Vulnerabilities
Vulnerable Software
Clamav:  >> Clamav  >> 0.73.0  Security Vulnerabilities
The OLE2 parser in Clam AntiVirus (ClamAV) allows remote attackers to cause a denial of service (resource consumption) via an OLE2 file with (1) a large property size or (2) a loop in the FAT file block chain that triggers an infinite loop, as demonstrated via a crafted DOC file.
CVSS Score
4.3
EPSS Score
0.04
Published
2007-05-14
Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, which allows remote attackers to cause a denial of service (file descriptor consumption and failed scans) via CAB archives with a cabinet header record length of zero, which causes a function to return without closing a file descriptor.
CVSS Score
7.5
EPSS Score
0.051
Published
2007-02-16
Multiple format string vulnerabilities in the logging code in Clam AntiVirus (ClamAV) before 0.88.1 might allow remote attackers to execute arbitrary code. NOTE: as of 20060410, it is unclear whether this is a vulnerability, as there is some evidence that the arguments are actually being sanitized properly.
CVSS Score
10.0
EPSS Score
0.368
Published
2006-04-06
The cabd_find function in cabd.c of the libmspack library (mspack) for Clam AntiVirus (ClamAV) before 0.87.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted CAB file that causes cabd_find to be called with a zero length.
CVSS Score
4.3
EPSS Score
0.072
Published
2005-11-05


Contact Us

Shodan ® - All rights reserved