ClamAV Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with ClamAV products.
Products
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2020-37167HIGH | ClamAV ClamBC < 0.103.0-rc - 'ClamBC' Executable Regular Expression ErrorClamAV versions prior to 0.103.0-rc contain a vulnerability in function name processing through the ClamBC bytecode interpreter that allows attackers to manipulate bytecode function names. Attackers can exploit the weak input validation in function name encoding to potentially execute malicious bytecode or cause unexpected behavior in the ClamAV engine. CWE-94Feb 12, 2026 | CVSS8.6v4.0 | EPSS0.172% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-15961HIGH | Clam AntiVirus (ClamAV) Software Email Parsing VulnerabilityA vulnerability in the email parsing module Clam AntiVirus (ClamAV) Software versions 0.102.0, 0.101.4 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to inefficient MIME parsing routines that result in extremely long scan times of specially formatted email files. An attacker could exploit this vulnerability by sending a crafted email file to an affected device. An exploit could allow the attacker to… | CVSS7.5v3.1 | EPSS3.14% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2007-6745CRITICAL | clamav 0.91.2 suffers from a floating point exception when using ScanOLE2. Nov 7, 2019 | CVSS9.8v3.1 | EPSS2.23% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |