Search CVE reports
41 – 50 of 169 results
A vulnerability in the Object Linking & Embedding (OLE2) file scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could allow an unauthenticated, remote attacker to cause a denial of service...
1 affected package
clamav
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| clamav | — | — | — | Fixed | 
A vulnerability in the Portable Document Format (PDF) scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could allow an unauthenticated, remote attacker to cause a denial of service (DoS)...
1 affected package
clamav
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| clamav | — | — | — | Fixed | 
chmextract.c in the chmextract sample program, as distributed with libmspack before 0.8alpha, does not protect against absolute/relative pathnames in CHM files, leading to Directory Traversal. NOTE: the vendor disputes that this...
2 affected packages
clamav, libmspack
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| clamav | — | — | — | Not affected | 
| libmspack | — | — | — | Not affected | 
chmd_read_headers in mspack/chmd.c in libmspack before 0.8alpha accepts a filename that has '\0' as its first or second character (such as the "/\0" name).
2 affected packages
clamav, libmspack
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| clamav | Not affected | Not affected | Not affected | Not affected | 
| libmspack | Not affected | Not affected | Not affected | Fixed | 
In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading to an out-of-bounds write.
3 affected packages
cabextract, clamav, libmspack
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| cabextract | — | Not affected | Not affected | Not affected | 
| clamav | — | Not affected | Not affected | Not affected | 
| libmspack | — | Not affected | Not affected | Fixed | 
A vulnerability in ClamAV versions prior to 0.100.2 could allow an attacker to cause a denial of service (DoS) condition. The vulnerability is due to an error related to the MEW unpacker within the "unmew11()"...
1 affected package
clamav
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| clamav | — | — | — | Fixed | 
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the TOLOWER() macro for CHM decompression.
2 affected packages
clamav, libmspack
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| clamav | Not affected | Not affected | Not affected | Not affected | 
| libmspack | Not affected | Not affected | Not affected | Fixed | 
An issue was discovered in kwajd_read_headers in mspack/kwajd.c in libmspack before 0.7alpha. Bad KWAJ file header extensions could cause a one or two byte overwrite.
2 affected packages
clamav, libmspack
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| clamav | Not affected | Not affected | Not affected | Not affected | 
| libmspack | Not affected | Not affected | Not affected | Fixed | 
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. It does not reject blank CHM filenames.
2 affected packages
clamav, libmspack
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| clamav | Not affected | Not affected | Not affected | Not affected | 
| libmspack | Not affected | Not affected | Not affected | Fixed | 
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the CHM PMGI/PMGL chunk number validity checks, which could lead to denial of service (uninitialized data dereference and...
2 affected packages
clamav, libmspack
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 
|---|---|---|---|---|
| clamav | Not affected | Not affected | Not affected | Not affected | 
| libmspack | Not affected | Not affected | Not affected | Fixed |