cbcvebase.

Debian Clamav vulnerabilities

155 known vulnerabilities affecting debian/clamav.

Total CVEs
155
CISA KEV
0
Public exploits
8
Exploited in wild
0
Severity breakdown
CRITICAL19HIGH40MEDIUM74LOW22

Vulnerabilities

Page 4 of 8
CVE-2007-3725P4MEDIUMCVSS 4.3PoCfixed in clamav 0.91-1 (bookworm)2007
CVE-2007-3725 [MEDIUM] CVE-2007-3725: clamav - The RAR VM (unrarvm.c) in Clam Antivirus (ClamAV) before 0.91 allows user-assist... The RAR VM (unrarvm.c) in Clam Antivirus (ClamAV) before 0.91 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted RAR archive, resulting in a NULL pointer dereference. Scope: local bookworm: resolved (fixed in 0.91-1) bullseye: resolved (fixed in 0.91-1) forky: resolved (fixed in 0.91-1) sid: resolved (fixed in 0.91-1) trixie: res
debian
CVE-2012-1419P4LOWCVSS 4.3fixed in clamav 0.97.5+dfsg-1 (bookworm)2012
CVE-2012-1419 [MEDIUM] CVE-2012-1419: clamav - The TAR file parser in ClamAV 0.96.4 and Quick Heal (aka Cat QuickHeal) 11.00 al... The TAR file parser in ClamAV 0.96.4 and Quick Heal (aka Cat QuickHeal) 11.00 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial [aliases] character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementation
debian
CVE-2015-1461P3HIGHCVSS 7.5fixed in clamav 0.98.6+dfsg-1 (bookworm)2015
CVE-2015-1461 [HIGH] CVE-2015-1461: clamav - ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a cr... ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted (1) Yoda's crypter or (2) mew packer file, related to a "heap out of bounds condition." Scope: local bookworm: resolved (fixed in 0.98.6+dfsg-1) bullseye: resolved (fixed in 0.98.6+dfsg-1) forky: resolved (fixed in 0.98.6+dfsg-1) sid: resolved (fixed in 0.98.6+dfsg-1) trixie: resolved
debian
CVE-2015-1462P3HIGHCVSS 7.5fixed in clamav 0.98.6+dfsg-1 (bookworm)2015
CVE-2015-1462 [HIGH] CVE-2015-1462: clamav - ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a cr... ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted upx packer file, related to a "heap out of bounds condition." Scope: local bookworm: resolved (fixed in 0.98.6+dfsg-1) bullseye: resolved (fixed in 0.98.6+dfsg-1) forky: resolved (fixed in 0.98.6+dfsg-1) sid: resolved (fixed in 0.98.6+dfsg-1) trixie: resolved (fixed in 0.98.6+dfsg-1)
debian
CVE-2023-20052P3MEDIUMCVSS 5.3fixed in clamav 1.0.1+dfsg-1 (bookworm)2023
CVE-2023-20052 [MEDIUM] CVE-2023-20052: clamav - On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was ... On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to access sensitive information on an affected device. This vulnerability is due to enabling XML entity su
debian
CVE-2019-1789P3HIGHCVSS 7.5fixed in clamav 0.101.2+dfsg-1 (bookworm)2019
CVE-2019-1789 [HIGH] CVE-2019-1789: clamav - ClamAV versions prior to 0.101.2 are susceptible to a denial of service (DoS) vu... ClamAV versions prior to 0.101.2 are susceptible to a denial of service (DoS) vulnerability. An out-of-bounds heap read condition may occur when scanning PE files. An example is Windows EXE and DLL files that have been packed using Aspack as a result of inadequate bound-checking. Scope: local bookworm: resolved (fixed in 0.101.2+dfsg-1) bullseye: resolved (fixed in 0.1
debian
CVE-2005-3303P3HIGHCVSS 7.5fixed in clamav 0.87.1-1 (bookworm)2005
CVE-2005-3303 [HIGH] CVE-2005-3303: clamav - The FSG unpacker (fsg.c) in Clam AntiVirus (ClamAV) 0.80 through 0.87 allows rem... The FSG unpacker (fsg.c) in Clam AntiVirus (ClamAV) 0.80 through 0.87 allows remote attackers to cause "memory corruption" and execute arbitrary code via a crafted FSG 1.33 file. Scope: local bookworm: resolved (fixed in 0.87.1-1) bullseye: resolved (fixed in 0.87.1-1) forky: resolved (fixed in 0.87.1-1) sid: resolved (fixed in 0.87.1-1) trixie: resolved (fixed in 0.87
