Vulnerabilities
Vulnerable Software
Clamav:  >> Clamav  >> 0.88.3  Security Vulnerabilities
Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, which allows remote attackers to cause a denial of service (file descriptor consumption and failed scans) via CAB archives with a cabinet header record length of zero, which causes a function to return without closing a file descriptor.
CVSS Score
7.5
EPSS Score
0.034
Published
2007-02-16
Heap-based buffer overflow in the pefromupx function in libclamav/upx.c in Clam AntiVirus (ClamAV) 0.81 through 0.88.3 allows remote attackers to execute arbitrary code via a crafted UPX packed file containing sections with large rsize values.
CVSS Score
7.5
EPSS Score
0.191
Published
2006-08-08


Contact Us

Shodan ® - All rights reserved