Show filters
21 Total Results
Displaying 11-20 of 21
Sort by:
Attacker Value
Unknown

CVE-2010-0098

Disclosure Date: April 08, 2010 (last updated October 04, 2023)
ClamAV before 0.96 does not properly handle the (1) CAB and (2) 7z file formats, which allows remote attackers to bypass virus detection via a crafted archive that is compatible with standard archive utilities.
0
Attacker Value
Unknown

CVE-2010-1311

Disclosure Date: April 08, 2010 (last updated October 04, 2023)
The qtm_decompress function in libclamav/mspack.c in ClamAV before 0.96 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted CAB archive that uses the Quantum (aka .Q) compression format. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-6845

Disclosure Date: July 02, 2009 (last updated October 04, 2023)
The unpack feature in ClamAV 0.93.3 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a corrupted LZH file.
0
Attacker Value
Unknown

CVE-2009-1372

Disclosure Date: April 23, 2009 (last updated October 04, 2023)
Stack-based buffer overflow in the cli_url_canon function in libclamav/phishcheck.c in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted URL.
0
Attacker Value
Unknown

CVE-2009-1371

Disclosure Date: April 23, 2009 (last updated October 04, 2023)
The CLI_ISCONTAINED macro in libclamav/others.h in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) via a malformed file with UPack encoding.
0
Attacker Value
Unknown

CVE-2008-6680

Disclosure Date: April 08, 2009 (last updated October 04, 2023)
libclamav/pe.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (crash) via a crafted EXE file that triggers a divide-by-zero error.
0
Attacker Value
Unknown

CVE-2008-5525

Disclosure Date: December 12, 2008 (last updated October 04, 2023)
ClamAV 0.94.1 and possibly 0.93.1, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
0
Attacker Value
Unknown

CVE-2008-5314

Disclosure Date: December 03, 2008 (last updated October 04, 2023)
Stack consumption vulnerability in libclamav/special.c in ClamAV before 0.94.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted JPEG file, related to the cli_check_jpeg_exploit, jpeg_check_photoshop, and jpeg_check_photoshop_8bim functions.
0
Attacker Value
Unknown

CVE-2008-5050

Disclosure Date: November 13, 2008 (last updated October 04, 2023)
Off-by-one error in the get_unicode_name function (libclamav/vba_extract.c) in Clam Anti-Virus (ClamAV) before 0.94.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted VBA project file, which triggers a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2008-1389

Disclosure Date: September 04, 2008 (last updated October 04, 2023)
libclamav/chmunpack.c in the chm-parser in ClamAV before 0.94 allows remote attackers to cause a denial of service (application crash) via a malformed CHM file, related to an "invalid memory access."
0