Vulnerabilities
Vulnerable Software
Clamav:  Security Vulnerabilities
The cabd_read_string function in mspack/cabd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2 and other products, allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted CAB file.
CVSS Score
5.5
EPSS Score
0.019
Published
2017-07-18
ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted 7z file.
CVSS Score
5.5
EPSS Score
0.033
Published
2016-10-03
ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted mew packer executable.
CVSS Score
5.5
EPSS Score
0.006
Published
2016-10-03
libclamav in ClamAV (aka Clam AntiVirus), as used in Advanced Malware Protection (AMP) on Cisco Email Security Appliance (ESA) devices before 9.7.0-125 and Web Security Appliance (WSA) devices before 9.0.1-135 and 9.1.x before 9.1.1-041, allows remote attackers to cause a denial of service (AMP process restart) via a crafted document, aka Bug IDs CSCuv78533 and CSCuw60503.
CVSS Score
7.5
EPSS Score
0.023
Published
2016-06-08
ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infinite loop) via a crafted xz archive file.
CVSS Score
5.0
EPSS Score
0.016
Published
2015-05-12
ClamAV before 0.98.7 allows remote attackers to cause a denial of service (crash) via a crafted petite packed file.
CVSS Score
5.0
EPSS Score
0.016
Published
2015-05-12
ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infinite loop) via a crafted y0da cryptor file.
CVSS Score
5.0
EPSS Score
0.018
Published
2015-05-12
The upx decoder in ClamAV before 0.98.7 allows remote attackers to cause a denial of service (crash) via a crafted file.
CVSS Score
5.0
EPSS Score
0.016
Published
2015-05-12
ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted upx packer file, related to a "heap out of bounds condition."
CVSS Score
7.5
EPSS Score
0.012
Published
2015-02-03
ClamAV before 0.98.6 allows remote attackers to cause a denial of service (crash) via a crafted petite packer file, related to an "incorrect compiler optimization."
CVSS Score
5.0
EPSS Score
0.015
Published
2015-02-03


Contact Us

Shodan ® - All rights reserved