Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

175 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)1.8%—Clamav8/4/201917/6/2026
A vulnerability in the RAR file scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and 0.101.0 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a lack of proper error-handling mechanisms when processing…
ModificadaMedia (5.5)1.3%—ClamavDebian LinuxCanonical Ubuntu Linux15/10/201817/6/2026
A vulnerability in ClamAV versions prior to 0.100.2 could allow an attacker to cause a denial of service (DoS) condition. The vulnerability is due to an error related to the MEW unpacker within the "unmew11()" function (libclamav/mew.c), which can be exploited to trigger an invalid read memory access via a specially…
ModificadaBaja (3.3)1.6%—ClamavDebian Linux16/7/201817/6/2026
ClamAV before 0.100.1 lacks a PDF object length check, resulting in an unreasonably long time to parse a relatively small file.
ModificadaMedia (5.5)1.7%—ClamavCanonical Ubuntu LinuxDebian Linux16/7/201817/6/2026
ClamAV before 0.100.1 has an HWP integer overflow with a resultant infinite loop via a crafted Hangul Word Processor file. This is in parsehwp3_paragraph() in libclamav/hwp.c.
ModificadaMedia (5.5)2.6%💥 PoCClamavCanonical Ubuntu LinuxDebian Linux27/3/201817/6/2026
clamscan in ClamAV before 0.99.4 contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation checking mechanisms when handling Portable Document Format (.pdf) files sent to an…
ModificadaMedia (5.5)1.6%—ClamavDebian LinuxCanonical Ubuntu Linux13/3/201817/6/2026
ClamAV version version 0.99.3 contains a Out of bounds heap memory read vulnerability in XAR parser, function xar_hash_check() that can result in Leaking of memory, may help in developing exploit chains.. This attack appear to be exploitable via The victim must scan a crafted XAR file. This vulnerability appears to…
ModificadaAlta (7.5)5.1%—Debian LinuxClamav26/1/201817/6/2026
ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation checking mechanisms in mbox.c during certain mail parsing functions…
ModificadaCrítica (9.8)13%—Debian LinuxClamav26/1/201817/6/2026
ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or potentially execute arbitrary code on an affected device. The vulnerability is due to improper input validation checking mechanisms in the…
ModificadaMedia (5.5)2.8%—Debian LinuxClamav26/1/201817/6/2026
ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation checking mechanisms of .tar (Tape Archive) files sent to an affected…
ModificadaCrítica (9.8)12%—Debian LinuxClamav26/1/201817/6/2026
ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or potentially execute arbitrary code on an affected device. The vulnerability is due to improper input validation checking mechanisms in mew…
ModificadaAlta (7.8)6.6%—Debian LinuxClamav26/1/201817/6/2026
ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or potentially execute arbitrary code on an affected device. The vulnerability is due to improper input validation checking mechanisms when…
ModificadaAlta (7.5)5.6%—Debian LinuxClamav26/1/201817/6/2026
The ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a lack of input validation checking mechanisms during certain mail parsing functions (the…
ModificadaAlta (7.5)5.0%—Debian LinuxClamav26/1/201817/6/2026
The ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a lack of input validation checking mechanisms during certain mail parsing operations…
ModificadaMedia (5.5)1.4%—Clamav7/8/201717/6/2026
The wwunpack function in libclamav/wwunpack.c in ClamAV 0.99.2 allows remote attackers to cause a denial of service (use-after-free) via a crafted PE file with WWPack compression.
ModificadaMedia (5.5)1.4%—Clamav7/8/201717/6/2026
libclamav/message.c in ClamAV 0.99.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted e-mail message.
ModificadaMedia (5.5)1.6%—ClamavCanonical Ubuntu Linux3/10/201617/6/2026
ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted 7z file.
ModificadaMedia (5.5)1.6%—Canonical Ubuntu LinuxClamav3/10/201617/6/2026
ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted mew packer executable.
ModificadaAlta (7.5)3.4%—ClamavCisco Email Security ApplianceCisco WEB Security Appliance8/6/201617/6/2026
libclamav in ClamAV (aka Clam AntiVirus), as used in Advanced Malware Protection (AMP) on Cisco Email Security Appliance (ESA) devices before 9.7.0-125 and Web Security Appliance (WSA) devices before 9.0.1-135 and 9.1.x before 9.1.1-041, allows remote attackers to cause a denial of service (AMP process restart) via a…
ModificadaMedia (5)3.2%—ClamavCanonical Ubuntu Linux12/5/201517/6/2026
ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infinite loop) via a crafted xz archive file.
ModificadaMedia (5)3.2%—Canonical Ubuntu LinuxClamav12/5/201517/6/2026
ClamAV before 0.98.7 allows remote attackers to cause a denial of service (crash) via a crafted petite packed file.
ModificadaMedia (5)3.2%—ClamavCanonical Ubuntu Linux12/5/201517/6/2026
ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infinite loop) via a crafted y0da cryptor file.
ModificadaMedia (5)3.2%—Canonical Ubuntu LinuxClamav12/5/201517/6/2026
The upx decoder in ClamAV before 0.98.7 allows remote attackers to cause a denial of service (crash) via a crafted file.
ModificadaMedia (5)2.7%—ClamavFedoraproject Fedora3/2/201517/6/2026
ClamAV before 0.98.6 allows remote attackers to cause a denial of service (crash) via a crafted petite packer file, related to an "incorrect compiler optimization."
ModificadaAlta (7.5)2.8%—Fedoraproject FedoraClamav3/2/201517/6/2026
ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted upx packer file, related to a "heap out of bounds condition."
ModificadaAlta (7.5)2.8%—Fedoraproject FedoraClamav3/2/201517/6/2026
ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted (1) Yoda's crypter or (2) mew packer file, related to a "heap out of bounds condition."
Orbitaley — Vulnerabilidades