- EPSS 1.56%
- Published 12.02.2008 20:00:00
- Last modified 09.04.2025 00:30:58
The unmew11 function in libclamav/mew.c in libclamav in ClamAV before 0.92.1 has unknown impact and attack vectors that trigger "heap corruption."
CVE-2007-2650
- EPSS 3.93%
- Published 14.05.2007 21:19:00
- Last modified 09.04.2025 00:30:58
The OLE2 parser in Clam AntiVirus (ClamAV) allows remote attackers to cause a denial of service (resource consumption) via an OLE2 file with (1) a large property size or (2) a loop in the FAT file block chain that triggers an infinite loop, as demons...
CVE-2007-0897
- EPSS 5.27%
- Published 16.02.2007 19:28:00
- Last modified 09.04.2025 00:30:58
Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, which allows remote attackers to cause a denial of service (file descriptor consumption and failed scans) via CAB archives with a cabinet header record l...
CVE-2006-4018
- EPSS 44.63%
- Published 08.08.2006 20:04:00
- Last modified 03.04.2025 01:03:51
Heap-based buffer overflow in the pefromupx function in libclamav/upx.c in Clam AntiVirus (ClamAV) 0.81 through 0.88.3 allows remote attackers to execute arbitrary code via a crafted UPX packed file containing sections with large rsize values.
- EPSS 36.76%
- Published 06.04.2006 22:04:00
- Last modified 03.04.2025 01:03:51
Multiple format string vulnerabilities in the logging code in Clam AntiVirus (ClamAV) before 0.88.1 might allow remote attackers to execute arbitrary code. NOTE: as of 20060410, it is unclear whether this is a vulnerability, as there is some evidenc...
CVE-2005-3501
- EPSS 7.36%
- Published 05.11.2005 11:02:00
- Last modified 03.04.2025 01:03:51
The cabd_find function in cabd.c of the libmspack library (mspack) for Clam AntiVirus (ClamAV) before 0.87.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted CAB file that causes cabd_find to be called with a zero le...