Debian Clamav vulnerabilities
155 known vulnerabilities affecting debian/clamav.
Total CVEs
155
CISA KEV
0
Public exploits
8
Exploited in wild
0
Severity breakdown
CRITICAL19HIGH40MEDIUM74LOW22
Vulnerabilities
Page 5 of 8
CVE-2007-0898P4MEDIUMCVSS 6.4fixed in clamav 0.90-1 (bookworm)2007
CVE-2007-0898 [MEDIUM] CVE-2007-0898: clamav - Directory traversal vulnerability in clamd in Clam AntiVirus ClamAV before 0.90 ...
Directory traversal vulnerability in clamd in Clam AntiVirus ClamAV before 0.90 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the id MIME header parameter in a multi-part message.
Scope: local
bookworm: resolved (fixed in 0.90-1)
bullseye: resolved (fixed in 0.90-1)
forky: resolved (fixed in 0.90-1)
sid: resolved (fixed in 0.90-1)
trixie:
debian
CVE-2006-1614P4MEDIUMCVSS 5.1fixed in clamav 0.88.1-1 (bookworm)2006
CVE-2006-1614 [MEDIUM] CVE-2006-1614: clamav - Integer overflow in the cli_scanpe function in the PE header parser (libclamav/p...
Integer overflow in the cli_scanpe function in the PE header parser (libclamav/pe.c) in Clam AntiVirus (ClamAV) before 0.88.1, when ArchiveMaxFileSize is disabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code.
Scope: local
bookworm: resolved (fixed in 0.88.1-1)
bullseye: resolved (fixed in 0.88.1-1)
forky: resolved (fixed i
debian
CVE-2009-1270P4MEDIUMCVSS 7.8fixed in clamav 0.95.1+dfsg-1 (bookworm)2009
CVE-2009-1270 [HIGH] CVE-2009-1270: clamav - libclamav/untar.c in ClamAV before 0.95 allows remote attackers to cause a denia...
libclamav/untar.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (infinite loop) via a crafted TAR file that causes (1) clamd and (2) clamscan to hang.
Scope: local
bookworm: resolved (fixed in 0.95.1+dfsg-1)
bullseye: resolved (fixed in 0.95.1+dfsg-1)
forky: resolved (fixed in 0.95.1+dfsg-1)
sid: resolved (fixed in 0.95.1+dfsg-1)
trixie: re
debian
CVE-2024-20506P4MEDIUMCVSS 6.1fixed in clamav 1.0.7+dfsg-1~deb12u1 (bookworm)2024
CVE-2024-20506 [MEDIUM] CVE-2024-20506: clamav - A vulnerability in the ClamD service module of Clam AntiVirus (ClamAV) versions ...
A vulnerability in the ClamD service module of Clam AntiVirus (ClamAV) versions 1.4.0, 1.3.2 and prior versions, all 1.2.x versions, 1.0.6 and prior versions, all 0.105.x versions, all 0.104.x versions, and 0.103.11 and all prior versions could allow an authenticated, local attacker to corrupt critical system files. The vulnerability is due to allowing the ClamD pr
debian
CVE-2007-6596P4LOWCVSS 5.0fixed in clamav 0.92.1~dfsg-1 (bookworm)2007
CVE-2007-6596 [MEDIUM] CVE-2007-6596: clamav - ClamAV 0.92 does not recognize Base64 UUEncoded archives, which allows remote at...
ClamAV 0.92 does not recognize Base64 UUEncoded archives, which allows remote attackers to bypass the scanner via a Base64-UUEncoded file.
Scope: local
bookworm: resolved (fixed in 0.92.1~dfsg-1)
bullseye: resolved (fixed in 0.92.1~dfsg-1)
forky: resolved (fixed in 0.92.1~dfsg-1)
sid: resolved (fixed in 0.92.1~dfsg-1)
trixie: resolved (fixed in 0.92.1~dfsg-1)
debian
CVE-2006-1989P4MEDIUMCVSS 5.1fixed in clamav 0.88.2 (bookworm)2006
CVE-2006-1989 [MEDIUM] CVE-2006-1989: clamav - Buffer overflow in the get_database function in the HTTP client in Freshclam in ...
Buffer overflow in the get_database function in the HTTP client in Freshclam in ClamAV 0.80 to 0.88.1 might allow remote web servers to execute arbitrary code via long HTTP headers.
