Showing 2 vulnerabilities on this page for ClamAV

Signals CISA KEV Ransomware Nuclei
ClamAV vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Clam AntiVirus (ClamAV) Software Email Parsing Vulnerability

A vulnerability in the email parsing module Clam AntiVirus (ClamAV) Software versions 0.102.0, 0.101.4 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to inefficient MIME parsing routines that result in extremely long scan times of specially formatted email files. An attacker could exploit this vulnerability by sending a crafted email file to an affected device. An exploit could allow the attacker to

CWE-20CWE-400Jan 15, 2020
CVSS7.5v3.1EPSS3.14%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

clamav 0.91.2 suffers from a floating point exception when using ScanOLE2.

Nov 7, 2019
CVSS9.8v3.1EPSS2.23%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX