Debian Clamav vulnerabilities
155 known vulnerabilities affecting debian/clamav.
Total CVEs
155
CISA KEV
0
Public exploits
8
Exploited in wild
0
Severity breakdown
CRITICAL19HIGH40MEDIUM74LOW22
Vulnerabilities
Page 7 of 8
CVE-2017-11423P4LOWCVSS 5.5fixed in clamav 0.99.3~beta1+dfsg-1 (bookworm)2017
CVE-2017-11423 [MEDIUM] CVE-2017-11423: clamav - The cabd_read_string function in mspack/cabd.c in libmspack 0.5alpha, as used in...
The cabd_read_string function in mspack/cabd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2 and other products, allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted CAB file.
Scope: local
bookworm: resolved (fixed in 0.99.3~beta1+dfsg-1)
bullseye: resolved (fixed in 0.99.3~beta1+dfsg-1)
forky: re
debian
CVE-2018-15378P4MEDIUMCVSS 5.5fixed in clamav 0.100.2+dfsg-1 (bookworm)2018
CVE-2018-15378 [MEDIUM] CVE-2018-15378: clamav - A vulnerability in ClamAV versions prior to 0.100.2 could allow an attacker to c...
A vulnerability in ClamAV versions prior to 0.100.2 could allow an attacker to cause a denial of service (DoS) condition. The vulnerability is due to an error related to the MEW unpacker within the "unmew11()" function (libclamav/mew.c), which can be exploited to trigger an invalid read memory access via a specially crafted EXE file.
Scope: local
bookworm: resolved
debian
CVE-2011-3627P4LOWCVSS 4.3fixed in clamav 0.97.3+dfsg-1 (bookworm)2011
CVE-2011-3627 [MEDIUM] CVE-2011-3627: clamav - The bytecode engine in ClamAV before 0.97.3 allows remote attackers to cause a d...
The bytecode engine in ClamAV before 0.97.3 allows remote attackers to cause a denial of service (crash) via vectors related to "recursion level" and (1) libclamav/bytecode.c and (2) libclamav/bytecode_api.c.
Scope: local
bookworm: resolved (fixed in 0.97.3+dfsg-1)
bullseye: resolved (fixed in 0.97.3+dfsg-1)
forky: resolved (fixed in 0.97.3+dfsg-1)
sid: resolved (fix
debian
CVE-2006-6481P4LOWCVSS 5.0fixed in clamav 0.88.7-1 (bookworm)2006
CVE-2006-6481 [MEDIUM] CVE-2006-6481: clamav - Clam AntiVirus (ClamAV) 0.88.6 allows remote attackers to cause a denial of serv...
Clam AntiVirus (ClamAV) 0.88.6 allows remote attackers to cause a denial of service (stack overflow and application crash) by wrapping many layers of multipart/mixed content around a document, a different vulnerability than CVE-2006-5874 and CVE-2006-6406.
Scope: local
bookworm: resolved (fixed in 0.88.7-1)
bullseye: resolved (fixed in 0.88.7-1)
forky: resolved (fixe
debian
CVE-2008-3913P4MEDIUMCVSS 5.0fixed in clamav 0.94.dfsg-1 (bookworm)2008
CVE-2008-3913 [MEDIUM] CVE-2008-3913: clamav - Multiple memory leaks in freshclam/manager.c in ClamAV before 0.94 might allow a...
Multiple memory leaks in freshclam/manager.c in ClamAV before 0.94 might allow attackers to cause a denial of service (memory consumption) via unspecified vectors related to "error handling logic".
Scope: local
bookworm: resolved (fixed in 0.94.dfsg-1)
bullseye: resolved (fixed in 0.94.dfsg-1)
forky: resolved (fixed in 0.94.dfsg-1)
sid: resolved (fixed in 0.94.dfsg-1
debian
CVE-2017-6418P4MEDIUMCVSS 5.5fixed in clamav 0.99.3~beta1+dfsg-1 (bookworm)2017
CVE-2017-6418 [MEDIUM] CVE-2017-6418: clamav - libclamav/message.c in ClamAV 0.99.2 allows remote attackers to cause a denial o...
libclamav/message.c in ClamAV 0.99.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted e-mail message.
Scope: local
bookworm: resolved (fixed in 0.99.3~beta1+dfsg-1)
bullseye: resolved (fixed in 0.99.3~beta1+dfsg-1)
forky: resolved (fixed in 0.99.3~beta1+dfsg-1)
sid: resolved (fixed in 0.99.3~beta1+dfsg-1)
trixie: resolved (fixed
debian
CVE-2015-1463P4MEDIUMCVSS 5.0fixed in clamav 0.98.6+dfsg-1 (bookworm)2015
CVE-2015-1463 [MEDIUM] CVE-2015-1463: clamav - ClamAV before 0.98.6 allows remote attackers to cause a denial of service (crash...
ClamAV before 0.98.6 allows remote attackers to cause a denial of service (crash) via a crafted petite packer file, related to an "incorrect compiler optimization."
