Debian Clamav vulnerabilities
155 known vulnerabilities affecting debian/clamav.
Total CVEs
155
CISA KEV
0
Public exploits
8
Exploited in wild
0
Severity breakdown
CRITICAL19HIGH40MEDIUM74LOW22
Vulnerabilities
Page 3 of 8
CVE-2022-20698P3HIGHCVSS 7.5fixed in clamav 0.103.5+dfsg-1 (bookworm)2022
CVE-2022-20698 [HIGH] CVE-2022-20698: clamav - A vulnerability in the OOXML parsing module in Clam AntiVirus (ClamAV) Software ...
A vulnerability in the OOXML parsing module in Clam AntiVirus (ClamAV) Software version 0.104.1 and LTS version 0.103.4 and prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper checks that may result in an invalid pointer read. An attacker could exploit this v
debian
CVE-2021-1252P3HIGHCVSS 7.5fixed in clamav 0.103.2+dfsg-1 (bookworm)2021
CVE-2021-1252 [HIGH] CVE-2021-1252: clamav - A vulnerability in the Excel XLM macro parsing module in Clam AntiVirus (ClamAV)...
A vulnerability in the Excel XLM macro parsing module in Clam AntiVirus (ClamAV) Software versions 0.103.0 and 0.103.1 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper error handling that may result in an infinite loop. An attacker could exploit this vulnerability by sendi
debian
CVE-2021-1404P3HIGHCVSS 7.5fixed in clamav 0.103.2+dfsg-1 (bookworm)2021
CVE-2021-1404 [HIGH] CVE-2021-1404: clamav - A vulnerability in the PDF parsing module in Clam AntiVirus (ClamAV) Software ve...
A vulnerability in the PDF parsing module in Clam AntiVirus (ClamAV) Software versions 0.103.0 and 0.103.1 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper buffer size tracking that may result in a heap buffer over-read. An attacker could exploit this vulnerability by send
debian
CVE-2007-0899P3CRITICALCVSS 9.8fixed in clamav 0.90-1 (bookworm)2007
CVE-2007-0899 [CRITICAL] CVE-2007-0899: clamav - There is a possible heap overflow in libclamav/fsg.c before 0.100.0.
There is a possible heap overflow in libclamav/fsg.c before 0.100.0.
Scope: local
bookworm: resolved (fixed in 0.90-1)
bullseye: resolved (fixed in 0.90-1)
forky: resolved (fixed in 0.90-1)
sid: resolved (fixed in 0.90-1)
trixie: resolved (fixed in 0.90-1)
debian
CVE-2023-20197P3HIGHCVSS 7.5fixed in clamav 1.0.2+dfsg-1~deb12u1 (bookworm)2023
CVE-2023-20197 [HIGH] CVE-2023-20197: clamav - A vulnerability in the filesystem image parser for Hierarchical File System Plus...
A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for completion when a file is decompressed, which may result in a loop condition that could cause the affec
debian
CVE-2008-5314P4MEDIUMCVSS 4.3PoCfixed in clamav 0.94.dfsg.2-1 (bookworm)2008
CVE-2008-5314 [MEDIUM] CVE-2008-5314: clamav - Stack consumption vulnerability in libclamav/special.c in ClamAV before 0.94.2 a...
Stack consumption vulnerability in libclamav/special.c in ClamAV before 0.94.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted JPEG file, related to the cli_check_jpeg_exploit, jpeg_check_photoshop, and jpeg_check_photoshop_8bim functions.
Scope: local
bookworm: resolved (fixed in 0.94.dfsg.2-1)
bullseye: resolved (fixed in 0.94.dfsg
debian
CVE-2020-3481P3HIGHCVSS 7.5fixed in clamav 0.102.4+dfsg-1 (bookworm)2020
CVE-2020-3481 [HIGH] CVE-2020-3481: clamav - A vulnerability in the EGG archive parsing module in Clam AntiVirus (ClamAV) Sof...
