cbcvebase.

Debian Clamav vulnerabilities

155 known vulnerabilities affecting debian/clamav.

Total CVEs
155
CISA KEV
0
Public exploits
8
Exploited in wild
0
Severity breakdown
CRITICAL19HIGH40MEDIUM74LOW22

Vulnerabilities

Page 8 of 8
CVE-2008-3912P4MEDIUMCVSS 5.0fixed in clamav 0.94.dfsg-1 (bookworm)2008
CVE-2008-3912 [MEDIUM] CVE-2008-3912: clamav - libclamav in ClamAV before 0.94 allows attackers to cause a denial of service (N... libclamav in ClamAV before 0.94 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to an out-of-memory condition. Scope: local bookworm: resolved (fixed in 0.94.dfsg-1) bullseye: resolved (fixed in 0.94.dfsg-1) forky: resolved (fixed in 0.94.dfsg-1) sid: resolved (fixed in 0.94.dfsg-1) trixie: resolved (
debian
CVE-2005-3501P4MEDIUMCVSS 4.3fixed in clamav 0.87.1-1 (bookworm)2005
CVE-2005-3501 [MEDIUM] CVE-2005-3501: clamav - The cabd_find function in cabd.c of the libmspack library (mspack) for Clam Anti... The cabd_find function in cabd.c of the libmspack library (mspack) for Clam AntiVirus (ClamAV) before 0.87.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted CAB file that causes cabd_find to be called with a zero length. Scope: local bookworm: resolved (fixed in 0.87.1-1) bullseye: resolved (fixed in 0.87.1-1) forky: resolved (fixed
debian
CVE-2005-2070P4MEDIUMCVSS 5.0fixed in clamav 0.86.1 (bookworm)2005
CVE-2005-2070 [MEDIUM] CVE-2005-2070: clamav - The ClamAV Mail fILTER (clamav-milter) 0.84 through 0.85d, when used in Sendmail... The ClamAV Mail fILTER (clamav-milter) 0.84 through 0.85d, when used in Sendmail using long timeouts, allows remote attackers to cause a denial of service by keeping an open connection, which prevents ClamAV from reloading. Scope: local bookworm: resolved (fixed in 0.86.1) bullseye: resolved (fixed in 0.86.1) forky: resolved (fixed in 0.86.1) sid: resolved (fixed in
debian
CVE-2010-1639P4MEDIUMCVSS 4.3fixed in clamav 0.96.1+dfsg-1 (bookworm)2010
CVE-2010-1639 [MEDIUM] CVE-2010-1639: clamav - The cli_pdf function in libclamav/pdf.c in ClamAV before 0.96.1 allows remote at... The cli_pdf function in libclamav/pdf.c in ClamAV before 0.96.1 allows remote attackers to cause a denial of service (crash) via a malformed PDF file, related to an inconsistency in the calculated stream length and the real stream length. Scope: local bookworm: resolved (fixed in 0.96.1+dfsg-1) bullseye: resolved (fixed in 0.96.1+dfsg-1) forky: resolved (fixed in 0.9
debian
CVE-2005-0133P4MEDIUMCVSS 5.0fixed in clamav 0.80-0.81rc1-1 (bookworm)2005
CVE-2005-0133 [MEDIUM] CVE-2005-0133: clamav - ClamAV 0.80 and earlier allows remote attackers to cause a denial of service (cl... ClamAV 0.80 and earlier allows remote attackers to cause a denial of service (clamd daemon crash) via a ZIP file with malformed headers. Scope: local bookworm: resolved (fixed in 0.80-0.81rc1-1) bullseye: resolved (fixed in 0.80-0.81rc1-1) forky: resolved (fixed in 0.80-0.81rc1-1) sid: resolved (fixed in 0.80-0.81rc1-1) trixie: resolved (fixed in 0.80-0.81rc1-1)
debian
CVE-2007-2650P4MEDIUMCVSS 4.3fixed in clamav 0.90.2-1 (bookworm)2007
CVE-2007-2650 [MEDIUM] CVE-2007-2650: clamav - The OLE2 parser in Clam AntiVirus (ClamAV) allows remote attackers to cause a de... The OLE2 parser in Clam AntiVirus (ClamAV) allows remote attackers to cause a denial of service (resource consumption) via an OLE2 file with (1) a large property size or (2) a loop in the FAT file block chain that triggers an infinite loop, as demonstrated via a crafted DOC file. Scope: local bookworm: resolved (fixed in 0.90.2-1) bullseye: resolved (fixed in 0.90.2-
debian
CVE-2007-4510P4MEDIUMCVSS 4.3fixed in clamav 0.91.2-1~volatile1 (bookworm)2007
CVE-2007-4510 [MEDIUM] CVE-2007-4510: clamav - ClamAV before 0.91.2, as used in Kolab Server 2.0 through 2.2beta1 and other pro... ClamAV before 0.91.2, as used in Kolab Server 2.0 through 2.2beta1 and other products, allows remote attackers to cause a denial of service (application crash) via (1) a crafted RTF file, which triggers a NULL dereference in the cli_scanrtf function in libclamav/rtf.c; or (2) a crafted HTML document with a data: URI, which triggers a NULL dereference in the cli_html_
debian
CVE-2005-1922P4LOWCVSS 5.0fixed in clamav 0.86.1-1 (bookworm)2005