Scope: local
bookworm: resolved (fixed in 0.98.6+dfsg-1)
bullseye: resolved (fixed in 0.98.6+dfsg-1)
forky: resolved (fixed in 0.98.6+dfsg-1)
sid: resolved (fixed in 0.98.6+dfsg-1)
trixie: resolved (fixed
debian
CVE-2013-2021P4MEDIUMCVSS 4.3fixed in clamav 0.97.8+dfsg-1 (bookworm)2013
CVE-2013-2021 [MEDIUM] CVE-2013-2021: clamav - pdf.c in ClamAV 0.97.1 through 0.97.7 allows remote attackers to cause a denial ...
pdf.c in ClamAV 0.97.1 through 0.97.7 allows remote attackers to cause a denial of service (out-of-bounds-read) via a crafted length value in an encrypted PDF file.
Scope: local
bookworm: resolved (fixed in 0.97.8+dfsg-1)
bullseye: resolved (fixed in 0.97.8+dfsg-1)
forky: resolved (fixed in 0.97.8+dfsg-1)
sid: resolved (fixed in 0.97.8+dfsg-1)
trixie: resolved (fixed
debian
CVE-2010-1640P4MEDIUMCVSS 4.3fixed in clamav 0.96.1+dfsg-1 (bookworm)2010
CVE-2010-1640 [MEDIUM] CVE-2010-1640: clamav - Off-by-one error in the parseicon function in libclamav/pe_icons.c in ClamAV 0.9...
Off-by-one error in the parseicon function in libclamav/pe_icons.c in ClamAV 0.96 allows remote attackers to cause a denial of service (crash) via a crafted PE icon that triggers an out-of-bounds read, related to improper rounding during scaling.
Scope: local
bookworm: resolved (fixed in 0.96.1+dfsg-1)
bullseye: resolved (fixed in 0.96.1+dfsg-1)
forky: resolved (fixe
debian
CVE-2004-1876P4MEDIUMCVSS 4.6fixed in clamav 0.70-1 (bookworm)2004
CVE-2004-1876 [MEDIUM] CVE-2004-1876: clamav - The "%f" feature in the VirusEvent directive in Clam AntiVirus daemon (clamd) be...
The "%f" feature in the VirusEvent directive in Clam AntiVirus daemon (clamd) before 0.70 allows local users to execute arbitrary commands via shell metacharacters in a file name.
Scope: local
bookworm: resolved (fixed in 0.70-1)
bullseye: resolved (fixed in 0.70-1)
forky: resolved (fixed in 0.70-1)
sid: resolved (fixed in 0.70-1)
trixie: resolved (fixed in 0.70-1)
debian
CVE-2008-6680P4MEDIUMCVSS 5.0fixed in clamav 0.95.1+dfsg-1 (bookworm)2008
CVE-2008-6680 [MEDIUM] CVE-2008-6680: clamav - libclamav/pe.c in ClamAV before 0.95 allows remote attackers to cause a denial o...
libclamav/pe.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (crash) via a crafted EXE file that triggers a divide-by-zero error.
Scope: local
bookworm: resolved (fixed in 0.95.1+dfsg-1)
bullseye: resolved (fixed in 0.95.1+dfsg-1)
forky: resolved (fixed in 0.95.1+dfsg-1)
sid: resolved (fixed in 0.95.1+dfsg-1)
trixie: resolved (fixed in 0.
debian
CVE-2005-2919P4MEDIUMCVSS 5.0fixed in clamav 0.87-1 (bookworm)2005
CVE-2005-2919 [MEDIUM] CVE-2005-2919: clamav - libclamav/fsg.c in Clam AntiVirus (ClamAV) before 0.87 allows remote attackers t...
libclamav/fsg.c in Clam AntiVirus (ClamAV) before 0.87 allows remote attackers to cause a denial of service (infinite loop) via a crafted FSG packed executable.
Scope: local
bookworm: resolved (fixed in 0.87-1)
bullseye: resolved (fixed in 0.87-1)
forky: resolved (fixed in 0.87-1)
sid: resolved (fixed in 0.87-1)
trixie: resolved (fixed in 0.87-1)
debian
CVE-2016-1372P4MEDIUMCVSS 5.5fixed in clamav 0.99.2+dfsg-1 (bookworm)2016
CVE-2016-1372 [MEDIUM] CVE-2016-1372: clamav - ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a den...
ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted 7z file.
Scope: local
bookworm: resolved (fixed in 0.99.2+dfsg-1)
bullseye: resolved (fixed in 0.99.2+dfsg-1)
forky: resolved (fixed in 0.99.2+dfsg-1)
sid: resolved (fixed in 0.99.2+dfsg-1)
trixie: resolved (fixed in 0.99.2+dfsg-1)
debian
CVE-2008-1387P4MEDIUMCVSS 4.3fixed in clamav 0.92.1~dfsg2-1 (bookworm)2008
CVE-2008-1387 [MEDIUM] CVE-2008-1387: clamav - ClamAV before 0.93 allows remote attackers to cause a denial of service (CPU con...
