Clamav

Clamav

111 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 6.53%
  • Veröffentlicht 30.09.2010 15:00:04
  • Zuletzt bearbeitet 16.06.2026 23:22:45

Buffer overflow in the find_stream_bounds function in pdf.c in libclamav in ClamAV before 0.96.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document. NOTE: some of th...

  • EPSS 2.89%
  • Veröffentlicht 26.05.2010 18:30:01
  • Zuletzt bearbeitet 16.06.2026 23:18:45

The cli_pdf function in libclamav/pdf.c in ClamAV before 0.96.1 allows remote attackers to cause a denial of service (crash) via a malformed PDF file, related to an inconsistency in the calculated stream length and the real stream length.

  • EPSS 2.89%
  • Veröffentlicht 26.05.2010 18:30:01
  • Zuletzt bearbeitet 16.06.2026 23:18:45

Off-by-one error in the parseicon function in libclamav/pe_icons.c in ClamAV 0.96 allows remote attackers to cause a denial of service (crash) via a crafted PE icon that triggers an out-of-bounds read, related to improper rounding during scaling.

  • EPSS 4.89%
  • Veröffentlicht 08.04.2010 17:30:00
  • Zuletzt bearbeitet 16.06.2026 23:15:28

ClamAV before 0.96 does not properly handle the (1) CAB and (2) 7z file formats, which allows remote attackers to bypass virus detection via a crafted archive that is compatible with standard archive utilities.

  • EPSS 3.35%
  • Veröffentlicht 08.04.2010 17:30:00
  • Zuletzt bearbeitet 16.06.2026 23:18:04

The qtm_decompress function in libclamav/mspack.c in ClamAV before 0.96 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted CAB archive that uses the Quantum (aka .Q) compression format. NOTE:...

  • EPSS 2.21%
  • Veröffentlicht 02.07.2009 10:30:00
  • Zuletzt bearbeitet 16.06.2026 23:03:05

The unpack feature in ClamAV 0.93.3 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a corrupted LZH file.

  • EPSS 3.42%
  • Veröffentlicht 23.04.2009 15:30:00
  • Zuletzt bearbeitet 16.06.2026 23:07:08

The CLI_ISCONTAINED macro in libclamav/others.h in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) via a malformed file with UPack encoding.

  • EPSS 7.59%
  • Veröffentlicht 23.04.2009 15:30:00
  • Zuletzt bearbeitet 16.06.2026 23:07:08

Stack-based buffer overflow in the cli_url_canon function in libclamav/phishcheck.c in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted URL.

  • EPSS 3.72%
  • Veröffentlicht 08.04.2009 16:30:00
  • Zuletzt bearbeitet 16.06.2026 23:02:45

libclamav/pe.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (crash) via a crafted EXE file that triggers a divide-by-zero error.

  • EPSS 5.07%
  • Veröffentlicht 08.04.2009 16:30:00
  • Zuletzt bearbeitet 16.06.2026 23:06:54

libclamav/untar.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (infinite loop) via a crafted TAR file that causes (1) clamd and (2) clamscan to hang.