cbcvebase.

Debian Clamav vulnerabilities

155 known vulnerabilities affecting debian/clamav.

Total CVEs
155
CISA KEV
0
Public exploits
8
Exploited in wild
0
Severity breakdown
CRITICAL19HIGH40MEDIUM74LOW22

Vulnerabilities

Page 7 of 8
CVE-2017-11423P4LOWCVSS 5.5fixed in clamav 0.99.3~beta1+dfsg-1 (bookworm)2017
CVE-2017-11423 [MEDIUM] CVE-2017-11423: clamav - The cabd_read_string function in mspack/cabd.c in libmspack 0.5alpha, as used in... The cabd_read_string function in mspack/cabd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2 and other products, allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted CAB file. Scope: local bookworm: resolved (fixed in 0.99.3~beta1+dfsg-1) bullseye: resolved (fixed in 0.99.3~beta1+dfsg-1) forky: re
debian
CVE-2018-15378P4MEDIUMCVSS 5.5fixed in clamav 0.100.2+dfsg-1 (bookworm)2018
CVE-2018-15378 [MEDIUM] CVE-2018-15378: clamav - A vulnerability in ClamAV versions prior to 0.100.2 could allow an attacker to c... A vulnerability in ClamAV versions prior to 0.100.2 could allow an attacker to cause a denial of service (DoS) condition. The vulnerability is due to an error related to the MEW unpacker within the "unmew11()" function (libclamav/mew.c), which can be exploited to trigger an invalid read memory access via a specially crafted EXE file. Scope: local bookworm: resolved
debian
CVE-2011-3627P4LOWCVSS 4.3fixed in clamav 0.97.3+dfsg-1 (bookworm)2011
CVE-2011-3627 [MEDIUM] CVE-2011-3627: clamav - The bytecode engine in ClamAV before 0.97.3 allows remote attackers to cause a d... The bytecode engine in ClamAV before 0.97.3 allows remote attackers to cause a denial of service (crash) via vectors related to "recursion level" and (1) libclamav/bytecode.c and (2) libclamav/bytecode_api.c. Scope: local bookworm: resolved (fixed in 0.97.3+dfsg-1) bullseye: resolved (fixed in 0.97.3+dfsg-1) forky: resolved (fixed in 0.97.3+dfsg-1) sid: resolved (fix
debian
CVE-2006-6481P4LOWCVSS 5.0fixed in clamav 0.88.7-1 (bookworm)2006
CVE-2006-6481 [MEDIUM] CVE-2006-6481: clamav - Clam AntiVirus (ClamAV) 0.88.6 allows remote attackers to cause a denial of serv... Clam AntiVirus (ClamAV) 0.88.6 allows remote attackers to cause a denial of service (stack overflow and application crash) by wrapping many layers of multipart/mixed content around a document, a different vulnerability than CVE-2006-5874 and CVE-2006-6406. Scope: local bookworm: resolved (fixed in 0.88.7-1) bullseye: resolved (fixed in 0.88.7-1) forky: resolved (fixe
debian
CVE-2008-3913P4MEDIUMCVSS 5.0fixed in clamav 0.94.dfsg-1 (bookworm)2008
CVE-2008-3913 [MEDIUM] CVE-2008-3913: clamav - Multiple memory leaks in freshclam/manager.c in ClamAV before 0.94 might allow a... Multiple memory leaks in freshclam/manager.c in ClamAV before 0.94 might allow attackers to cause a denial of service (memory consumption) via unspecified vectors related to "error handling logic". Scope: local bookworm: resolved (fixed in 0.94.dfsg-1) bullseye: resolved (fixed in 0.94.dfsg-1) forky: resolved (fixed in 0.94.dfsg-1) sid: resolved (fixed in 0.94.dfsg-1
debian
CVE-2017-6418P4MEDIUMCVSS 5.5fixed in clamav 0.99.3~beta1+dfsg-1 (bookworm)2017
CVE-2017-6418 [MEDIUM] CVE-2017-6418: clamav - libclamav/message.c in ClamAV 0.99.2 allows remote attackers to cause a denial o... libclamav/message.c in ClamAV 0.99.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted e-mail message. Scope: local bookworm: resolved (fixed in 0.99.3~beta1+dfsg-1) bullseye: resolved (fixed in 0.99.3~beta1+dfsg-1) forky: resolved (fixed in 0.99.3~beta1+dfsg-1) sid: resolved (fixed in 0.99.3~beta1+dfsg-1) trixie: resolved (fixed
debian
CVE-2015-1463P4MEDIUMCVSS 5.0fixed in clamav 0.98.6+dfsg-1 (bookworm)2015