A vulnerability in the EGG archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.0 - 0.102.3 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a null pointer dereference. An attacker could exploit this vulnerability by sending a crafted EGG file to an affected de
debian
CVE-2020-3123P3HIGHCVSS 7.5fixed in clamav 0.102.2+dfsg-1 (bookworm)2020
CVE-2020-3123 [HIGH] CVE-2020-3123: clamav - A vulnerability in the Data-Loss-Prevention (DLP) module in Clam AntiVirus (Clam...
A vulnerability in the Data-Loss-Prevention (DLP) module in Clam AntiVirus (ClamAV) Software versions 0.102.1 and 0.102.0 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to an out-of-bounds read affecting users that have enabled the optional DLP feature. An attacker could exploit thi
debian
CVE-2019-1785P3HIGHCVSS 7.8fixed in clamav 0.101.2+dfsg-1 (bookworm)2019
CVE-2019-1785 [HIGH] CVE-2019-1785: clamav - A vulnerability in the RAR file scanning functionality of Clam AntiVirus (ClamAV...
A vulnerability in the RAR file scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and 0.101.0 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a lack of proper error-handling mechanisms when processing nested RAR files sent to an affected device. An attack
debian
CVE-2025-20234P3LOWCVSS 5.3fixed in clamav 1.4.3+dfsg-1 (forky)2025
CVE-2025-20234 [MEDIUM] CVE-2025-20234: clamav - A vulnerability in Universal Disk Format (UDF) processing of ClamAV could allow ...
A vulnerability in Universal Disk Format (UDF) processing of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a memory overread during UDF file scanning. An attacker could exploit this vulnerability by submitting a crafted file containing UDF content to be scanned
debian
CVE-2010-3434P3CRITICALCVSS 9.3fixed in clamav 0.96.3+dfsg-1 (bookworm)2010
CVE-2010-3434 [CRITICAL] CVE-2010-3434: clamav - Buffer overflow in the find_stream_bounds function in pdf.c in libclamav in Clam...
Buffer overflow in the find_stream_bounds function in pdf.c in libclamav in ClamAV before 0.96.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document. NOTE: some of these details are obtained from third party information.
Scope: local
bookworm: resolved (fixed in 0.96.3+dfsg-1)
bullse
debian
CVE-2006-0162P3HIGHCVSS 7.5fixed in clamav 0.88-1 (bookworm)2006
CVE-2006-0162 [HIGH] CVE-2006-0162: clamav - Heap-based buffer overflow in libclamav/upx.c in Clam Antivirus (ClamAV) before ...
Heap-based buffer overflow in libclamav/upx.c in Clam Antivirus (ClamAV) before 0.88 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted UPX files.
Scope: local
bookworm: resolved (fixed in 0.88-1)
bullseye: resolved (fixed in 0.88-1)
forky: resolved (fixed in 0.88-1)
sid: resolved (fixed in 0.88-1)
trixie: resol
debian
CVE-2019-12625P3HIGHCVSS 7.5fixed in clamav 0.101.4+dfsg-1 (bookworm)2019
CVE-2019-12625 [HIGH] CVE-2019-12625: clamav - ClamAV versions prior to 0.101.3 are susceptible to a zip bomb vulnerability whe...
ClamAV versions prior to 0.101.3 are susceptible to a zip bomb vulnerability where an unauthenticated attacker can cause a denial of service condition by sending crafted messages to an affected system.
Scope: local
bookworm: resolved (fixed in 0.101.4+dfsg-1)
bullseye: resolved (fixed in 0.101.4+dfsg-1)
forky: resolved (fixed in 0.101.4+dfsg-1)
sid: resolved (fixed i
debian
CVE-2024-20505P3MEDIUMCVSS 4.0fixed in clamav 1.0.7+dfsg-1~deb12u1 (bookworm)2024
CVE-2024-20505 [MEDIUM] CVE-2024-20505: clamav - A vulnerability in the PDF parsing module of Clam AntiVirus (ClamAV) versions 1....
