Vulnerabilities
Vulnerable Software
Clam Anti-Virus:  >> Clamav  >> 0.88  Security Vulnerabilities
freshclam in (1) Clam Antivirus (ClamAV) 0.88 and (2) ClamXav 1.0.3h and earlier does not drop privileges before processing the config-file command line option, which allows local users to read portions of arbitrary files when an error message displays the first line of the target file.
CVSS Score
7.2
EPSS Score
0.0
Published
2006-05-17
Buffer overflow in the get_database function in the HTTP client in Freshclam in ClamAV 0.80 to 0.88.1 might allow remote web servers to execute arbitrary code via long HTTP headers.
CVSS Score
5.1
EPSS Score
0.045
Published
2006-05-01
Integer overflow in the cli_scanpe function in the PE header parser (libclamav/pe.c) in Clam AntiVirus (ClamAV) before 0.88.1, when ArchiveMaxFileSize is disabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code.
CVSS Score
5.1
EPSS Score
0.282
Published
2006-04-06
The cli_bitset_set function in libclamav/others.c in Clam AntiVirus (ClamAV) before 0.88.1 allows remote attackers to cause a denial of service via unspecified vectors that trigger an "invalid memory access."
CVSS Score
5.0
EPSS Score
0.17
Published
2006-04-06


Contact Us

Shodan ® - All rights reserved