CVE-2015-1463 [MEDIUM] CVE-2015-1463: clamav - ClamAV before 0.98.6 allows remote attackers to cause a denial of service (crash... ClamAV before 0.98.6 allows remote attackers to cause a denial of service (crash) via a crafted petite packer file, related to an "incorrect compiler optimization." Scope: local bookworm: resolved (fixed in 0.98.6+dfsg-1) bullseye: resolved (fixed in 0.98.6+dfsg-1) forky: resolved (fixed in 0.98.6+dfsg-1) sid: resolved (fixed in 0.98.6+dfsg-1) trixie: resolved (fixed
debian
CVE-2013-2021P4MEDIUMCVSS 4.3fixed in clamav 0.97.8+dfsg-1 (bookworm)2013
CVE-2013-2021 [MEDIUM] CVE-2013-2021: clamav - pdf.c in ClamAV 0.97.1 through 0.97.7 allows remote attackers to cause a denial ... pdf.c in ClamAV 0.97.1 through 0.97.7 allows remote attackers to cause a denial of service (out-of-bounds-read) via a crafted length value in an encrypted PDF file. Scope: local bookworm: resolved (fixed in 0.97.8+dfsg-1) bullseye: resolved (fixed in 0.97.8+dfsg-1) forky: resolved (fixed in 0.97.8+dfsg-1) sid: resolved (fixed in 0.97.8+dfsg-1) trixie: resolved (fixed
debian
CVE-2010-1640P4MEDIUMCVSS 4.3fixed in clamav 0.96.1+dfsg-1 (bookworm)2010
CVE-2010-1640 [MEDIUM] CVE-2010-1640: clamav - Off-by-one error in the parseicon function in libclamav/pe_icons.c in ClamAV 0.9... Off-by-one error in the parseicon function in libclamav/pe_icons.c in ClamAV 0.96 allows remote attackers to cause a denial of service (crash) via a crafted PE icon that triggers an out-of-bounds read, related to improper rounding during scaling. Scope: local bookworm: resolved (fixed in 0.96.1+dfsg-1) bullseye: resolved (fixed in 0.96.1+dfsg-1) forky: resolved (fixe
debian
CVE-2004-1876P4MEDIUMCVSS 4.6fixed in clamav 0.70-1 (bookworm)2004
CVE-2004-1876 [MEDIUM] CVE-2004-1876: clamav - The "%f" feature in the VirusEvent directive in Clam AntiVirus daemon (clamd) be... The "%f" feature in the VirusEvent directive in Clam AntiVirus daemon (clamd) before 0.70 allows local users to execute arbitrary commands via shell metacharacters in a file name. Scope: local bookworm: resolved (fixed in 0.70-1) bullseye: resolved (fixed in 0.70-1) forky: resolved (fixed in 0.70-1) sid: resolved (fixed in 0.70-1) trixie: resolved (fixed in 0.70-1)
debian
CVE-2008-6680P4MEDIUMCVSS 5.0fixed in clamav 0.95.1+dfsg-1 (bookworm)2008
CVE-2008-6680 [MEDIUM] CVE-2008-6680: clamav - libclamav/pe.c in ClamAV before 0.95 allows remote attackers to cause a denial o... libclamav/pe.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (crash) via a crafted EXE file that triggers a divide-by-zero error. Scope: local bookworm: resolved (fixed in 0.95.1+dfsg-1) bullseye: resolved (fixed in 0.95.1+dfsg-1) forky: resolved (fixed in 0.95.1+dfsg-1) sid: resolved (fixed in 0.95.1+dfsg-1) trixie: resolved (fixed in 0.
debian
CVE-2005-2919P4MEDIUMCVSS 5.0fixed in clamav 0.87-1 (bookworm)2005
CVE-2005-2919 [MEDIUM] CVE-2005-2919: clamav - libclamav/fsg.c in Clam AntiVirus (ClamAV) before 0.87 allows remote attackers t... libclamav/fsg.c in Clam AntiVirus (ClamAV) before 0.87 allows remote attackers to cause a denial of service (infinite loop) via a crafted FSG packed executable. Scope: local bookworm: resolved (fixed in 0.87-1) bullseye: resolved (fixed in 0.87-1) forky: resolved (fixed in 0.87-1) sid: resolved (fixed in 0.87-1) trixie: resolved (fixed in 0.87-1)
debian
CVE-2016-1372P4MEDIUMCVSS 5.5fixed in clamav 0.99.2+dfsg-1 (bookworm)2016
CVE-2016-1372 [MEDIUM] CVE-2016-1372: clamav - ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a den... ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted 7z file. Scope: local bookworm: resolved (fixed in 0.99.2+dfsg-1) bullseye: resolved (fixed in 0.99.2+dfsg-1) forky: resolved (fixed in 0.99.2+dfsg-1) sid: resolved (fixed in 0.99.2+dfsg-1) trixie: resolved (fixed in 0.99.2+dfsg-1)
debian
CVE-2008-1387P4MEDIUMCVSS 4.3fixed in clamav 0.92.1~dfsg2-1 (bookworm)2008
