Search: "clamav"

144 CVEs found

CVE-2018-0360
5.5 MEDIUM

ClamAV before 0.100.1 has an HWP integer overflow with a resultant infinite loop via a crafted Hangul Word Processor file. This is in parsehwp3_paragraph() in libclamav/hwp.c.

Published: 2018-07-16
Products: 6
Vendors:
clamav debian canonical

ClamAV before 0.100.1 lacks a PDF object length check, resulting in an unreasonably long time to parse a relatively small file.

Published: 2018-07-16
Products: 2
Vendors:
clamav debian
CVE-2018-15378
5.5 MEDIUM

A vulnerability in ClamAV versions prior to 0.100.2 could allow an attacker to cause a denial of service (DoS) condition. The vulnerability is due to an error related to the MEW unpacker within the "u...

Published: 2018-10-15
Products: 6
Vendors:
clamav debian canonical
CVE-2019-1788
5.5 MEDIUM

A vulnerability in the Object Linking & Embedding (OLE2) file scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could allow an unauthenticated, remote attacker to c...

Published: 2019-04-08
Products: 4
Vendors:
clamav debian opensuse
CVE-2019-1798
5.5 MEDIUM

A vulnerability in the Portable Executable (PE) file scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could allow an unauthenticated, remote attacker to cause a de...

Published: 2019-04-08
Products: 1
Vendors:
clamav

cPanel before 74.0.8 allows local users to disable the ClamAV daemon (SEC-409).

Published: 2019-08-01
Products: 2
Vendors:
cpanel
CVE-2018-20902
5.5 MEDIUM

cPanel before 71.9980.37 allows attackers to read root's crontab file by leveraging ClamAV installation (SEC-408).

Published: 2019-08-01
Products: 1
Vendors:
cpanel

ClamAV versions prior to 0.101.3 are susceptible to a zip bomb vulnerability where an unauthenticated attacker can cause a denial of service condition by sending crafted messages to an affected system...

Published: 2019-11-05
Products: 1
Vendors:
clamav

ClamAV versions prior to 0.101.2 are susceptible to a denial of service (DoS) vulnerability. An out-of-bounds heap read condition may occur when scanning PE files. An example is Windows EXE and DLL fi...

Published: 2019-11-05
Products: 1
Vendors:
clamav
CVE-2007-6745
9.8 CRITICAL

clamav 0.91.2 suffers from a floating point exception when using ScanOLE2.

Published: 2019-11-07
Products: 4
Vendors:
clamav debian
CVE-2013-7087
9.8 CRITICAL

ClamAV before 0.97.7 has WWPack corrupt heap memory

Published: 2019-11-15
Products: 6
Vendors:
clamav debian fedoraproject
CVE-2013-7088
9.8 CRITICAL

ClamAV before 0.97.7 has buffer overflow in the libclamav component

Published: 2019-11-15
Products: 6
Vendors:
clamav debian fedoraproject

ClamAV before 0.97.7: dbg_printhex possible information leak

Published: 2019-11-15
Products: 6
Vendors:
clamav debian fedoraproject

A vulnerability in the email parsing module Clam AntiVirus (ClamAV) Software versions 0.102.0, 0.101.4 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition ...

Published: 2020-01-15
Products: 7
Vendors:
clamav cisco debian canonical

A vulnerability in the Data-Loss-Prevention (DLP) module in Clam AntiVirus (ClamAV) Software versions 0.102.1 and 0.102.0 could allow an unauthenticated, remote attacker to cause a denial of service c...

Published: 2020-02-05
Products: 7
Vendors:
clamav canonical

A vulnerability in the ARJ archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affe...

Published: 2020-05-13
Products: 12
Vendors:
fedoraproject cisco debian canonical

A vulnerability in the PDF archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.101 - 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on...

Published: 2020-05-13
Products: 11
Vendors:
canonical cisco debian fedoraproject

A vulnerability in the EGG archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.0 - 0.102.3 could allow an unauthenticated, remote attacker to cause a denial of service condition ...

Published: 2020-07-20
Products: 9
Vendors:
clamav debian fedoraproject canonical
CVE-2021-27506
5.5 MEDIUM

The ClamAV Engine (version 0.103.1 and below) component embedded in Storsmshield Network Security (SNS) is subject to DoS in case of parsing of malformed png files. This affect Netasq versions 9.1.0 t...

Published: 2021-03-19
Products: 3
Vendors:
clamav netasq_project stormshield

A vulnerability in the dynamic link library (DLL) loading mechanism in Cisco Advanced Malware Protection (AMP) for Endpoints Windows Connector, ClamAV for Windows, and Immunet could allow an authentic...

Published: 2021-04-08
Products: 3
Vendors:
cisco