Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
175 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 1.8% | — | Clamav | 8/4/2019 | 17/6/2026 | A vulnerability in the RAR file scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and 0.101.0 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a lack of proper error-handling mechanisms when processing… | |
| Modificada | Media (5.5) | 1.3% | — | ClamavDebian LinuxCanonical Ubuntu Linux | 15/10/2018 | 17/6/2026 | A vulnerability in ClamAV versions prior to 0.100.2 could allow an attacker to cause a denial of service (DoS) condition. The vulnerability is due to an error related to the MEW unpacker within the "unmew11()" function (libclamav/mew.c), which can be exploited to trigger an invalid read memory access via a specially… | |
| Modificada | Baja (3.3) | 1.6% | — | ClamavDebian Linux | 16/7/2018 | 17/6/2026 | ClamAV before 0.100.1 lacks a PDF object length check, resulting in an unreasonably long time to parse a relatively small file. | |
| Modificada | Media (5.5) | 1.7% | — | ClamavCanonical Ubuntu LinuxDebian Linux | 16/7/2018 | 17/6/2026 | ClamAV before 0.100.1 has an HWP integer overflow with a resultant infinite loop via a crafted Hangul Word Processor file. This is in parsehwp3_paragraph() in libclamav/hwp.c. | |
| Modificada | Media (5.5) | 2.6% | 💥 PoC | ClamavCanonical Ubuntu LinuxDebian Linux | 27/3/2018 | 17/6/2026 | clamscan in ClamAV before 0.99.4 contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation checking mechanisms when handling Portable Document Format (.pdf) files sent to an… | |
| Modificada | Media (5.5) | 1.6% | — | ClamavDebian LinuxCanonical Ubuntu Linux | 13/3/2018 | 17/6/2026 | ClamAV version version 0.99.3 contains a Out of bounds heap memory read vulnerability in XAR parser, function xar_hash_check() that can result in Leaking of memory, may help in developing exploit chains.. This attack appear to be exploitable via The victim must scan a crafted XAR file. This vulnerability appears to… | |
| Modificada | Alta (7.5) | 5.1% | — | Debian LinuxClamav | 26/1/2018 | 17/6/2026 | ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation checking mechanisms in mbox.c during certain mail parsing functions… | |
| Modificada | Crítica (9.8) | 13% | — | Debian LinuxClamav | 26/1/2018 | 17/6/2026 | ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or potentially execute arbitrary code on an affected device. The vulnerability is due to improper input validation checking mechanisms in the… | |
| Modificada | Media (5.5) | 2.8% | — | Debian LinuxClamav | 26/1/2018 | 17/6/2026 | ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation checking mechanisms of .tar (Tape Archive) files sent to an affected… | |
| Modificada | Crítica (9.8) | 12% | — | Debian LinuxClamav | 26/1/2018 | 17/6/2026 | ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or potentially execute arbitrary code on an affected device. The vulnerability is due to improper input validation checking mechanisms in mew… | |
| Modificada | Alta (7.8) | 6.6% | — | Debian LinuxClamav | 26/1/2018 | 17/6/2026 | ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or potentially execute arbitrary code on an affected device. The vulnerability is due to improper input validation checking mechanisms when… | |
| Modificada | Alta (7.5) | 5.6% | — | Debian LinuxClamav | 26/1/2018 | 17/6/2026 | The ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a lack of input validation checking mechanisms during certain mail parsing functions (the… | |
| Modificada | Alta (7.5) | 5.0% | — | Debian LinuxClamav | 26/1/2018 | 17/6/2026 | The ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a lack of input validation checking mechanisms during certain mail parsing operations… | |
| Modificada | Media (5.5) | 1.4% | — | Clamav | 7/8/2017 | 17/6/2026 | The wwunpack function in libclamav/wwunpack.c in ClamAV 0.99.2 allows remote attackers to cause a denial of service (use-after-free) via a crafted PE file with WWPack compression. | |
| Modificada | Media (5.5) | 1.4% | — | Clamav | 7/8/2017 | 17/6/2026 | libclamav/message.c in ClamAV 0.99.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted e-mail message. | |
| Modificada | Media (5.5) | 1.6% | — | ClamavCanonical Ubuntu Linux | 3/10/2016 | 17/6/2026 | ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted 7z file. | |
| Modificada | Media (5.5) | 1.6% | — | Canonical Ubuntu LinuxClamav | 3/10/2016 | 17/6/2026 | ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted mew packer executable. | |
| Modificada | Alta (7.5) | 3.4% | — | ClamavCisco Email Security ApplianceCisco WEB Security Appliance | 8/6/2016 | 17/6/2026 | libclamav in ClamAV (aka Clam AntiVirus), as used in Advanced Malware Protection (AMP) on Cisco Email Security Appliance (ESA) devices before 9.7.0-125 and Web Security Appliance (WSA) devices before 9.0.1-135 and 9.1.x before 9.1.1-041, allows remote attackers to cause a denial of service (AMP process restart) via a… | |
| Modificada | Media (5) | 3.2% | — | ClamavCanonical Ubuntu Linux | 12/5/2015 | 17/6/2026 | ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infinite loop) via a crafted xz archive file. | |
| Modificada | Media (5) | 3.2% | — | Canonical Ubuntu LinuxClamav | 12/5/2015 | 17/6/2026 | ClamAV before 0.98.7 allows remote attackers to cause a denial of service (crash) via a crafted petite packed file. | |
| Modificada | Media (5) | 3.2% | — | ClamavCanonical Ubuntu Linux | 12/5/2015 | 17/6/2026 | ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infinite loop) via a crafted y0da cryptor file. | |
| Modificada | Media (5) | 3.2% | — | Canonical Ubuntu LinuxClamav | 12/5/2015 | 17/6/2026 | The upx decoder in ClamAV before 0.98.7 allows remote attackers to cause a denial of service (crash) via a crafted file. | |
| Modificada | Media (5) | 2.7% | — | ClamavFedoraproject Fedora | 3/2/2015 | 17/6/2026 | ClamAV before 0.98.6 allows remote attackers to cause a denial of service (crash) via a crafted petite packer file, related to an "incorrect compiler optimization." | |
| Modificada | Alta (7.5) | 2.8% | — | Fedoraproject FedoraClamav | 3/2/2015 | 17/6/2026 | ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted upx packer file, related to a "heap out of bounds condition." | |
| Modificada | Alta (7.5) | 2.8% | — | Fedoraproject FedoraClamav | 3/2/2015 | 17/6/2026 | ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted (1) Yoda's crypter or (2) mew packer file, related to a "heap out of bounds condition." |