Scope: local
bookworm: resolved (fixed in 0.88.2)
bullseye: resolved (fixed in 0.88.2)
forky: resolved (fixed in 0.88.2)
sid: resolved (fixed in 0.88.2)
trixie: resolved (fixed in 0.88.2)
debian
CVE-2010-4260P4MEDIUMCVSS 5.0fixed in clamav 0.96.5+dfsg-1 (bookworm)2010
CVE-2010-4260 [MEDIUM] CVE-2010-4260: clamav - Multiple unspecified vulnerabilities in pdf.c in libclamav in ClamAV before 0.96...
Multiple unspecified vulnerabilities in pdf.c in libclamav in ClamAV before 0.96.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document, aka (1) "bb #2358" and (2) "bb #2396."
Scope: local
bookworm: resolved (fixed in 0.96.5+dfsg-1)
bullseye: resolved (fixed in 0.96.5+dfsg-1)
forky: reso
debian
CVE-2014-9050P4MEDIUMCVSS 5.0fixed in clamav 0.98.5+dfsg-1 (bookworm)2014
CVE-2014-9050 [MEDIUM] CVE-2014-9050: clamav - Heap-based buffer overflow in the cli_scanpe function in libclamav/pe.c in ClamA...
Heap-based buffer overflow in the cli_scanpe function in libclamav/pe.c in ClamAV before 0.98.5 allows remote attackers to cause a denial of service (crash) via a crafted y0da Crypter PE file.
Scope: local
bookworm: resolved (fixed in 0.98.5+dfsg-1)
bullseye: resolved (fixed in 0.98.5+dfsg-1)
forky: resolved (fixed in 0.98.5+dfsg-1)
sid: resolved (fixed in 0.98.5+dfs
debian
CVE-2003-0946P4HIGHCVSS 7.5fixed in clamav 0.65 (bookworm)2003
CVE-2003-0946 [HIGH] CVE-2003-0946: clamav - Format string vulnerability in clamav-milter for Clam AntiVirus 0.60 through 0.6...
Format string vulnerability in clamav-milter for Clam AntiVirus 0.60 through 0.60p, and other versions before 0.65, allows remote attackers to cause a denial of service and possibly execute arbitrary code via format string specifiers in the email address argument of a "MAIL FROM" command.
Scope: local
bookworm: resolved (fixed in 0.65)
bullseye: resolved (fixed in 0.65
debian
CVE-2007-0897P4HIGHCVSS 7.5fixed in clamav 0.90-1 (bookworm)2007
CVE-2007-0897 [HIGH] CVE-2007-0897: clamav - Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under cer...
Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, which allows remote attackers to cause a denial of service (file descriptor consumption and failed scans) via CAB archives with a cabinet header record length of zero, which causes a function to return without closing a file descriptor.
Scope: local
bookworm: resolved (fixe
debian
CVE-2010-0405P4MEDIUMCVSS 5.1fixed in bzip2 1.0.5-6 (bookworm)2010
CVE-2010-0405 [MEDIUM] CVE-2010-0405: bzip2 - Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and lib...
Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 before 1.0.6 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted compressed file.
Scope: local
bookworm: resolved (fixed in 1.0.5-6)
bullseye: resolved (fixed in 1.0.5-6)
forky: resolved (fixed in 1.0.5-
debian
CVE-2018-0202P4MEDIUMCVSS 5.5fixed in clamav 0.100.0~beta+dfsg-2 (bookworm)2018
CVE-2018-0202 [MEDIUM] CVE-2018-0202: clamav - clamscan in ClamAV before 0.99.4 contains a vulnerability that could allow an un...
clamscan in ClamAV before 0.99.4 contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation checking mechanisms when handling Portable Document Format (.pdf) files sent to an affected device. An unauthenticated, remote attacker
debian
CVE-2019-1788P4MEDIUMCVSS 5.5fixed in clamav 0.101.2+dfsg-1 (bookworm)2019
CVE-2019-1788 [MEDIUM] CVE-2019-1788: clamav - A vulnerability in the Object Linking & Embedding (OLE2) file scanning functiona...
A vulnerability in the Object Linking & Embedding (OLE2) file scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a lack of proper input and validation checking mechanisms for OLE2 files sent an af
debian
CVE-2005-3239P4MEDIUMCVSS 7.8fixed in clamav 0.87.1-1 (bookworm)2005
CVE-2005-3239 [HIGH] CVE-2005-3239: clamav - The OLE2 unpacker in clamd in Clam AntiVirus (ClamAV) 0.87-1 allows remote attac...
