Vulnerabilities
Vulnerable Software
Clamav:  >> Clamav  >> 0.97.0  Security Vulnerabilities
ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted upack packer file, related to a "heap out of bounds condition."
CVSS Score
7.5
EPSS Score
0.042
Published
2015-02-03
clamscan in ClamAV before 0.98.5, when using -a option, allows remote attackers to cause a denial of service (crash) as demonstrated by the jwplayer.js file.
CVSS Score
2.1
EPSS Score
0.004
Published
2014-12-01
Integer underflow in the cli_scanpe function in pe.c in ClamAV before 0.97.8 allows remote attackers to cause a denial of service (crash) via a skewed offset larger than the size of the PE section in a UPX packed executable, which triggers an out-of-bounds read.
CVSS Score
5.0
EPSS Score
0.107
Published
2013-05-13
The bytecode engine in ClamAV before 0.97.3 allows remote attackers to cause a denial of service (crash) via vectors related to "recursion level" and (1) libclamav/bytecode.c and (2) libclamav/bytecode_api.c.
CVSS Score
4.3
EPSS Score
0.016
Published
2011-11-17
Off-by-one error in the cli_hm_scan function in matcher-hash.c in libclamav in ClamAV before 0.97.2 allows remote attackers to cause a denial of service (daemon crash) via an e-mail message that is not properly handled during certain hash calculations.
CVSS Score
5.0
EPSS Score
0.026
Published
2011-08-05


Contact Us

Shodan ® - All rights reserved