Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
175 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.2% | — | Fedoraproject FedoraClamav | 3/2/2015 | 17/6/2026 | ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted upack packer file, related to a "heap out of bounds condition." | |
| Modificada | Media (5) | 4.9% | — | Clamav | 1/12/2014 | 17/6/2026 | Heap-based buffer overflow in the cli_scanpe function in libclamav/pe.c in ClamAV before 0.98.5 allows remote attackers to cause a denial of service (crash) via a crafted y0da Crypter PE file. | |
| Modificada | Baja (2.1) | 1.1% | — | Clamav | 1/12/2014 | 17/6/2026 | clamscan in ClamAV before 0.98.5, when using -a option, allows remote attackers to cause a denial of service (crash) as demonstrated by the jwplayer.js file. | |
| Modificada | Media (4.3) | 3.5% | — | Canonical Ubuntu LinuxSuse Linux Enterprise ServerClamav | 13/5/2013 | 16/6/2026 | pdf.c in ClamAV 0.97.1 through 0.97.7 allows remote attackers to cause a denial of service (out-of-bounds-read) via a crafted length value in an encrypted PDF file. | |
| Modificada | Media (5) | 3.5% | — | Canonical Ubuntu LinuxSuse Linux Enterprise ServerClamav | 13/5/2013 | 16/6/2026 | Integer underflow in the cli_scanpe function in pe.c in ClamAV before 0.97.8 allows remote attackers to cause a denial of service (crash) via a skewed offset larger than the size of the PE section in a UPX packed executable, which triggers an out-of-bounds read. | |
| Modificada | Media (4.3) | 1.8% | — | Darold Squidclamav | 25/8/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in SquidClamav 5.x before 5.8 allow remote attackers to inject arbitrary web script or HTML via the (1) url, (2) virus, (3) source, or (4) user parameter to (a) clwarn.cgi, (b) clwarn.cgi.de_DE, (c) clwarn.cgi.en_EN, (d) clwarn.cgi.fr_FR, (e) clwarn.cgi.pt_BR, or (f)… | |
| Modificada | Media (5) | 3.3% | — | Darold Squidclamav | 25/8/2012 | 16/6/2026 | The squidclamav_check_preview_handler function in squidclamav.c in SquidClamav 5.x before 5.8 and 6.x before 6.7 passes an unescaped URL to a system command call, which allows remote attackers to cause a denial of service (daemon crash) via a URL with certain characters, as demonstrated using %0D or %0A. | |
| Modificada | Media (4.3) | 100% | — | Ahnlab V3 Internet SecurityAlwil Avast AntivirusAnti-virus Vba32Antiy AVL SDK+30 | 21/3/2012 | 16/6/2026 | The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Comodo Antivirus 7424,… | |
| Modificada | Media (4.3) | 74% | — | ClamavSophos Anti-virus | 21/3/2012 | 16/6/2026 | The Microsoft CHM file parser in ClamAV 0.96.4 and Sophos Anti-Virus 4.61.0 allows remote attackers to bypass malware detection via a crafted reset interval in the LZXC header of a CHM file. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred… | |
| Modificada | Media (4.3) | 98% | — | Aladdin EsafeAlwil Avast AntivirusAnti-virus Vba32Antiy AVL SDK+24 | 21/3/2012 | 16/6/2026 | The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus… | |
| Modificada | Media (4.3) | 100% | — | Ahnlab V3 Internet SecurityAladdin EsafeAlwil Avast AntivirusAnti-virus Vba32+31 | 21/3/2012 | 16/6/2026 | The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Command Antivirus 5.2.11.5, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Emsisoft Anti-Malware 5.1.0.1, PC Tools… | |
| Modificada | Media (4.3) | 41% | — | CAT Quick HealClamav | 21/3/2012 | 16/6/2026 | The TAR file parser in ClamAV 0.96.4 and Quick Heal (aka Cat QuickHeal) 11.00 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial [aliases] character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred… | |
| Modificada | Media (4.3) | 2.6% | — | Clamav | 17/11/2011 | 16/6/2026 | The bytecode engine in ClamAV before 0.97.3 allows remote attackers to cause a denial of service (crash) via vectors related to "recursion level" and (1) libclamav/bytecode.c and (2) libclamav/bytecode_api.c. | |
| Modificada | Media (5) | 3.4% | — | Clamav | 5/8/2011 | 16/6/2026 | Off-by-one error in the cli_hm_scan function in matcher-hash.c in libclamav in ClamAV before 0.97.2 allows remote attackers to cause a denial of service (daemon crash) via an e-mail message that is not properly handled during certain hash calculations. | |
| Modificada | Media (6.8) | 4.2% | — | Clamav | 23/2/2011 | 16/6/2026 | Double free vulnerability in the vba_read_project_strings function in vba_extract.c in libclamav in ClamAV before 0.97 might allow remote attackers to execute arbitrary code via crafted Visual Basic for Applications (VBA) data in a Microsoft Office document. NOTE: some of these details are obtained from third party… | |
| Modificada | Alta (7.5) | 4.9% | — | Clamav | 7/12/2010 | 16/6/2026 | Unspecified vulnerability in pdf.c in libclamav in ClamAV before 0.96.5 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document, aka "bb #2380," a different vulnerability than CVE-2010-4260. | |
| Modificada | Alta (7.5) | 4.8% | — | Clamav | 7/12/2010 | 16/6/2026 | Off-by-one error in the icon_cb function in pe_icons.c in libclamav in ClamAV before 0.96.5 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (5) | 4.9% | — | Clamav | 7/12/2010 | 16/6/2026 | Multiple unspecified vulnerabilities in pdf.c in libclamav in ClamAV before 0.96.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document, aka (1) "bb #2358" and (2) "bb #2396." | |
| Modificada | Alta (9.3) | 6.5% | — | Clamav | 30/9/2010 | 16/6/2026 | Buffer overflow in the find_stream_bounds function in pdf.c in libclamav in ClamAV before 0.96.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 2.9% | — | Clamav | 26/5/2010 | 16/6/2026 | Off-by-one error in the parseicon function in libclamav/pe_icons.c in ClamAV 0.96 allows remote attackers to cause a denial of service (crash) via a crafted PE icon that triggers an out-of-bounds read, related to improper rounding during scaling. | |
| Modificada | Media (4.3) | 2.9% | — | Clamav | 26/5/2010 | 16/6/2026 | The cli_pdf function in libclamav/pdf.c in ClamAV before 0.96.1 allows remote attackers to cause a denial of service (crash) via a malformed PDF file, related to an inconsistency in the calculated stream length and the real stream length. | |
| Modificada | Media (5) | 3.3% | — | ClamavClamavs Clamav | 8/4/2010 | 16/6/2026 | The qtm_decompress function in libclamav/mspack.c in ClamAV before 0.96 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted CAB archive that uses the Quantum (aka .Q) compression format. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (10) | 4.9% | — | ClamavClamavs Clamav | 8/4/2010 | 16/6/2026 | ClamAV before 0.96 does not properly handle the (1) CAB and (2) 7z file formats, which allows remote attackers to bypass virus detection via a crafted archive that is compatible with standard archive utilities. | |
| Modificada | Media (5) | 2.2% | — | Clamav | 2/7/2009 | 16/6/2026 | The unpack feature in ClamAV 0.93.3 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a corrupted LZH file. | |
| Modificada | Alta (10) | 7.6% | — | Clamav | 23/4/2009 | 16/6/2026 | Stack-based buffer overflow in the cli_url_canon function in libclamav/phishcheck.c in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted URL. |