cbcvebase.

Cisco Secure Endpoint vulnerabilities

16 known vulnerabilities affecting cisco/cisco_secure_endpoint.

Total CVEs
16
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH12MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2023-20032P2CRITICALCVSS 9.8v6.1.9v6.2.5+20 more2023-03-01
CVE-2023-20032 [CRITICAL] CWE-120 CVE-2023-20032: On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vu On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to execute arbitrary code. This vulnerability is due to a missing buffer size chec
nvd
CVE-2024-20290P3HIGHCVSS 7.5v6.0.9v6.0.7+31 more2024-02-07
CVE-2024-20290 [HIGH] CWE-126 CVE-2024-20290: A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote atta A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for end-of-string values during scanning, which may result in a heap buffer over-read. An attacker could exploit this vulnerability
nvd
CVE-2026-20216P3HIGHCVSS 7.5v7.0.5v6.2.19+144 more2026-07-01
CVE-2026-20216 [HIGH] CWE-770 CVE-2026-20216: A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, re A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper handling of temporary resources during file scanning. An attacker could exploit this vulnerability by submitting a crafted InstallShield file to be scan
nvd
CVE-2026-20214P3HIGHCVSS 7.5v7.0.5v6.2.19+144 more2026-07-01
CVE-2026-20214 [HIGH] CWE-120 CVE-2026-20214: A vulnerability in the FSG file format parser of ClamAV could allow an unauthenticated, remote attac A vulnerability in the FSG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in FSG files during scanning, which may result in an out-of-boun
nvd
CVE-2026-20213P3HIGHCVSS 7.5v7.0.5v6.2.19+144 more2026-07-01
CVE-2026-20213 [HIGH] CWE-120 CVE-2026-20213: A vulnerability in the PE file format parser of ClamAV could allow an unauthenticated, remote attack A vulnerability in the PE file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PE files during scanning, which may result in an out-of-bounds
nvd
CVE-2026-20243P3HIGHCVSS 7.5v7.0.5v6.2.19+144 more2026-07-01
CVE-2026-20243 [HIGH] CWE-120 CVE-2026-20243: A vulnerability in the ALZ file format parser of ClamAV could allow an unauthenticated, remote attac A vulnerability in the ALZ file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in ALZ files during scanning, which may result in an out-of-boun
nvd
CVE-2026-20217P3HIGHCVSS 7.5v7.0.5v6.2.19+144 more2026-07-01
CVE-2026-20217 [HIGH] CWE-120 CVE-2026-20217: A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote at A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PESpin files during scanning, which may result in an out-o
nvd
CVE-2026-20244P3HIGHCVSS 7.5v7.0.5v6.2.19+144 more2026-07-01
CVE-2026-20244 [HIGH] CWE-120 CVE-2026-20244: A vulnerability in the DMG file format parser of ClamAV could allow an unauthenticated, remote attac A vulnerability in the DMG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in DMG files during scanning, which may result in an integer ove
nvd
CVE-2026-20215P3HIGHCVSS 7.5v7.0.5v6.2.19+144 more2026-07-01
CVE-2026-20215 [HIGH] CWE-120 CVE-2026-20215: A vulnerability in the 7z file format parser of ClamAV could allow an unauthenticated, remote attack A vulnerability in the 7z file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in 7z files during scanning, which may result in an out-of-bounds
nvd
CVE-2025-20128P3HIGHCVSS 7.5v7.0.5v6.2.19+53 more2025-01-22
CVE-2025-20128 [HIGH] CWE-122 CVE-2025-20128: A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allo A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an integer underflow in a bounds check that allows for a heap buffer overflow read. An attacker could exploit this vu
nvd
CVE-2023-20212P3HIGHCVSS 7.5vN/A2023-08-18
CVE-2023-20212 [HIGH] CWE-825 CVE-2023-20212: A vulnerability in the AutoIt module of ClamAV could allow an unauthenticated, remote attacker to ca A vulnerability in the AutoIt module of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a logic error in the memory management of an affected device. An attacker could exploit this vulnerability by submitting a crafted AutoIt file to be scanned by C
nvd
CVE-2023-20197P3HIGHCVSS 7.5v6.0.9v6.0.7+45 more2023-08-16
CVE-2023-20197 [HIGH] CWE-835 CVE-2023-20197: A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV co A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for completion when a file is decompressed, which may result in a loop condition that could
nvd
CVE-2025-20234P3HIGHCVSS 7.5v7.0.5v6.2.19+72 more2025-06-18
CVE-2025-20234 [HIGH] CWE-125 CVE-2025-20234: A vulnerability in Universal Disk Format (UDF) processing of ClamAV could allow an unauthenticated, A vulnerability in Universal Disk Format (UDF) processing of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a memory overread during UDF file scanning. An attacker could exploit this vulnerability by submitting a crafted file containing UDF content
nvd
CVE-2023-20052P3MEDIUMCVSS 5.3v6.0.9v6.0.7+44 more2023-03-01
CVE-2023-20052 [MEDIUM] CWE-611 CVE-2023-20052: On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vu On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to access sensitive information on an affected device. This vulnerability is due to enabling XM
nvd
CVE-2026-20031P4MEDIUMCVSS 5.3v7.0.5v6.2.19+160 more2026-03-04
CVE-2026-20031 [MEDIUM] CWE-248 CVE-2026-20031: A vulnerability in the HTML Cascading Style Sheets (CSS) module of ClamAV could allow an unauthentic A vulnerability in the HTML Cascading Style Sheets (CSS) module of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error handling when splitting UTF-8 strings. An attacker could exploit this vulnerability by submitting a crafted HTML fil
nvd
CVE-2023-20084P4MEDIUMCVSS 4.4v6.0.9v6.0.7+31 more2023-11-22
CVE-2023-20084 [MEDIUM] CWE-437 CVE-2023-20084: A vulnerability in the endpoint software of Cisco Secure Endpoint for Windows could allow an authent A vulnerability in the endpoint software of Cisco Secure Endpoint for Windows could allow an authenticated, local attacker to evade endpoint protection within a limited time window. This vulnerability is due to a timing issue that occurs between various software components. An attacker could exploit this vulnerability by persuading a user to put a m
nvd
Cisco Secure Endpoint vulnerabilities | cvebase