bzip2 decompression algorithm in nsis/bzlib_private.h in ClamAV before 0.92 has unknown impact and remote attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6595

Published Dec 31, 2007

ClamAV 0.92 allows local users to overwrite arbitrary files via a symlink attack on (1) temporary files used by the cli_gentempfd function in libclamav/others.c or on (2) .ascii f…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-6596

Published Dec 31, 2007

ClamAV 0.92 does not recognize Base64 UUEncoded archives, which allows remote attackers to bypass the scanner via a Base64-UUEncoded file.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6335

Published Dec 20, 2007

Integer overflow in libclamav in ClamAV before 0.92 allows remote attackers to execute arbitrary code via a crafted MEW packed PE file, which triggers a heap-based buffer overflow.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6336

Published Dec 20, 2007

Off-by-one error in ClamAV before 0.92 allows remote attackers to execute arbitrary code via a crafted MS-ZIP compressed CAB file.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6029

Published Nov 20, 2007

Unspecified vulnerability in ClamAV 0.91.1 and 0.91.2 allows remote attackers to execute arbitrary code via a crafted e-mail message. NOTE: this information is based upon a vague…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-4560

Published Aug 28, 2007

clamav-milter in ClamAV before 0.91.2, when run in black hole mode, allows remote attackers to execute arbitrary commands via shell metacharacters that are used in a certain popen…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2007-4510

Published Aug 23, 2007

ClamAV before 0.91.2, as used in Kolab Server 2.0 through 2.2beta1 and other products, allows remote attackers to cause a denial of service (application crash) via (1) a crafted R…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3725

Published Jul 12, 2007

The RAR VM (unrarvm.c) in Clam Antivirus (ClamAV) before 0.91 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted RAR archive, resulting in a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3024

Published Jun 7, 2007

libclamav/others.c in ClamAV before 0.90.3 and 0.91 before 0.91rc1 uses insecure permissions for temporary files that are created by the cli_gentempstream function in clamd/clamds…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-3025

Published Jun 7, 2007

Unspecified vulnerability in libclamav/phishcheck.c in ClamAV before 0.90.3 and 0.91 before 0.91rc1, when running on Solaris, allows remote attackers to cause a denial of service…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3023

Published Jun 7, 2007

unsp.c in ClamAV before 0.90.3 and 0.91 before 0.91rc1 does not properly calculate the end of a certain buffer, with unknown impact and remote attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 61 CVEsPage 1 of 3