Vulnerabilities
Vulnerable Software
Clamav:  >> Clamav  >> 0.83.0  Security Vulnerabilities
Buffer overflow in the find_stream_bounds function in pdf.c in libclamav in ClamAV before 0.96.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document. NOTE: some of these details are obtained from third party information.
CVSS Score
9.3
EPSS Score
0.1
Published
2010-09-30
The cli_pdf function in libclamav/pdf.c in ClamAV before 0.96.1 allows remote attackers to cause a denial of service (crash) via a malformed PDF file, related to an inconsistency in the calculated stream length and the real stream length.
CVSS Score
4.3
EPSS Score
0.028
Published
2010-05-26
The unpack feature in ClamAV 0.93.3 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a corrupted LZH file.
CVSS Score
5.0
EPSS Score
0.01
Published
2009-07-02
The CLI_ISCONTAINED macro in libclamav/others.h in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) via a malformed file with UPack encoding.
CVSS Score
5.0
EPSS Score
0.131
Published
2009-04-23
libclamav/pe.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (crash) via a crafted EXE file that triggers a divide-by-zero error.
CVSS Score
5.0
EPSS Score
0.061
Published
2009-04-08
libclamav/untar.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (infinite loop) via a crafted TAR file that causes (1) clamd and (2) clamscan to hang.
CVSS Score
7.8
EPSS Score
0.045
Published
2009-04-08
Unspecified vulnerability in ClamAV before 0.95 allows remote attackers to bypass detection of malware via a modified RAR archive.
CVSS Score
7.5
EPSS Score
0.014
Published
2009-04-03
libclamav in ClamAV before 0.94 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to an out-of-memory condition.
CVSS Score
5.0
EPSS Score
0.029
Published
2008-09-11
Multiple memory leaks in freshclam/manager.c in ClamAV before 0.94 might allow attackers to cause a denial of service (memory consumption) via unspecified vectors related to "error handling logic".
CVSS Score
5.0
EPSS Score
0.037
Published
2008-09-11
Multiple unspecified vulnerabilities in ClamAV before 0.94 have unknown impact and attack vectors related to file descriptor leaks on the "error path" in (1) libclamav/others.c and (2) libclamav/sis.c.
CVSS Score
10.0
EPSS Score
0.02
Published
2008-09-11


Contact Us

Shodan ® - All rights reserved