The OLE2 unpacker in clamd in Clam AntiVirus (ClamAV) 0.87-1 allows remote attackers to cause a denial of service (segmentation fault) via a DOC file with an invalid property tree, which triggers an infinite recursion in the ole2_walk_property_tree function.
Scope: local
bookworm: resolved (fixed in 0.87.1-1)
bullseye: resolved (fixed in 0.87.1-1)
forky: resolved (fixe
debian
CVE-2017-12378P4MEDIUMCVSS 5.5fixed in clamav 0.99.3~beta2+dfsg-1 (bookworm)2017
CVE-2017-12378 [MEDIUM] CVE-2017-12378: clamav - ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that...
ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation checking mechanisms of .tar (Tape Archive) files sent to an affected device. A successful exploit could cause a chec
debian
CVE-2007-2029P4LOWCVSS 7.8fixed in clamav 0.90.2-1 (bookworm)2007
CVE-2007-2029 [HIGH] CVE-2007-2029: clamav - File descriptor leak in the PDF handler in Clam AntiVirus (ClamAV) allows remote...
File descriptor leak in the PDF handler in Clam AntiVirus (ClamAV) allows remote attackers to cause a denial of service via a crafted PDF file.
Scope: local
bookworm: resolved (fixed in 0.90.2-1)
bullseye: resolved (fixed in 0.90.2-1)
forky: resolved (fixed in 0.90.2-1)
sid: resolved (fixed in 0.90.2-1)
trixie: resolved (fixed in 0.90.2-1)
debian
CVE-2006-6406P4MEDIUMCVSS 5.0fixed in clamav 0.88.7-1 (bookworm)2006
CVE-2006-6406 [MEDIUM] CVE-2006-6406: clamav - Clam AntiVirus (ClamAV) 0.88.6 allows remote attackers to bypass virus detection...
Clam AntiVirus (ClamAV) 0.88.6 allows remote attackers to bypass virus detection by inserting invalid characters into base64 encoded content in a multipart/mixed MIME file, as demonstrated with the EICAR test file.
Scope: local
bookworm: resolved (fixed in 0.88.7-1)
bullseye: resolved (fixed in 0.88.7-1)
forky: resolved (fixed in 0.88.7-1)
sid: resolved (fixed in 0.8
debian
CVE-2019-1787P4MEDIUMCVSS 5.5fixed in clamav 0.101.2+dfsg-1 (bookworm)2019
CVE-2019-1787 [MEDIUM] CVE-2019-1787: clamav - A vulnerability in the Portable Document Format (PDF) scanning functionality of ...
A vulnerability in the Portable Document Format (PDF) scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a lack of proper data handling mechanisms within the device buffer while indexing rem
debian
CVE-2005-3587P4MEDIUMCVSS 10.0fixed in clamav 0.87.1-1 (bookworm)2005
CVE-2005-3587 [CRITICAL] CVE-2005-3587: clamav - Improper boundary checks in petite.c in Clam AntiVirus (ClamAV) before 0.87.1 al...
Improper boundary checks in petite.c in Clam AntiVirus (ClamAV) before 0.87.1 allows attackers to perform unknown attacks via unknown vectors.
Scope: local
bookworm: resolved (fixed in 0.87.1-1)
bullseye: resolved (fixed in 0.87.1-1)
forky: resolved (fixed in 0.87.1-1)
sid: resolved (fixed in 0.87.1-1)
trixie: resolved (fixed in 0.87.1-1)
debian
CVE-2005-0218P4MEDIUMCVSS 5.0fixed in clamav 0.81 (bookworm)2005
CVE-2005-0218 [MEDIUM] CVE-2005-0218: clamav - ClamAV 0.80 and earlier allows remote attackers to bypass virus scanning via a b...
ClamAV 0.80 and earlier allows remote attackers to bypass virus scanning via a base64 encoded image in a data: (RFC 2397) URL.
Scope: local
bookworm: resolved (fixed in 0.81)
bullseye: resolved (fixed in 0.81)
forky: resolved (fixed in 0.81)
sid: resolved (fixed in 0.81)
trixie: resolved (fixed in 0.81)
debian