← Back

Clamav

clamav

Vendor: Clamav • 103 CVEs

CVEs (103)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Clamav
1Clamav
Apr 29, 2026
Dec 7, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Off-by-one error in the icon_cb function in pe_icons.c in libclamav in ClamAV before 0.96.5 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary cod...Show more
Off-by-one error in the icon_cb function in pe_icons.c in libclamav in ClamAV before 0.96.5 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors. NOTE: some of these details are obtained from third party information.Show less
1Clamav
1Clamav
Apr 29, 2026
Dec 7, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Multiple unspecified vulnerabilities in pdf.c in libclamav in ClamAV before 0.96.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document, ak...Show more
Multiple unspecified vulnerabilities in pdf.c in libclamav in ClamAV before 0.96.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document, aka (1) "bb #2358" and (2) "bb #2396."Show less
1Clamav
1Clamav
Apr 29, 2026
Sep 30, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Buffer overflow in the find_stream_bounds function in pdf.c in libclamav in ClamAV before 0.96.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted P...Show more
Buffer overflow in the find_stream_bounds function in pdf.c in libclamav in ClamAV before 0.96.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document. NOTE: some of these details are obtained from third party information.Show less
1Clamav
1Clamav
Apr 29, 2026
May 26, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Off-by-one error in the parseicon function in libclamav/pe_icons.c in ClamAV 0.96 allows remote attackers to cause a denial of service (crash) via a crafted PE icon that triggers an out-of-bounds read, related to imprope...Show more
Off-by-one error in the parseicon function in libclamav/pe_icons.c in ClamAV 0.96 allows remote attackers to cause a denial of service (crash) via a crafted PE icon that triggers an out-of-bounds read, related to improper rounding during scaling.Show less
1Clamav
1Clamav
Apr 29, 2026
May 26, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The cli_pdf function in libclamav/pdf.c in ClamAV before 0.96.1 allows remote attackers to cause a denial of service (crash) via a malformed PDF file, related to an inconsistency in the calculated stream length and the r...Show more
The cli_pdf function in libclamav/pdf.c in ClamAV before 0.96.1 allows remote attackers to cause a denial of service (crash) via a malformed PDF file, related to an inconsistency in the calculated stream length and the real stream length.Show less
2Clamav
Clamavs
2Clamav
Clamav
Apr 29, 2026
Apr 8, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The qtm_decompress function in libclamav/mspack.c in ClamAV before 0.96 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted CAB archive that uses the Quantum (aka...Show more
The qtm_decompress function in libclamav/mspack.c in ClamAV before 0.96 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted CAB archive that uses the Quantum (aka .Q) compression format. NOTE: some of these details are obtained from third party information.Show less
2Clamav
Clamavs
2Clamav
Clamav
Apr 29, 2026
Apr 8, 2010
N/A· v4
N/A· v3
10.0 HIGH· v2
ClamAV before 0.96 does not properly handle the (1) CAB and (2) 7z file formats, which allows remote attackers to bypass virus detection via a crafted archive that is compatible with standard archive utilities.
1Clamav
1Clamav
Apr 23, 2026
Jul 2, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The unpack feature in ClamAV 0.93.3 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a corrupted LZH file.
1Clamav
1Clamav
Apr 23, 2026
Apr 23, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
Stack-based buffer overflow in the cli_url_canon function in libclamav/phishcheck.c in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via...Show more
Stack-based buffer overflow in the cli_url_canon function in libclamav/phishcheck.c in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted URL.Show less
1Clamav
1Clamav
Apr 23, 2026
Apr 23, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The CLI_ISCONTAINED macro in libclamav/others.h in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) via a malformed file with UPack encoding.
3Canonical
ClamavDebian
3Clamav
Debian LinuxUbuntu Linux
Apr 23, 2026
Apr 8, 2009
N/A· v4
N/A· v3
7.8 HIGH· v2
libclamav/untar.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (infinite loop) via a crafted TAR file that causes (1) clamd and (2) clamscan to hang.
1Clamav
1Clamav
Apr 23, 2026
Apr 8, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
libclamav/pe.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (crash) via a crafted EXE file that triggers a divide-by-zero error.
1Clamav
1Clamav
Apr 23, 2026
Apr 3, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in ClamAV before 0.95 allows remote attackers to bypass detection of malware via a modified RAR archive.
1Clamav
1Clamav
Apr 23, 2026
Dec 12, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
ClamAV 0.94.1 and possibly 0.93.1, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifyin...Show more
ClamAV 0.94.1 and possibly 0.93.1, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.Show less
1Clamav
1Clamav
Apr 23, 2026
Sep 11, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple unspecified vulnerabilities in ClamAV before 0.94 have unknown impact and attack vectors related to file descriptor leaks on the "error path" in (1) libclamav/others.c and (2) libclamav/sis.c.
2Clamav
Debian
2Clamav
Debian Linux
Apr 23, 2026
Sep 11, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Multiple memory leaks in freshclam/manager.c in ClamAV before 0.94 might allow attackers to cause a denial of service (memory consumption) via unspecified vectors related to "error handling logic".
2Clamav
Debian
2Clamav
Debian Linux
Apr 23, 2026
Sep 11, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
libclamav in ClamAV before 0.94 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to an out-of-memory condition.
1Clamav
1Clamav
Apr 23, 2026
Feb 12, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
The unmew11 function in libclamav/mew.c in libclamav in ClamAV before 0.92.1 has unknown impact and attack vectors that trigger "heap corruption."
2Clamav
Debian
2Clamav
Debian Linux
Apr 23, 2026
May 14, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The OLE2 parser in Clam AntiVirus (ClamAV) allows remote attackers to cause a denial of service (resource consumption) via an OLE2 file with (1) a large property size or (2) a loop in the FAT file block chain that trigge...Show more
The OLE2 parser in Clam AntiVirus (ClamAV) allows remote attackers to cause a denial of service (resource consumption) via an OLE2 file with (1) a large property size or (2) a loop in the FAT file block chain that triggers an infinite loop, as demonstrated via a crafted DOC file.Show less
3Apple
ClamavDebian
3Clamav
Debian LinuxMac Os X Server
Apr 23, 2026
Feb 16, 2007
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, which allows remote attackers to cause a denial of service (file descriptor consumption and failed scans) via CAB archives...Show more
Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, which allows remote attackers to cause a denial of service (file descriptor consumption and failed scans) via CAB archives with a cabinet header record length of zero, which causes a function to return without closing a file descriptor.Show less