Vulnerabilities > Clamav > Clamav > 0.12

DATE CVE VULNERABILITY TITLE RISK
2009-04-23 CVE-2009-1372 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Clamav
Stack-based buffer overflow in the cli_url_canon function in libclamav/phishcheck.c in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted URL.
network
low complexity
clamav CWE-119
critical
10.0
2009-04-23 CVE-2009-1371 Improper Input Validation vulnerability in Clamav
The CLI_ISCONTAINED macro in libclamav/others.h in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) via a malformed file with UPack encoding.
network
low complexity
clamav CWE-20
5.0
2009-04-08 CVE-2009-1270 Infinite Loop vulnerability in multiple products
libclamav/untar.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (infinite loop) via a crafted TAR file that causes (1) clamd and (2) clamscan to hang.
network
low complexity
clamav debian canonical CWE-835
7.8
2009-04-08 CVE-2008-6680 Numeric Errors vulnerability in Clamav
libclamav/pe.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (crash) via a crafted EXE file that triggers a divide-by-zero error.
network
low complexity
clamav CWE-189
5.0
2009-04-03 CVE-2009-1241 Unspecified vulnerability in Clamav
Unspecified vulnerability in ClamAV before 0.95 allows remote attackers to bypass detection of malware via a modified RAR archive.
network
low complexity
clamav
7.5
2008-09-11 CVE-2008-3914 Information Exposure vulnerability in Clamav
Multiple unspecified vulnerabilities in ClamAV before 0.94 have unknown impact and attack vectors related to file descriptor leaks on the "error path" in (1) libclamav/others.c and (2) libclamav/sis.c.
network
low complexity
clamav CWE-200
critical
10.0
2008-09-11 CVE-2008-3913 Memory Leak vulnerability in multiple products
Multiple memory leaks in freshclam/manager.c in ClamAV before 0.94 might allow attackers to cause a denial of service (memory consumption) via unspecified vectors related to "error handling logic".
network
low complexity
clamav debian CWE-401
5.0
2008-09-11 CVE-2008-3912 Resource Management Errors vulnerability in multiple products
libclamav in ClamAV before 0.94 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to an out-of-memory condition.
network
low complexity
clamav debian CWE-399
5.0
2008-02-12 CVE-2008-0728 Resource Management Errors vulnerability in Clamav
The unmew11 function in libclamav/mew.c in libclamav in ClamAV before 0.92.1 has unknown impact and attack vectors that trigger "heap corruption."
network
low complexity
clamav CWE-399
critical
10.0
2007-05-14 CVE-2007-2650 Resource Exhaustion vulnerability in multiple products
The OLE2 parser in Clam AntiVirus (ClamAV) allows remote attackers to cause a denial of service (resource consumption) via an OLE2 file with (1) a large property size or (2) a loop in the FAT file block chain that triggers an infinite loop, as demonstrated via a crafted DOC file.
4.3