Vulnerabilities > Clam Anti Virus

DATE CVE VULNERABILITY TITLE RISK
2005-11-16 CVE-2005-3587 Remote Security vulnerability in ClamAV
Improper boundary checks in petite.c in Clam AntiVirus (ClamAV) before 0.87.1 allows attackers to perform unknown attacks via unknown vectors.
network
low complexity
clam-anti-virus
critical
10.0
2005-11-05 CVE-2005-3500 Denial Of Service vulnerability in Clam Anti-Virus ClamAV TNEF File Handling
The tnef_attachment function in tnef.c for Clam AntiVirus (ClamAV) before 0.87.1 allows remote attackers to cause a denial of service (infinite loop and memory exhaustion) via a crafted value in a CAB file that causes ClamAV to repeatedly scan the same block.
network
low complexity
clam-anti-virus
5.0
2005-11-05 CVE-2005-3303 Buffer Overflow vulnerability in Clam Anti-Virus ClamAV FSG File Handling
The FSG unpacker (fsg.c) in Clam AntiVirus (ClamAV) 0.80 through 0.87 allows remote attackers to cause "memory corruption" and execute arbitrary code via a crafted FSG 1.33 file.
network
low complexity
clam-anti-virus
7.5
2005-10-14 CVE-2005-3239 Denial Of Service vulnerability in Clam Anti-Virus Clamav .
The OLE2 unpacker in clamd in Clam AntiVirus (ClamAV) 0.87-1 allows remote attackers to cause a denial of service (segmentation fault) via a DOC file with an invalid property tree, which triggers an infinite recursion in the ole2_walk_property_tree function.
network
low complexity
clam-anti-virus
7.8
2005-10-14 CVE-2005-3229 Security Bypass vulnerability in ClamAV Antivirus
Multiple interpretation error in unspecified versions of ClamAV Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.
network
high complexity
clam-anti-virus
5.1
2005-09-20 CVE-2005-2920 Buffer Overflow vulnerability in ClamAV UPX Compressed Executable
Buffer overflow in libclamav/upx.c in Clam AntiVirus (ClamAV) before 0.87 allows remote attackers to execute arbitrary code via a crafted UPX packed executable.
network
low complexity
clam-anti-virus
7.5
2005-09-20 CVE-2005-2919 Code vulnerability in Clam Anti-Virus Clamav
libclamav/fsg.c in Clam AntiVirus (ClamAV) before 0.87 allows remote attackers to cause a denial of service (infinite loop) via a crafted FSG packed executable.
network
low complexity
clam-anti-virus CWE-17
5.0
2005-08-03 CVE-2005-2450 Integer Overflow vulnerability in Clam Anti-Virus Clamav 0.85/0.85.1/0.86
Multiple integer overflows in the (1) TNEF, (2) CHM, or (3) FSG file format processors in libclamav for Clam AntiVirus (ClamAV) 0.86.1 and earlier allow remote attackers to gain privileges via a crafted e-mail message.
network
low complexity
clam-anti-virus
7.5
2005-07-05 CVE-2005-1923 Unspecified vulnerability in Clam Anti-Virus Clamav
The ENSURE_BITS macro in mszipd.c for Clam AntiVirus (ClamAV) 0.83, and other versions vefore 0.86, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a cabinet (CAB) file with the cffile_FolderOffset field set to 0xff, which causes a zero-length read.
network
high complexity
clam-anti-virus
2.6
2005-07-05 CVE-2005-1922 Unspecified vulnerability in Clam Anti-Virus Clamav
The MS-Expand file handling in Clam AntiVirus (ClamAV) before 0.86 allows remote attackers to cause a denial of service (file descriptor and memory consumption) via a crafted file that causes repeated errors in the cli_msexpand function.
network
low complexity
clam-anti-virus
5.0