Clam Anti-virus

Clamav

60 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.1%
  • Published 29.06.2005 04:00:00
  • Last modified 03.04.2025 01:03:51

The Quantum archive decompressor in Clam AntiVirus (ClamAV) before 0.86.1 allows remote attackers to cause a denial of service (application crash) via a crafted Quantum archive.

  • EPSS 0.37%
  • Published 28.05.2005 04:00:00
  • Last modified 03.04.2025 01:03:51

Cross-site scripting (XSS) vulnerability in Jaws Glossary gadget 0.4 to 0.5.1 allows remote attackers to inject arbitrary web script or HTML via the term parameter in a view or ViewTerm action to index.php.

Exploit
  • EPSS 2.17%
  • Published 27.05.2005 04:00:00
  • Last modified 03.04.2025 01:03:51

The filecopy function in misc.c in Clam AntiVirus (ClamAV) before 0.85, on Mac OS, allows remote attackers to execute arbitrary code via a virus in a filename that contains shell metacharacters, which are not properly handled when HFS permissions pre...

  • EPSS 0.04%
  • Published 24.05.2005 04:00:00
  • Last modified 03.04.2025 01:03:51

Gibraltar Firewall 2.2 and earlier, when using the ClamAV update to 0.81 for Squid, uses a defunct ClamAV method to scan memory for viruses, which does not return an error code and prevents viruses from being detected.

  • EPSS 1.47%
  • Published 02.05.2005 04:00:00
  • Last modified 03.04.2025 01:03:51

ClamAV 0.80 and earlier allows remote attackers to bypass virus scanning via a base64 encoded image in a data: (RFC 2397) URL.

  • EPSS 1.31%
  • Published 02.05.2005 04:00:00
  • Last modified 03.04.2025 01:03:51

ClamAV 0.80 and earlier allows remote attackers to cause a denial of service (clamd daemon crash) via a ZIP file with malformed headers.

  • EPSS 0.91%
  • Published 31.12.2004 05:00:00
  • Last modified 03.04.2025 01:03:51

Claim Anti-Virus (ClamAV) 0.68 and earlier allows remote attackers to cause a denial of service (crash) via certain RAR archives, such as those generated by the Beagle/Bagle worm.

Exploit
  • EPSS 11.11%
  • Published 23.11.2004 05:00:00
  • Last modified 03.04.2025 01:03:51

libclamav in Clam AntiVirus 0.65 allows remote attackers to cause a denial of service (crash) via a uuencoded e-mail message with an invalid line length (e.g., a lowercase character), which causes an assert error in clamd that terminates the calling ...

Exploit
  • EPSS 0.13%
  • Published 30.03.2004 05:00:00
  • Last modified 03.04.2025 01:03:51

The "%f" feature in the VirusEvent directive in Clam AntiVirus daemon (clamd) before 0.70 allows local users to execute arbitrary commands via shell metacharacters in a file name.

  • EPSS 1.97%
  • Published 15.12.2003 05:00:00
  • Last modified 03.04.2025 01:03:51

Format string vulnerability in clamav-milter for Clam AntiVirus 0.60 through 0.60p, and other versions before 0.65, allows remote attackers to cause a denial of service and possibly execute arbitrary code via format string specifiers in the email add...