Vulnerabilities
Vulnerable Software
Clamav:  >> Clamav  >> 0.96  Security Vulnerabilities
The cli_pdf function in libclamav/pdf.c in ClamAV before 0.96.1 allows remote attackers to cause a denial of service (crash) via a malformed PDF file, related to an inconsistency in the calculated stream length and the real stream length.
CVSS Score
4.3
EPSS Score
0.028
Published
2010-05-26
Off-by-one error in the parseicon function in libclamav/pe_icons.c in ClamAV 0.96 allows remote attackers to cause a denial of service (crash) via a crafted PE icon that triggers an out-of-bounds read, related to improper rounding during scaling.
CVSS Score
4.3
EPSS Score
0.02
Published
2010-05-26
ClamAV before 0.96 does not properly handle the (1) CAB and (2) 7z file formats, which allows remote attackers to bypass virus detection via a crafted archive that is compatible with standard archive utilities.
CVSS Score
10.0
EPSS Score
0.034
Published
2010-04-08
The qtm_decompress function in libclamav/mspack.c in ClamAV before 0.96 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted CAB archive that uses the Quantum (aka .Q) compression format. NOTE: some of these details are obtained from third party information.
CVSS Score
5.0
EPSS Score
0.043
Published
2010-04-08


Contact Us

Shodan ® - All rights reserved