debian
CVE-2008-3914P4CRITICALCVSS 10.0fixed in clamav 0.94.dfsg-1 (bookworm)2008
CVE-2008-3914 [CRITICAL] CVE-2008-3914: clamav - Multiple unspecified vulnerabilities in ClamAV before 0.94 have unknown impact a... Multiple unspecified vulnerabilities in ClamAV before 0.94 have unknown impact and attack vectors related to file descriptor leaks on the "error path" in (1) libclamav/others.c and (2) libclamav/sis.c. Scope: local bookworm: resolved (fixed in 0.94.dfsg-1) bullseye: resolved (fixed in 0.94.dfsg-1) forky: resolved (fixed in 0.94.dfsg-1) sid: resolved (fixed in 0.94.
debian
CVE-2007-3023P4CRITICALCVSS 10.0fixed in clamav 0.90.3-1 (bookworm)2007
CVE-2007-3023 [CRITICAL] CVE-2007-3023: clamav - unsp.c in ClamAV before 0.90.3 and 0.91 before 0.91rc1 does not properly calcula... unsp.c in ClamAV before 0.90.3 and 0.91 before 0.91rc1 does not properly calculate the end of a certain buffer, with unknown impact and remote attack vectors. Scope: local bookworm: resolved (fixed in 0.90.3-1) bullseye: resolved (fixed in 0.90.3-1) forky: resolved (fixed in 0.90.3-1) sid: resolved (fixed in 0.90.3-1) trixie: resolved (fixed in 0.90.3-1)
debian
CVE-2011-1003P3LOWCVSS 6.8fixed in clamav 0.97+dfsg-1 (bookworm)2011
CVE-2011-1003 [MEDIUM] CVE-2011-1003: clamav - Double free vulnerability in the vba_read_project_strings function in vba_extrac... Double free vulnerability in the vba_read_project_strings function in vba_extract.c in libclamav in ClamAV before 0.97 might allow remote attackers to execute arbitrary code via crafted Visual Basic for Applications (VBA) data in a Microsoft Office document. NOTE: some of these details are obtained from third party information. Scope: local bookworm: resolved (fixed
debian
CVE-2010-4261P3HIGHCVSS 7.5fixed in clamav 0.96.5+dfsg-1 (bookworm)2010
CVE-2010-4261 [HIGH] CVE-2010-4261: clamav - Off-by-one error in the icon_cb function in pe_icons.c in libclamav in ClamAV be... Off-by-one error in the icon_cb function in pe_icons.c in libclamav in ClamAV before 0.96.5 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors. NOTE: some of these details are obtained from third party information. Scope: local bookworm: resolved (fixed in 0.96.5+dfsg
debian
CVE-2010-4479P3MEDIUMCVSS 5.0fixed in clamav 0.96.5+dfsg-1 (bookworm)2010
CVE-2010-4479 [MEDIUM] CVE-2010-4479: clamav - Unspecified vulnerability in pdf.c in libclamav in ClamAV before 0.96.5 allows r... Unspecified vulnerability in pdf.c in libclamav in ClamAV before 0.96.5 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document, aka "bb #2380," a different vulnerability than CVE-2010-4260. Scope: local bookworm: resolved (fixed in 0.96.5+dfsg-1) bullseye: resolved (fixed in 0.96.5+dfsg-1
debian
CVE-2019-15961P4HIGHCVSS 7.5fixed in clamav 0.102.1+dfsg-1 (bookworm)2019
CVE-2019-15961 [HIGH] CVE-2019-15961: clamav - A vulnerability in the email parsing module Clam AntiVirus (ClamAV) Software ver... A vulnerability in the email parsing module Clam AntiVirus (ClamAV) Software versions 0.102.0, 0.101.4 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to inefficient MIME parsing routines that result in extremely long scan times of specially formatted email files. An atta
debian
CVE-2007-6336P3MEDIUMCVSS 6.8fixed in clamav 0.92~dfsg-1~volatile2 (bookworm)2007
