Vulnerabilities > Clam Anti Virus > Clamav > 0.65

DATE CVE VULNERABILITY TITLE RISK
2008-11-13 CVE-2008-5050 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Clam Anti-Virus Clamav
Off-by-one error in the get_unicode_name function (libclamav/vba_extract.c) in Clam Anti-Virus (ClamAV) before 0.94.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted VBA project file, which triggers a heap-based buffer overflow.
network
clam-anti-virus CWE-119
critical
9.3
2008-09-04 CVE-2008-1389 Resource Management Errors vulnerability in Clam Anti-Virus Clamav
libclamav/chmunpack.c in the chm-parser in ClamAV before 0.94 allows remote attackers to cause a denial of service (application crash) via a malformed CHM file, related to an "invalid memory access."
network
low complexity
clam-anti-virus CWE-399
5.0
2008-06-16 CVE-2008-2713 Resource Management Errors vulnerability in Clam Anti-Virus Clamav
libclamav/petite.c in ClamAV before 0.93.1 allows remote attackers to cause a denial of service via a crafted Petite file that triggers an out-of-bounds read.
network
low complexity
clam-anti-virus CWE-399
5.0
2008-04-16 CVE-2008-1837 Resource Management Errors vulnerability in Clam Anti-Virus Clamav
libclamunrar in ClamAV before 0.93 allows remote attackers to cause a denial of service (crash) via crafted RAR files that trigger "memory problems," as demonstrated by the PROTOS GENOME test suite for Archive Formats.
network
low complexity
clam-anti-virus CWE-399
5.0
2008-04-16 CVE-2008-1835 Improper Input Validation vulnerability in Clam Anti-Virus Clamav
ClamAV before 0.93 allows remote attackers to bypass the scanning enging via a RAR file with an invalid version number, which cannot be parsed by ClamAV but can be extracted by Winrar.
network
low complexity
clam-anti-virus CWE-20
5.0
2007-07-12 CVE-2007-3725 Unspecified vulnerability in Clam Anti-Virus Clamav
The RAR VM (unrarvm.c) in Clam Antivirus (ClamAV) before 0.91 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted RAR archive, resulting in a NULL pointer dereference.
network
clam-anti-virus
4.3
2007-02-16 CVE-2007-0898 Path Traversal vulnerability in Clam Anti-Virus Clamav
Directory traversal vulnerability in clamd in Clam AntiVirus ClamAV before 0.90 allows remote attackers to overwrite arbitrary files via a ..
network
low complexity
clam-anti-virus CWE-22
6.4
2006-10-16 CVE-2006-5295 Denial Of Service vulnerability in Clam Anti-Virus CHM Unpacker
Unspecified vulnerability in ClamAV before 0.88.5 allows remote attackers to cause a denial of service (scanning service crash) via a crafted Compressed HTML Help (CHM) file that causes ClamAV to "read an invalid memory location." This vulnerability is addressed in the following product release: Clam Anti-Virus, ClamAV, 0.88.5
network
low complexity
clam-anti-virus
5.0
2006-10-16 CVE-2006-4182 Buffer Overflow vulnerability in Clam Anti-Virus PE Rebuilding Heap
Integer overflow in ClamAV 0.88.1 and 0.88.4, and other versions before 0.88.5, allows remote attackers to cause a denial of service (scanning service crash) and execute arbitrary code via a crafted Portable Executable (PE) file that leads to a heap-based buffer overflow when less memory is allocated than expected.
network
low complexity
clam-anti-virus
7.5
2006-04-06 CVE-2006-1630 Multiple vulnerability in Clam AntiVirus ClamAV
The cli_bitset_set function in libclamav/others.c in Clam AntiVirus (ClamAV) before 0.88.1 allows remote attackers to cause a denial of service via unspecified vectors that trigger an "invalid memory access."
network
low complexity
clam-anti-virus
5.0