ClamAV vulnerabilities
4 CVEs tracked
In our reports, ClamAV appears in the context of multiple newly discovered vulnerabilities specifically within its file format parsers. The main theme is remotely exploitable flaws that can lead to memory corruption and DoS conditions via specially crafted files. The affected components include the GPT, ZIP, PDF, and Mach-O file parsers. Defenders should focus on input points where ClamAV automatically processes files, such as email attachments and downloads, and prioritize rapid patching.
Azərbaycanca: Hesabatlarımızda ClamAV, xüsusilə fayl formatı parser-lərində aşkarlanan bir neçə yeni zəifliklə bağlı görünür. Əsas mövzu, xüsusi hazırlanmış fayllar vasitəsilə memory corruption və DoS hücumlarına səbəb ola biləcək uzaqdan istismar edilə bilən boşluqlardır. Təsirə məruz qalan komponentlər GPT, ZIP, PDF və Mach-O fayl parser-lərini əhatə edir. Müdafiəçilər xüsusilə məktub əlavələri və yüklənən faylların skan edilməsi kimi ClamAV-ın avtomatik emal etdiyi giriş nöqtələrinə diqqət yetirməli və sürətli şəkildə yeniləmə tətbiq etməlidirlər.
This vendor's CVEs4
This hub is built from skopnix's own reporting on ClamAV: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.