CVE-2008-1387 [MEDIUM] CVE-2008-1387: clamav - ClamAV before 0.93 allows remote attackers to cause a denial of service (CPU con... ClamAV before 0.93 allows remote attackers to cause a denial of service (CPU consumption) via a crafted ARJ archive, as demonstrated by the PROTOS GENOME test suite for Archive Formats. Scope: local bookworm: resolved (fixed in 0.92.1~dfsg2-1) bullseye: resolved (fixed in 0.92.1~dfsg2-1) forky: resolved (fixed in 0.92.1~dfsg2-1) sid: resolved (fixed in 0.92.1~dfsg2-1
debian
CVE-2008-6845P4MEDIUMCVSS 5.0fixed in clamav 0.94.dfsg-1 (bookworm)2008
CVE-2008-6845 [MEDIUM] CVE-2008-6845: clamav - The unpack feature in ClamAV 0.93.3 and earlier allows remote attackers to cause... The unpack feature in ClamAV 0.93.3 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a corrupted LZH file. Scope: local bookworm: resolved (fixed in 0.94.dfsg-1) bullseye: resolved (fixed in 0.94.dfsg-1) forky: resolved (fixed in 0.94.dfsg-1) sid: resolved (fixed in 0.94.dfsg-1) trixie: resolved (fixed in 0.94.dfsg-1)
debian
CVE-2005-3500P4MEDIUMCVSS 5.0fixed in clamav 0.87.1-1 (bookworm)2005
CVE-2005-3500 [MEDIUM] CVE-2005-3500: clamav - The tnef_attachment function in tnef.c for Clam AntiVirus (ClamAV) before 0.87.1... The tnef_attachment function in tnef.c for Clam AntiVirus (ClamAV) before 0.87.1 allows remote attackers to cause a denial of service (infinite loop and memory exhaustion) via a crafted value in a CAB file that causes ClamAV to repeatedly scan the same block. Scope: local bookworm: resolved (fixed in 0.87.1-1) bullseye: resolved (fixed in 0.87.1-1) forky: resolved (f
debian
CVE-2009-1371P4MEDIUMCVSS 5.0fixed in clamav 0.95.1+dfsg-1 (bookworm)2009
CVE-2009-1371 [MEDIUM] CVE-2009-1371: clamav - The CLI_ISCONTAINED macro in libclamav/others.h in ClamAV before 0.95.1 allows r... The CLI_ISCONTAINED macro in libclamav/others.h in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) via a malformed file with UPack encoding. Scope: local bookworm: resolved (fixed in 0.95.1+dfsg-1) bullseye: resolved (fixed in 0.95.1+dfsg-1) forky: resolved (fixed in 0.95.1+dfsg-1) sid: resolved (fixed in 0.95.1+dfsg-1) t
debian
CVE-2008-1389P4MEDIUMCVSS 5.0fixed in clamav 0.94.dfsg-1 (bookworm)2008
CVE-2008-1389 [MEDIUM] CVE-2008-1389: clamav - libclamav/chmunpack.c in the chm-parser in ClamAV before 0.94 allows remote atta... libclamav/chmunpack.c in the chm-parser in ClamAV before 0.94 allows remote attackers to cause a denial of service (application crash) via a malformed CHM file, related to an "invalid memory access." Scope: local bookworm: resolved (fixed in 0.94.dfsg-1) bullseye: resolved (fixed in 0.94.dfsg-1) forky: resolved (fixed in 0.94.dfsg-1) sid: resolved (fixed in 0.94.dfsg
debian
CVE-2016-1371P4MEDIUMCVSS 5.5fixed in clamav 0.99.2+dfsg-1 (bookworm)2016
CVE-2016-1371 [MEDIUM] CVE-2016-1371: clamav - ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a den... ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted mew packer executable. Scope: local bookworm: resolved (fixed in 0.99.2+dfsg-1) bullseye: resolved (fixed in 0.99.2+dfsg-1) forky: resolved (fixed in 0.99.2+dfsg-1) sid: resolved (fixed in 0.99.2+dfsg-1) trixie: resolved (fixed in 0.99.2+df
debian
CVE-2006-5874P4MEDIUMCVSS 5.0fixed in clamav 0.86-1 (bookworm)2006
CVE-2006-5874 [MEDIUM] CVE-2006-5874: clamav - Clam AntiVirus (ClamAV) 0.88 and earlier allows remote attackers to cause a deni... Clam AntiVirus (ClamAV) 0.88 and earlier allows remote attackers to cause a denial of service (crash) via a malformed base64-encoded MIME attachment that triggers a null pointer dereference. Scope: local bookworm: resolved (fixed in 0.86-1) bullseye: resolved (fixed in 0.86-1) forky: resolved (fixed in 0.86-1) sid: resolved (fixed in 0.86-1) trixie: resolved (fixed i
debian
Debian Clamav vulnerabilities | cvebase