Search: "clamav"

144 CVEs found

CVE-2008-3914
10.0 HIGH

Multiple unspecified vulnerabilities in ClamAV before 0.94 have unknown impact and attack vectors related to file descriptor leaks on the "error path" in (1) libclamav/others.c and (2) libclamav/sis.c...

Published: 2008-09-11
Products: 1
Vendors:
clamav
CVE-2008-5312
6.9 MEDIUM

mailscanner 4.55.10 and other versions before 4.74.16-1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files used by the (1) f-prot-autoupdate, (2) clam...

Published: 2008-12-03
Products: 20
Vendors:
mailscanner
CVE-2008-5313
6.9 MEDIUM

mailscanner 4.68.8 and other versions before 4.74.16-1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files used by the (1) f-prot-autoupdate, (2) clama...

Published: 2008-12-03
Products: 7
Vendors:
mailscanner
CVE-2008-5314
4.3 MEDIUM

Stack consumption vulnerability in libclamav/special.c in ClamAV before 0.94.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted JPEG file, related to the cli_check_jpe...

Published: 2008-12-03
Products: 49
Vendors:
clam_anti-virus

ClamAV 0.94.1 and possibly 0.93.1, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beg...

Published: 2008-12-12
Products: 4
Vendors:
clamav microsoft

Unspecified vulnerability in ClamAV before 0.95 allows remote attackers to bypass detection of malware via a modified RAR archive.

Published: 2009-04-03
Products: 1
Vendors:
clamav
CVE-2008-6680
5.0 MEDIUM

libclamav/pe.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (crash) via a crafted EXE file that triggers a divide-by-zero error.

Published: 2009-04-08
Products: 4
Vendors:
clamav

libclamav/untar.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (infinite loop) via a crafted TAR file that causes (1) clamd and (2) clamscan to hang.

Published: 2009-04-08
Products: 4
Vendors:
clamav debian canonical
CVE-2009-1371
5.0 MEDIUM

The CLI_ISCONTAINED macro in libclamav/others.h in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) via a malformed file with UPack encoding.

Published: 2009-04-23
Products: 99
Vendors:
clamav
CVE-2009-1372
10.0 HIGH

Stack-based buffer overflow in the cli_url_canon function in libclamav/phishcheck.c in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) and possibly execut...

Published: 2009-04-23
Products: 99
Vendors:
clamav
CVE-2009-1601
6.8 MEDIUM

The Ubuntu clamav-milter.init script in clamav-milter before 0.95.1+dfsg-1ubuntu1.2 in Ubuntu 9.04 sets the ownership of the current working directory to the clamav account, which might allow local us...

Published: 2009-05-11
Products: 1
Vendors:
ubuntu
CVE-2008-6845
5.0 MEDIUM

The unpack feature in ClamAV 0.93.3 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a corrupted LZH file.

Published: 2009-07-02
Products: 77
Vendors:
clamav
CVE-2010-0058
6.4 MEDIUM

freshclam in ClamAV in Apple Mac OS X 10.5.8 with Security Update 2009-005 has an incorrect launchd.plist ProgramArguments key and consequently does not run, which might allow remote attackers to intr...

Published: 2010-03-30
Products: 2
Vendors:
apple
CVE-2010-0098
10.0 HIGH

ClamAV before 0.96 does not properly handle the (1) CAB and (2) 7z file formats, which allows remote attackers to bypass virus detection via a crafted archive that is compatible with standard archive ...

Published: 2010-04-08
Products: 96
Vendors:
clamav clamavs
CVE-2010-1311
5.0 MEDIUM

The qtm_decompress function in libclamav/mspack.c in ClamAV before 0.96 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted CAB archive that us...

Published: 2010-04-08
Products: 96
Vendors:
clamav clamavs
CVE-2010-1639
4.3 MEDIUM

The cli_pdf function in libclamav/pdf.c in ClamAV before 0.96.1 allows remote attackers to cause a denial of service (crash) via a malformed PDF file, related to an inconsistency in the calculated str...

Published: 2010-05-26
Products: 94
Vendors:
clamav
CVE-2010-1640
4.3 MEDIUM

Off-by-one error in the parseicon function in libclamav/pe_icons.c in ClamAV 0.96 allows remote attackers to cause a denial of service (crash) via a crafted PE icon that triggers an out-of-bounds read...

Published: 2010-05-26
Products: 1
Vendors:
clamav

Buffer overflow in the find_stream_bounds function in pdf.c in libclamav in ClamAV before 0.96.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary ...

Published: 2010-09-30
Products: 100
Vendors:
clamav
CVE-2010-4260
5.0 MEDIUM

Multiple unspecified vulnerabilities in pdf.c in libclamav in ClamAV before 0.96.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a craf...

Published: 2010-12-07
Products: 113
Vendors:
clamav

Off-by-one error in the icon_cb function in pe_icons.c in libclamav in ClamAV before 0.96.5 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly e...

Published: 2010-12-07
Products: 113
Vendors:
clamav