Search CVE reports


Toggle filters

41 – 50 of 169 results


CVE-2019-1788

Medium priority
Fixed

A vulnerability in the Object Linking & Embedding (OLE2) file scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could allow an unauthenticated, remote attacker to cause a denial of service...

1 affected package

clamav

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
clamav Fixed
Show less packages

CVE-2019-1787

Medium priority
Fixed

A vulnerability in the Portable Document Format (PDF) scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could allow an unauthenticated, remote attacker to cause a denial of service (DoS)...

1 affected package

clamav

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
clamav Fixed
Show less packages

CVE-2018-18586

Negligible priority
Not affected

chmextract.c in the chmextract sample program, as distributed with libmspack before 0.8alpha, does not protect against absolute/relative pathnames in CHM files, leading to Directory Traversal. NOTE: the vendor disputes that this...

2 affected packages

clamav, libmspack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
clamav Not affected
libmspack Not affected
Show less packages

CVE-2018-18585

Medium priority

Some fixes available 4 of 5

chmd_read_headers in mspack/chmd.c in libmspack before 0.8alpha accepts a filename that has '\0' as its first or second character (such as the "/\0" name).

2 affected packages

clamav, libmspack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
clamav Not affected Not affected Not affected Not affected
libmspack Not affected Not affected Not affected Fixed
Show less packages

CVE-2018-18584

Medium priority
Fixed

In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading to an out-of-bounds write.

3 affected packages

cabextract, clamav, libmspack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cabextract Not affected Not affected Not affected
clamav Not affected Not affected Not affected
libmspack Not affected Not affected Fixed
Show less packages

CVE-2018-15378

Medium priority
Fixed

A vulnerability in ClamAV versions prior to 0.100.2 could allow an attacker to cause a denial of service (DoS) condition. The vulnerability is due to an error related to the MEW unpacker within the "unmew11()"...

1 affected package

clamav

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
clamav Fixed
Show less packages

CVE-2018-14682

Medium priority

Some fixes available 3 of 4

An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the TOLOWER() macro for CHM decompression.

2 affected packages

clamav, libmspack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
clamav Not affected Not affected Not affected Not affected
libmspack Not affected Not affected Not affected Fixed
Show less packages

CVE-2018-14681

Medium priority

Some fixes available 3 of 4

An issue was discovered in kwajd_read_headers in mspack/kwajd.c in libmspack before 0.7alpha. Bad KWAJ file header extensions could cause a one or two byte overwrite.

2 affected packages

clamav, libmspack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
clamav Not affected Not affected Not affected Not affected
libmspack Not affected Not affected Not affected Fixed
Show less packages

CVE-2018-14680

Medium priority

Some fixes available 3 of 4

An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. It does not reject blank CHM filenames.

2 affected packages

clamav, libmspack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
clamav Not affected Not affected Not affected Not affected
libmspack Not affected Not affected Not affected Fixed
Show less packages

CVE-2018-14679

Medium priority

Some fixes available 3 of 4

An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the CHM PMGI/PMGL chunk number validity checks, which could lead to denial of service (uninitialized data dereference and...

2 affected packages

clamav, libmspack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
clamav Not affected Not affected Not affected Not affected
libmspack Not affected Not affected Not affected Fixed
Show less packages