CVE-2005-1922 [MEDIUM] CVE-2005-1922: clamav - The MS-Expand file handling in Clam AntiVirus (ClamAV) before 0.86 allows remote... The MS-Expand file handling in Clam AntiVirus (ClamAV) before 0.86 allows remote attackers to cause a denial of service (file descriptor and memory consumption) via a crafted file that causes repeated errors in the cli_msexpand function. Scope: local bookworm: resolved (fixed in 0.86.1-1) bullseye: resolved (fixed in 0.86.1-1) forky: resolved (fixed in 0.86.1-1) sid:
debian
CVE-2005-1923P4MEDIUMCVSS 2.6fixed in clamav 0.86.1 (bookworm)2005
CVE-2005-1923 [LOW] CVE-2005-1923: clamav - The ENSURE_BITS macro in mszipd.c for Clam AntiVirus (ClamAV) 0.83, and other ve... The ENSURE_BITS macro in mszipd.c for Clam AntiVirus (ClamAV) 0.83, and other versions vefore 0.86, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a cabinet (CAB) file with the cffile_FolderOffset field set to 0xff, which causes a zero-length read. Scope: local bookworm: resolved (fixed in 0.86.1) bullseye: resolved (fixed in
debian
CVE-2004-1909P4LOWCVSS 2.6fixed in clamav 0.68.1 (bookworm)2004
CVE-2004-1909 [LOW] CVE-2004-1909: clamav - Claim Anti-Virus (ClamAV) 0.68 and earlier allows remote attackers to cause a de... Claim Anti-Virus (ClamAV) 0.68 and earlier allows remote attackers to cause a denial of service (crash) via certain RAR archives, such as those generated by the Beagle/Bagle worm. Scope: local bookworm: resolved (fixed in 0.68.1) bullseye: resolved (fixed in 0.68.1) forky: resolved (fixed in 0.68.1) sid: resolved (fixed in 0.68.1) trixie: resolved (fixed in 0.68.1)
debian
CVE-2013-6497P4LOWCVSS 2.1fixed in clamav 0.98.5+dfsg-1 (bookworm)2013
CVE-2013-6497 [LOW] CVE-2013-6497: clamav - clamscan in ClamAV before 0.98.5, when using -a option, allows remote attackers ... clamscan in ClamAV before 0.98.5, when using -a option, allows remote attackers to cause a denial of service (crash) as demonstrated by the jwplayer.js file. Scope: local bookworm: resolved (fixed in 0.98.5+dfsg-1) bullseye: resolved (fixed in 0.98.5+dfsg-1) forky: resolved (fixed in 0.98.5+dfsg-1) sid: resolved (fixed in 0.98.5+dfsg-1) trixie: resolved (fixed in 0.98.5
debian
CVE-2018-0361P4LOWCVSS 3.3fixed in clamav 0.100.1+dfsg-1 (bookworm)2018
CVE-2018-0361 [LOW] CVE-2018-0361: clamav - ClamAV before 0.100.1 lacks a PDF object length check, resulting in an unreasona... ClamAV before 0.100.1 lacks a PDF object length check, resulting in an unreasonably long time to parse a relatively small file. Scope: local bookworm: resolved (fixed in 0.100.1+dfsg-1) bullseye: resolved (fixed in 0.100.1+dfsg-1) forky: resolved (fixed in 0.100.1+dfsg-1) sid: resolved (fixed in 0.100.1+dfsg-1) trixie: resolved (fixed in 0.100.1+dfsg-1)
debian
CVE-2007-6595P4LOWCVSS 2.1fixed in clamav 0.92.1~dfsg-1 (bookworm)2007
CVE-2007-6595 [LOW] CVE-2007-6595: clamav - ClamAV 0.92 allows local users to overwrite arbitrary files via a symlink attack... ClamAV 0.92 allows local users to overwrite arbitrary files via a symlink attack on (1) temporary files used by the cli_gentempfd function in libclamav/others.c or on (2) .ascii files used by sigtool, when utf16-decode is enabled. Scope: local bookworm: resolved (fixed in 0.92.1~dfsg-1) bullseye: resolved (fixed in 0.92.1~dfsg-1) forky: resolved (fixed in 0.92.1~dfsg-1)
debian
CVE-2005-2056P4MEDIUMCVSS 2.6fixed in clamav 0.86.1-1 (bookworm)2005
CVE-2005-2056 [LOW] CVE-2005-2056: clamav - The Quantum archive decompressor in Clam AntiVirus (ClamAV) before 0.86.1 allows... The Quantum archive decompressor in Clam AntiVirus (ClamAV) before 0.86.1 allows remote attackers to cause a denial of service (application crash) via a crafted Quantum archive. Scope: local bookworm: resolved (fixed in 0.86.1-1) bullseye: resolved (fixed in 0.86.1-1) forky: resolved (fixed in 0.86.1-1) sid: resolved (fixed in 0.86.1-1) trixie: resolved (fixed in 0.86.1
debian
CVE-2007-3024P4LOWCVSS 2.1fixed in clamav 0.90.3-1 (bookworm)2007
CVE-2007-3024 [LOW] CVE-2007-3024: clamav - libclamav/others.c in ClamAV before 0.90.3 and 0.91 before 0.91rc1 uses insecure... libclamav/others.c in ClamAV before 0.90.3 and 0.91 before 0.91rc1 uses insecure permissions for temporary files that are created by the cli_gentempstream function in clamd/clamdscan, which might allow local users to read sensitive files. Scope: local bookworm: resolved (fixed in 0.90.3-1) bullseye: resolved (fixed in 0.90.3-1) forky: resolved (fixed in 0.90.3-1) sid: r
debian
Debian Clamav vulnerabilities | cvebase