- EPSS 1.01%
- Published 02.07.2009 10:30:00
- Last modified 09.04.2025 00:30:58
The unpack feature in ClamAV 0.93.3 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a corrupted LZH file.
- EPSS 11.89%
- Published 23.04.2009 15:30:00
- Last modified 09.04.2025 00:30:58
Stack-based buffer overflow in the cli_url_canon function in libclamav/phishcheck.c in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted URL.
- EPSS 15.07%
- Published 23.04.2009 15:30:00
- Last modified 09.04.2025 00:30:58
The CLI_ISCONTAINED macro in libclamav/others.h in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) via a malformed file with UPack encoding.
CVE-2009-1270
- EPSS 3.36%
- Published 08.04.2009 16:30:00
- Last modified 09.04.2025 00:30:58
libclamav/untar.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (infinite loop) via a crafted TAR file that causes (1) clamd and (2) clamscan to hang.
- EPSS 7.14%
- Published 08.04.2009 16:30:00
- Last modified 09.04.2025 00:30:58
libclamav/pe.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (crash) via a crafted EXE file that triggers a divide-by-zero error.
CVE-2009-1241
- EPSS 1.65%
- Published 03.04.2009 18:30:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in ClamAV before 0.95 allows remote attackers to bypass detection of malware via a modified RAR archive.
CVE-2008-5525
- EPSS 0.4%
- Published 12.12.2008 18:30:02
- Last modified 09.04.2025 00:30:58
ClamAV 0.94.1 and possibly 0.93.1, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no ...
- EPSS 2.01%
- Published 11.09.2008 01:13:41
- Last modified 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in ClamAV before 0.94 have unknown impact and attack vectors related to file descriptor leaks on the "error path" in (1) libclamav/others.c and (2) libclamav/sis.c.
- EPSS 4.36%
- Published 11.09.2008 01:13:41
- Last modified 09.04.2025 00:30:58
Multiple memory leaks in freshclam/manager.c in ClamAV before 0.94 might allow attackers to cause a denial of service (memory consumption) via unspecified vectors related to "error handling logic".
- EPSS 3.45%
- Published 11.09.2008 01:13:41
- Last modified 09.04.2025 00:30:58
libclamav in ClamAV before 0.94 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to an out-of-memory condition.