Show filters
91 Total Results
Displaying 11-20 of 91
Sort by:
Attacker Value
Unknown
CVE-2022-20698
Disclosure Date: January 13, 2022 (last updated October 07, 2023)
A vulnerability in the OOXML parsing module in Clam AntiVirus (ClamAV) Software version 0.104.1 and LTS version 0.103.4 and prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper checks that may result in an invalid pointer read. An attacker could exploit this vulnerability by sending a crafted OOXML file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process to crash, resulting in a denial of service condition.
0
Attacker Value
Unknown
CVE-2021-1404
Disclosure Date: April 08, 2021 (last updated November 28, 2024)
A vulnerability in the PDF parsing module in Clam AntiVirus (ClamAV) Software versions 0.103.0 and 0.103.1 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper buffer size tracking that may result in a heap buffer over-read. An attacker could exploit this vulnerability by sending a crafted PDF file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process to crash, resulting in a denial of service condition.
0
Attacker Value
Unknown
CVE-2021-1405
Disclosure Date: April 08, 2021 (last updated November 28, 2024)
A vulnerability in the email parsing module in Clam AntiVirus (ClamAV) Software version 0.103.1 and all prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper variable initialization that may result in an NULL pointer read. An attacker could exploit this vulnerability by sending a crafted email to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process crash, resulting in a denial of service condition.
0
Attacker Value
Unknown
CVE-2021-1252
Disclosure Date: April 08, 2021 (last updated November 28, 2024)
A vulnerability in the Excel XLM macro parsing module in Clam AntiVirus (ClamAV) Software versions 0.103.0 and 0.103.1 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper error handling that may result in an infinite loop. An attacker could exploit this vulnerability by sending a crafted Excel file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process hang, resulting in a denial of service condition.
0
Attacker Value
Unknown
CVE-2021-27506
Disclosure Date: March 19, 2021 (last updated August 21, 2024)
The ClamAV Engine (version 0.103.1 and below) component embedded in Storsmshield Network Security (SNS) is subject to DoS in case of parsing of malformed png files. This affect Netasq versions 9.1.0 to 9.1.11 and SNS versions 1.0.0 to 4.2.0. This issue is fixed in SNS 3.7.19, 3.11.7 and 4.2.1.
0
Attacker Value
Unknown
CVE-2020-3481
Disclosure Date: July 20, 2020 (last updated November 08, 2023)
A vulnerability in the EGG archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.0 - 0.102.3 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a null pointer dereference. An attacker could exploit this vulnerability by sending a crafted EGG file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process crash, resulting in a denial of service condition.
0
Attacker Value
Unknown
CVE-2020-3123
Disclosure Date: February 05, 2020 (last updated November 27, 2024)
A vulnerability in the Data-Loss-Prevention (DLP) module in Clam AntiVirus (ClamAV) Software versions 0.102.1 and 0.102.0 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to an out-of-bounds read affecting users that have enabled the optional DLP feature. An attacker could exploit this vulnerability by sending a crafted email file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process crash, resulting in a denial of service condition.
0
Attacker Value
Unknown
CVE-2013-7089
Disclosure Date: November 15, 2019 (last updated November 27, 2024)
ClamAV before 0.97.7: dbg_printhex possible information leak
0
Attacker Value
Unknown
CVE-2013-7088
Disclosure Date: November 15, 2019 (last updated November 27, 2024)
ClamAV before 0.97.7 has buffer overflow in the libclamav component
0
Attacker Value
Unknown
CVE-2013-7087
Disclosure Date: November 15, 2019 (last updated November 27, 2024)
ClamAV before 0.97.7 has WWPack corrupt heap memory
0