Clamav

Clamav

96 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.01%
  • Veröffentlicht 02.07.2009 10:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The unpack feature in ClamAV 0.93.3 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a corrupted LZH file.

  • EPSS 11.89%
  • Veröffentlicht 23.04.2009 15:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Stack-based buffer overflow in the cli_url_canon function in libclamav/phishcheck.c in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted URL.

  • EPSS 15.07%
  • Veröffentlicht 23.04.2009 15:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The CLI_ISCONTAINED macro in libclamav/others.h in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) via a malformed file with UPack encoding.

  • EPSS 3.36%
  • Veröffentlicht 08.04.2009 16:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

libclamav/untar.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (infinite loop) via a crafted TAR file that causes (1) clamd and (2) clamscan to hang.

  • EPSS 7.14%
  • Veröffentlicht 08.04.2009 16:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

libclamav/pe.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (crash) via a crafted EXE file that triggers a divide-by-zero error.

  • EPSS 1.65%
  • Veröffentlicht 03.04.2009 18:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Unspecified vulnerability in ClamAV before 0.95 allows remote attackers to bypass detection of malware via a modified RAR archive.

  • EPSS 0.4%
  • Veröffentlicht 12.12.2008 18:30:02
  • Zuletzt bearbeitet 09.04.2025 00:30:58

ClamAV 0.94.1 and possibly 0.93.1, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no ...

  • EPSS 2.01%
  • Veröffentlicht 11.09.2008 01:13:41
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple unspecified vulnerabilities in ClamAV before 0.94 have unknown impact and attack vectors related to file descriptor leaks on the "error path" in (1) libclamav/others.c and (2) libclamav/sis.c.

  • EPSS 4.36%
  • Veröffentlicht 11.09.2008 01:13:41
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple memory leaks in freshclam/manager.c in ClamAV before 0.94 might allow attackers to cause a denial of service (memory consumption) via unspecified vectors related to "error handling logic".

  • EPSS 3.45%
  • Veröffentlicht 11.09.2008 01:13:41
  • Zuletzt bearbeitet 09.04.2025 00:30:58

libclamav in ClamAV before 0.94 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to an out-of-memory condition.