Vulnerabilities > Clam Anti Virus > Clamav > Critical

DATE CVE VULNERABILITY TITLE RISK
2008-11-13 CVE-2008-5050 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Clam Anti-Virus Clamav
Off-by-one error in the get_unicode_name function (libclamav/vba_extract.c) in Clam Anti-Virus (ClamAV) before 0.94.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted VBA project file, which triggers a heap-based buffer overflow.
network
clam-anti-virus CWE-119
critical
9.3
2008-04-14 CVE-2008-1100 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Clam Anti-Virus Clamav 0.92/0.92.1
Buffer overflow in the cli_scanpe function in libclamav (libclamav/pe.c) for ClamAV 0.92 and 0.92.1 allows remote attackers to execute arbitrary code via a crafted Upack PE file.
network
low complexity
clam-anti-virus CWE-119
critical
10.0
2008-02-12 CVE-2008-0318 Numeric Errors vulnerability in Clam Anti-Virus Clamav
Integer overflow in the cli_scanpe function in libclamav in ClamAV before 0.92.1, as used in clamd, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Petite packed PE file, which triggers a heap-based buffer overflow.
network
low complexity
clam-anti-virus CWE-189
critical
10.0
2007-12-31 CVE-2007-6337 Unspecified vulnerability in Clam Anti-Virus Clamav 0.91.2
Unspecified vulnerability in the bzip2 decompression algorithm in nsis/bzlib_private.h in ClamAV before 0.92 has unknown impact and remote attack vectors.
network
low complexity
gentoo clam-anti-virus
critical
10.0
2007-06-07 CVE-2007-3023 Multiple Unspecified vulnerability in ClamAV
unsp.c in ClamAV before 0.90.3 and 0.91 before 0.91rc1 does not properly calculate the end of a certain buffer, with unknown impact and remote attack vectors.
network
low complexity
clam-anti-virus
critical
10.0
2005-11-16 CVE-2005-3587 Remote Security vulnerability in ClamAV
Improper boundary checks in petite.c in Clam AntiVirus (ClamAV) before 0.87.1 allows attackers to perform unknown attacks via unknown vectors.
network
low complexity
clam-anti-virus
critical
10.0