CVE-2007-6336 [MEDIUM] CVE-2007-6336: clamav - Off-by-one error in ClamAV before 0.92 allows remote attackers to execute arbitr... Off-by-one error in ClamAV before 0.92 allows remote attackers to execute arbitrary code via a crafted MS-ZIP compressed CAB file. Scope: local bookworm: resolved (fixed in 0.92~dfsg-1~volatile2) bullseye: resolved (fixed in 0.92~dfsg-1~volatile2) forky: resolved (fixed in 0.92~dfsg-1~volatile2) sid: resolved (fixed in 0.92~dfsg-1~volatile2) trixie: resolved (fixed i
debian
CVE-2013-7089P4HIGHCVSS 7.5fixed in clamav 0.97.7+dfsg-1 (bookworm)2013
CVE-2013-7089 [HIGH] CVE-2013-7089: clamav - ClamAV before 0.97.7: dbg_printhex possible information leak ClamAV before 0.97.7: dbg_printhex possible information leak Scope: local bookworm: resolved (fixed in 0.97.7+dfsg-1) bullseye: resolved (fixed in 0.97.7+dfsg-1) forky: resolved (fixed in 0.97.7+dfsg-1) sid: resolved (fixed in 0.97.7+dfsg-1) trixie: resolved (fixed in 0.97.7+dfsg-1)
debian
CVE-2005-2450P4MEDIUMCVSS 7.5fixed in clamav 0.86.2-1 (bookworm)2005
CVE-2005-2450 [HIGH] CVE-2005-2450: clamav - Multiple integer overflows in the (1) TNEF, (2) CHM, or (3) FSG file format proc... Multiple integer overflows in the (1) TNEF, (2) CHM, or (3) FSG file format processors in libclamav for Clam AntiVirus (ClamAV) 0.86.1 and earlier allow remote attackers to gain privileges via a crafted e-mail message. Scope: local bookworm: resolved (fixed in 0.86.2-1) bullseye: resolved (fixed in 0.86.2-1) forky: resolved (fixed in 0.86.2-1) sid: resolved (fixed in 0
debian
CVE-2017-6419P4LOWCVSS 7.8fixed in clamav 0.99.3~beta1+dfsg-1 (bookworm)2017
CVE-2017-6419 [HIGH] CVE-2017-6419: clamav - mspack/lzxd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2, allows remote att... mspack/lzxd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted CHM file. Scope: local bookworm: resolved (fixed in 0.99.3~beta1+dfsg-1) bullseye: resolved (fixed in 0.99.3~beta1+dfsg-1) forky: resolved (fixed in
debian
CVE-2020-3350P4MEDIUMCVSS 5.5fixed in clamav 0.102.4+dfsg-1 (bookworm)2020
CVE-2020-3350 [MEDIUM] CVE-2020-3350: clamav - A vulnerability in the endpoint software of Cisco AMP for Endpoints and Clam Ant... A vulnerability in the endpoint software of Cisco AMP for Endpoints and Clam AntiVirus could allow an authenticated, local attacker to cause the running software to delete arbitrary files on the system. The vulnerability is due to a race condition that could occur when scanning malicious files. An attacker with local shell access could exploit this vulnerability by e
debian
CVE-2007-6337P4CRITICALCVSS 10.0fixed in clamav 0.92~dfsg-1~volatile2 (bookworm)2007
CVE-2007-6337 [CRITICAL] CVE-2007-6337: clamav - Unspecified vulnerability in the bzip2 decompression algorithm in nsis/bzlib_pri... Unspecified vulnerability in the bzip2 decompression algorithm in nsis/bzlib_private.h in ClamAV before 0.92 has unknown impact and remote attack vectors. Scope: local bookworm: resolved (fixed in 0.92~dfsg-1~volatile2) bullseye: resolved (fixed in 0.92~dfsg-1~volatile2) forky: resolved (fixed in 0.92~dfsg-1~volatile2) sid: resolved (fixed in 0.92~dfsg-1~volatile2)
debian
CVE-2008-0728P4CRITICALCVSS 10.0fixed in clamav 0.92.1~dfsg-1 (bookworm)2008
CVE-2008-0728 [CRITICAL] CVE-2008-0728: clamav - The unmew11 function in libclamav/mew.c in libclamav in ClamAV before 0.92.1 has... The unmew11 function in libclamav/mew.c in libclamav in ClamAV before 0.92.1 has unknown impact and attack vectors that trigger "heap corruption." Scope: local bookworm: resolved (fixed in 0.92.1~dfsg-1) bullseye: resolved (fixed in 0.92.1~dfsg-1) forky: resolved (fixed in 0.92.1~dfsg-1) sid: resolved (fixed in 0.92.1~dfsg-1) trixie: resolved (fixed in 0.92.1~dfsg-
debian
Debian Clamav vulnerabilities | cvebase