Search: "clamav"

144 CVEs found

Format string vulnerability in clamav-milter for Clam AntiVirus 0.60 through 0.60p, and other versions before 0.65, allows remote attackers to cause a denial of service and possibly execute arbitrary ...

Published: 2003-12-15
Products: 2
Vendors:
clam_anti-virus
CVE-2005-0133
5.0 MEDIUM

ClamAV 0.80 and earlier allows remote attackers to cause a denial of service (clamd daemon crash) via a ZIP file with malformed headers.

Published: 2005-05-02
Products: 10
Vendors:
clam_anti-virus
CVE-2005-0218
5.0 MEDIUM

ClamAV 0.80 and earlier allows remote attackers to bypass virus scanning via a base64 encoded image in a data: (RFC 2397) URL.

Published: 2005-05-02
Products: 10
Vendors:
clam_anti-virus

Gibraltar Firewall 2.2 and earlier, when using the ClamAV update to 0.81 for Squid, uses a defunct ClamAV method to scan memory for viruses, which does not return an error code and prevents viruses fr...

Published: 2005-05-24
Products: 3
Vendors:
clam_anti-virus squid gibraltar
CVE-2005-2070
5.0 MEDIUM

The ClamAV Mail fILTER (clamav-milter) 0.84 through 0.85d, when used in Sendmail using long timeouts, allows remote attackers to cause a denial of service by keeping an open connection, which prevents...

Published: 2005-06-29
Products: 33
Vendors:
sendmail
CVE-2005-3229
5.1 MEDIUM

Multiple interpretation error in unspecified versions of ClamAV Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed ce...

Published: 2005-10-14
Products: 1
Vendors:
clam_anti-virus
CVE-2005-3500
5.0 MEDIUM

The tnef_attachment function in tnef.c for Clam AntiVirus (ClamAV) before 0.87.1 allows remote attackers to cause a denial of service (infinite loop and memory exhaustion) via a crafted value in a CAB...

Published: 2005-11-05
Products: 33
Vendors:
clam_anti-virus
CVE-2006-1989
5.1 MEDIUM

Buffer overflow in the get_database function in the HTTP client in Freshclam in ClamAV 0.80 to 0.88.1 might allow remote web servers to execute arbitrary code via long HTTP headers.

Published: 2006-05-01
Products: 2
Vendors:
clam_anti-virus

Multiple unspecified vulnerabilities in SnapGear before 3.1.4u1 allow remote attackers to cause a denial of service via unspecified vectors involving (1) IPSec replay windows and (2) the use of vulner...

Published: 2006-09-07
Products: 4
Vendors:
securecomputing

Integer overflow in ClamAV 0.88.1 and 0.88.4, and other versions before 0.88.5, allows remote attackers to cause a denial of service (scanning service crash) and execute arbitrary code via a crafted P...

Published: 2006-10-16
Products: 48
Vendors:
clam_anti-virus
CVE-2006-5295
5.0 MEDIUM

Unspecified vulnerability in ClamAV before 0.88.5 allows remote attackers to cause a denial of service (scanning service crash) via a crafted Compressed HTML Help (CHM) file that causes ClamAV to "rea...

Published: 2006-10-16
Products: 48
Vendors:
clam_anti-virus

Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, which allows remote attackers to cause a denial of service (file descriptor consumption and failed scan...

Published: 2007-02-16
Products: 3
Vendors:
clamav debian apple
CVE-2007-0898
6.4 MEDIUM

Directory traversal vulnerability in clamd in Clam AntiVirus ClamAV before 0.90 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the id MIME header parameter in a multi-part ...

Published: 2007-02-16
Products: 48
Vendors:
clam_anti-virus
CVE-2007-3023
10.0 HIGH

unsp.c in ClamAV before 0.90.3 and 0.91 before 0.91rc1 does not properly calculate the end of a certain buffer, with unknown impact and remote attack vectors.

Published: 2007-06-07
Products: 5
Vendors:
clam_anti-virus
CVE-2007-3122
5.0 MEDIUM

The parsing engine in ClamAV before 0.90.3 and 0.91 before 0.91rc1 allows remote attackers to bypass scanning via a RAR file with a header flag value of 10, which can be processed by WinRAR.

Published: 2007-06-07
Products: 6
Vendors:
clam_anti-virus
CVE-2007-3123
5.0 MEDIUM

unrar.c in libclamav in ClamAV before 0.90.3 and 0.91 before 0.91rc1 allows remote attackers to cause a denial of service (core dump) via a crafted RAR file with a modified vm_codesize value, which tr...

Published: 2007-06-07
Products: 6
Vendors:
clam_anti-virus

libclamav/others.c in ClamAV before 0.90.3 and 0.91 before 0.91rc1 uses insecure permissions for temporary files that are created by the cli_gentempstream function in clamd/clamdscan, which might allo...

Published: 2007-06-07
Products: 6
Vendors:
clam_anti-virus
CVE-2007-3025
5.0 MEDIUM

Unspecified vulnerability in libclamav/phishcheck.c in ClamAV before 0.90.3 and 0.91 before 0.91rc1, when running on Solaris, allows remote attackers to cause a denial of service (hang) via unknown ve...

Published: 2007-06-07
Products: 7
Vendors:
sun clam_anti-virus
CVE-2007-4510
4.3 MEDIUM

ClamAV before 0.91.2, as used in Kolab Server 2.0 through 2.2beta1 and other products, allows remote attackers to cause a denial of service (application crash) via (1) a crafted RTF file, which trigge...

Published: 2007-08-23
Products: 8
Vendors:
clam_anti-virus kolab

clamav-milter in ClamAV before 0.91.2, when run in black hole mode, allows remote attackers to execute arbitrary commands via shell metacharacters that are used in a certain popen call, involving the ...

Published: 2007-08-28
Products: 1
Vendors:
clam_anti-virus