Search: "clamav"

144 CVEs found

Unspecified vulnerability in pdf.c in libclamav in ClamAV before 0.96.5 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF do...

Published: 2010-12-07
Products: 113
Vendors:
clamav
CVE-2011-1003
6.8 MEDIUM

Double free vulnerability in the vba_read_project_strings function in vba_extract.c in libclamav in ClamAV before 0.97 might allow remote attackers to execute arbitrary code via crafted Visual Basic f...

Published: 2011-02-23
Products: 114
Vendors:
clamav
CVE-2011-2721
5.0 MEDIUM

Off-by-one error in the cli_hm_scan function in matcher-hash.c in libclamav in ClamAV before 0.97.2 allows remote attackers to cause a denial of service (daemon crash) via an e-mail message that is no...

Published: 2011-08-05
Products: 117
Vendors:
clamav
CVE-2011-3627
4.3 MEDIUM

The bytecode engine in ClamAV before 0.97.3 allows remote attackers to cause a denial of service (crash) via vectors related to "recursion level" and (1) libclamav/bytecode.c and (2) libclamav/bytecod...

Published: 2011-11-17
Products: 43
Vendors:
clamav
CVE-2012-1419
4.3 MEDIUM

The TAR file parser in ClamAV 0.96.4 and Quick Heal (aka Cat QuickHeal) 11.00 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial [aliases] character sequence. NOT...

Published: 2012-03-21
Products: 2
Vendors:
clamav cat
CVE-2012-1443
4.3 MEDIUM

The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Command Antivi...

Published: 2012-03-21
Products: 36
Vendors:
clamav bitdefender pandasecurity k7computing alwil +28 more
CVE-2012-1457
4.3 MEDIUM

The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.0...

Published: 2012-03-21
Products: 29
Vendors:
clamav bitdefender k7computing alwil emsisoft +21 more
CVE-2012-1458
4.3 MEDIUM

The Microsoft CHM file parser in ClamAV 0.96.4 and Sophos Anti-Virus 4.61.0 allows remote attackers to bypass malware detection via a crafted reset interval in the LZXC header of a CHM file. NOTE: th...

Published: 2012-03-21
Products: 2
Vendors:
clamav sophos
CVE-2012-1459
4.3 MEDIUM

The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefend...

Published: 2012-03-21
Products: 35
Vendors:
clamav bitdefender pandasecurity k7computing alwil +27 more
CVE-2012-2243
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote attackers to inject arbitrary web script or HTML by uploading an XML file with the xhtml exte...

Published: 2012-11-24
Products: 15
Vendors:
mahara
CVE-2012-2244
6.0 MEDIUM

Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote authenticated administrators to execute arbitrary programs by modifying the path to clamav. NOTE: this can be exploited without authenti...

Published: 2012-11-24
Products: 14
Vendors:
mahara
CVE-2013-2020
5.0 MEDIUM

Integer underflow in the cli_scanpe function in pe.c in ClamAV before 0.97.8 allows remote attackers to cause a denial of service (crash) via a skewed offset larger than the size of the PE section in ...

Published: 2013-05-13
Products: 60
Vendors:
canonical clamav suse
CVE-2013-2021
4.3 MEDIUM

pdf.c in ClamAV 0.97.1 through 0.97.7 allows remote attackers to cause a denial of service (out-of-bounds-read) via a crafted length value in an encrypted PDF file.

Published: 2013-05-13
Products: 14
Vendors:
canonical clamav suse

clamscan in ClamAV before 0.98.5, when using -a option, allows remote attackers to cause a denial of service (crash) as demonstrated by the jwplayer.js file.

Published: 2014-12-01
Products: 1
Vendors:
clamav
CVE-2014-9050
5.0 MEDIUM

Heap-based buffer overflow in the cli_scanpe function in libclamav/pe.c in ClamAV before 0.98.5 allows remote attackers to cause a denial of service (crash) via a crafted y0da Crypter PE file.

Published: 2014-12-01
Products: 99
Vendors:
clamav

ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted upack packer file, related to a "heap out of bounds condition."

Published: 2015-02-03
Products: 3
Vendors:
fedoraproject clamav

ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted (1) Yoda's crypter or (2) mew packer file, related to a "heap out of bounds condition."

Published: 2015-02-03
Products: 3
Vendors:
fedoraproject clamav

ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted upx packer file, related to a "heap out of bounds condition."

Published: 2015-02-03
Products: 3
Vendors:
fedoraproject clamav
CVE-2015-1463
5.0 MEDIUM

ClamAV before 0.98.6 allows remote attackers to cause a denial of service (crash) via a crafted petite packer file, related to an "incorrect compiler optimization."

Published: 2015-02-03
Products: 3
Vendors:
clamav fedoraproject
CVE-2015-2170
5.0 MEDIUM

The upx decoder in ClamAV before 0.98.7 allows remote attackers to cause a denial of service (crash) via a crafted file.

Published: 2015-05-12
Products: 5
Vendors:
canonical clamav