ClamAV before 0.93 allows remote attackers to cause a denial of service (CPU consumption) via a crafted ARJ archive, as demonstrated by the PROTOS GENOME test suite for Archive Formats.
Scope: local
bookworm: resolved (fixed in 0.92.1~dfsg2-1)
bullseye: resolved (fixed in 0.92.1~dfsg2-1)
forky: resolved (fixed in 0.92.1~dfsg2-1)
sid: resolved (fixed in 0.92.1~dfsg2-1
debian
CVE-2008-6845P4MEDIUMCVSS 5.0fixed in clamav 0.94.dfsg-1 (bookworm)2008
CVE-2008-6845 [MEDIUM] CVE-2008-6845: clamav - The unpack feature in ClamAV 0.93.3 and earlier allows remote attackers to cause...
The unpack feature in ClamAV 0.93.3 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a corrupted LZH file.
Scope: local
bookworm: resolved (fixed in 0.94.dfsg-1)
bullseye: resolved (fixed in 0.94.dfsg-1)
forky: resolved (fixed in 0.94.dfsg-1)
sid: resolved (fixed in 0.94.dfsg-1)
trixie: resolved (fixed in 0.94.dfsg-1)
debian
CVE-2005-3500P4MEDIUMCVSS 5.0fixed in clamav 0.87.1-1 (bookworm)2005
CVE-2005-3500 [MEDIUM] CVE-2005-3500: clamav - The tnef_attachment function in tnef.c for Clam AntiVirus (ClamAV) before 0.87.1...
The tnef_attachment function in tnef.c for Clam AntiVirus (ClamAV) before 0.87.1 allows remote attackers to cause a denial of service (infinite loop and memory exhaustion) via a crafted value in a CAB file that causes ClamAV to repeatedly scan the same block.
Scope: local
bookworm: resolved (fixed in 0.87.1-1)
bullseye: resolved (fixed in 0.87.1-1)
forky: resolved (f
debian
CVE-2009-1371P4MEDIUMCVSS 5.0fixed in clamav 0.95.1+dfsg-1 (bookworm)2009
CVE-2009-1371 [MEDIUM] CVE-2009-1371: clamav - The CLI_ISCONTAINED macro in libclamav/others.h in ClamAV before 0.95.1 allows r...
The CLI_ISCONTAINED macro in libclamav/others.h in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) via a malformed file with UPack encoding.
Scope: local
bookworm: resolved (fixed in 0.95.1+dfsg-1)
bullseye: resolved (fixed in 0.95.1+dfsg-1)
forky: resolved (fixed in 0.95.1+dfsg-1)
sid: resolved (fixed in 0.95.1+dfsg-1)
t
debian
CVE-2008-1389P4MEDIUMCVSS 5.0fixed in clamav 0.94.dfsg-1 (bookworm)2008
CVE-2008-1389 [MEDIUM] CVE-2008-1389: clamav - libclamav/chmunpack.c in the chm-parser in ClamAV before 0.94 allows remote atta...
libclamav/chmunpack.c in the chm-parser in ClamAV before 0.94 allows remote attackers to cause a denial of service (application crash) via a malformed CHM file, related to an "invalid memory access."
Scope: local
bookworm: resolved (fixed in 0.94.dfsg-1)
bullseye: resolved (fixed in 0.94.dfsg-1)
forky: resolved (fixed in 0.94.dfsg-1)
sid: resolved (fixed in 0.94.dfsg
debian
CVE-2016-1371P4MEDIUMCVSS 5.5fixed in clamav 0.99.2+dfsg-1 (bookworm)2016
CVE-2016-1371 [MEDIUM] CVE-2016-1371: clamav - ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a den...
ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted mew packer executable.
Scope: local
bookworm: resolved (fixed in 0.99.2+dfsg-1)
bullseye: resolved (fixed in 0.99.2+dfsg-1)
forky: resolved (fixed in 0.99.2+dfsg-1)
sid: resolved (fixed in 0.99.2+dfsg-1)
trixie: resolved (fixed in 0.99.2+df
debian
CVE-2006-5874P4MEDIUMCVSS 5.0fixed in clamav 0.86-1 (bookworm)2006
CVE-2006-5874 [MEDIUM] CVE-2006-5874: clamav - Clam AntiVirus (ClamAV) 0.88 and earlier allows remote attackers to cause a deni...
Clam AntiVirus (ClamAV) 0.88 and earlier allows remote attackers to cause a denial of service (crash) via a malformed base64-encoded MIME attachment that triggers a null pointer dereference.
Scope: local
bookworm: resolved (fixed in 0.86-1)
bullseye: resolved (fixed in 0.86-1)
forky: resolved (fixed in 0.86-1)
sid: resolved (fixed in 0.86-1)
trixie: resolved (fixed i
debian