A vulnerability in the PDF parsing module of Clam AntiVirus (ClamAV) versions 1.4.0, 1.3.2 and prior versions, all 1.2.x versions, 1.0.6 and prior versions, all 0.105.x versions, all 0.104.x versions, and 0.103.11 and all prior versions could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerabil
debian
CVE-2016-1405P3HIGHCVSS 7.5fixed in clamav 0.99+dfsg-1 (bookworm)2016
CVE-2016-1405 [HIGH] CVE-2016-1405: clamav - libclamav in ClamAV (aka Clam AntiVirus), as used in Advanced Malware Protection...
libclamav in ClamAV (aka Clam AntiVirus), as used in Advanced Malware Protection (AMP) on Cisco Email Security Appliance (ESA) devices before 9.7.0-125 and Web Security Appliance (WSA) devices before 9.0.1-135 and 9.1.x before 9.1.1-041, allows remote attackers to cause a denial of service (AMP process restart) via a crafted document, aka Bug IDs CSCuv78533 and CSCuw60
debian
CVE-2004-0270P4MEDIUMCVSS 5.0PoCfixed in clamav 0.80 (bookworm)2004
CVE-2004-0270 [MEDIUM] CVE-2004-0270: clamav - libclamav in Clam AntiVirus 0.65 allows remote attackers to cause a denial of se...
libclamav in Clam AntiVirus 0.65 allows remote attackers to cause a denial of service (crash) via a uuencoded e-mail message with an invalid line length (e.g., a lowercase character), which causes an assert error in clamd that terminates the calling program.
Scope: local
bookworm: resolved (fixed in 0.80)
bullseye: resolved (fixed in 0.80)
forky: resolved (fixed in 0
debian
CVE-2007-1997P3HIGHCVSS 7.5fixed in clamav 0.90.2-1 (bookworm)2007
CVE-2007-1997 [HIGH] CVE-2007-1997: clamav - Integer signedness error in the (1) cab_unstore and (2) cab_extract functions in...
Integer signedness error in the (1) cab_unstore and (2) cab_extract functions in libclamav/cab.c in Clam AntiVirus (ClamAV) before 0.90.2 allow remote attackers to execute arbitrary code via a crafted CHM file that contains a negative integer, which passes a signed comparison and leads to a stack-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 0.90.2-1
debian
CVE-2014-9328P3HIGHCVSS 7.5fixed in clamav 0.98.6+dfsg-1 (bookworm)2014
CVE-2014-9328 [HIGH] CVE-2014-9328: clamav - ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a cr...
ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted upack packer file, related to a "heap out of bounds condition."
Scope: local
bookworm: resolved (fixed in 0.98.6+dfsg-1)
bullseye: resolved (fixed in 0.98.6+dfsg-1)
forky: resolved (fixed in 0.98.6+dfsg-1)
sid: resolved (fixed in 0.98.6+dfsg-1)
trixie: resolved (fixed in 0.98.6+dfsg-1
debian
CVE-2005-2920P3MEDIUMCVSS 7.5fixed in clamav 0.87-1 (bookworm)2005
CVE-2005-2920 [HIGH] CVE-2005-2920: clamav - Buffer overflow in libclamav/upx.c in Clam AntiVirus (ClamAV) before 0.87 allows...
Buffer overflow in libclamav/upx.c in Clam AntiVirus (ClamAV) before 0.87 allows remote attackers to execute arbitrary code via a crafted UPX packed executable.
Scope: local
bookworm: resolved (fixed in 0.87-1)
bullseye: resolved (fixed in 0.87-1)
forky: resolved (fixed in 0.87-1)
sid: resolved (fixed in 0.87-1)
trixie: resolved (fixed in 0.87-1)
debian
CVE-2022-20792P3HIGHCVSS 7.8fixed in clamav 0.103.6+dfsg-1 (bookworm)2022
CVE-2022-20792 [HIGH] CVE-2022-20792: clamav - A vulnerability in the regex module used by the signature database load module o...
A vulnerability in the regex module used by the signature database load module of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior versions could allow an authenticated, local attacker to crash ClamAV at database load time, and possibly gain code execution. The vulnerability is due to improper bounds checking that may result
debian