Clamav

Clamav

97 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.11%
  • Veröffentlicht 08.04.2010 17:30:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

ClamAV before 0.96 does not properly handle the (1) CAB and (2) 7z file formats, which allows remote attackers to bypass virus detection via a crafted archive that is compatible with standard archive utilities.

  • EPSS 1.27%
  • Veröffentlicht 02.07.2009 10:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The unpack feature in ClamAV 0.93.3 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a corrupted LZH file.

  • EPSS 8.7%
  • Veröffentlicht 23.04.2009 15:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Stack-based buffer overflow in the cli_url_canon function in libclamav/phishcheck.c in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted URL.

  • EPSS 5.06%
  • Veröffentlicht 23.04.2009 15:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The CLI_ISCONTAINED macro in libclamav/others.h in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) via a malformed file with UPack encoding.

  • EPSS 3.87%
  • Veröffentlicht 08.04.2009 16:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

libclamav/untar.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (infinite loop) via a crafted TAR file that causes (1) clamd and (2) clamscan to hang.

  • EPSS 4.17%
  • Veröffentlicht 08.04.2009 16:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

libclamav/pe.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (crash) via a crafted EXE file that triggers a divide-by-zero error.

  • EPSS 2.24%
  • Veröffentlicht 03.04.2009 18:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Unspecified vulnerability in ClamAV before 0.95 allows remote attackers to bypass detection of malware via a modified RAR archive.

  • EPSS 0.47%
  • Veröffentlicht 12.12.2008 18:30:02
  • Zuletzt bearbeitet 09.04.2025 00:30:58

ClamAV 0.94.1 and possibly 0.93.1, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no ...

  • EPSS 1.9%
  • Veröffentlicht 11.09.2008 01:13:41
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple unspecified vulnerabilities in ClamAV before 0.94 have unknown impact and attack vectors related to file descriptor leaks on the "error path" in (1) libclamav/others.c and (2) libclamav/sis.c.

  • EPSS 4.13%
  • Veröffentlicht 11.09.2008 01:13:41
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple memory leaks in freshclam/manager.c in ClamAV before 0.94 might allow attackers to cause a denial of service (memory consumption) via unspecified vectors related to "error handling logic".