Логотип exploitDog
bind:"GHSA-95rx-jp6p-3cmx" OR bind:"CVE-2021-1404"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-95rx-jp6p-3cmx" OR bind:"CVE-2021-1404"

Количество 11

Количество 11

github логотип

GHSA-95rx-jp6p-3cmx

больше 3 лет назад

A vulnerability in the email parsing module in Clam AntiVirus (ClamAV) Software version 0.103.0 and all prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper variable initialization that may result in an NULL pointer read. An attacker could exploit this vulnerability by sending a crafted email to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process crash, resulting in a denial of service condition.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2021-1404

почти 5 лет назад

A vulnerability in the PDF parsing module in Clam AntiVirus (ClamAV) Software versions 0.103.0 and 0.103.1 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper buffer size tracking that may result in a heap buffer over-read. An attacker could exploit this vulnerability by sending a crafted PDF file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process to crash, resulting in a denial of service condition.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2021-1404

почти 5 лет назад

A vulnerability in the PDF parsing module in Clam AntiVirus (ClamAV) Software versions 0.103.0 and 0.103.1 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper buffer size tracking that may result in a heap buffer over-read. An attacker could exploit this vulnerability by sending a crafted PDF file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process to crash, resulting in a denial of service condition.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-1404

почти 5 лет назад

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2021-1404

почти 5 лет назад

A vulnerability in the PDF parsing module in Clam AntiVirus (ClamAV) S ...

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2021-02218

почти 5 лет назад

Уязвимость модуля синтаксического анализа PDF-файлов пакета антивирусных программ ClamAV, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:0555-1

почти 5 лет назад

Security update for clamav

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:14692-1

почти 5 лет назад

Security update for clamav

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:1190-1

почти 5 лет назад

Security update for clamav

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:1189-1

почти 5 лет назад

Security update for clamav

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:1174-1

почти 5 лет назад

Security update for clamav

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-95rx-jp6p-3cmx

A vulnerability in the email parsing module in Clam AntiVirus (ClamAV) Software version 0.103.0 and all prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper variable initialization that may result in an NULL pointer read. An attacker could exploit this vulnerability by sending a crafted email to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process crash, resulting in a denial of service condition.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2021-1404

A vulnerability in the PDF parsing module in Clam AntiVirus (ClamAV) Software versions 0.103.0 and 0.103.1 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper buffer size tracking that may result in a heap buffer over-read. An attacker could exploit this vulnerability by sending a crafted PDF file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process to crash, resulting in a denial of service condition.

CVSS3: 7.5
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-1404

A vulnerability in the PDF parsing module in Clam AntiVirus (ClamAV) Software versions 0.103.0 and 0.103.1 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper buffer size tracking that may result in a heap buffer over-read. An attacker could exploit this vulnerability by sending a crafted PDF file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process to crash, resulting in a denial of service condition.

CVSS3: 7.5
0%
Низкий
почти 5 лет назад
msrc логотип
CVSS3: 7.5
0%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-1404

A vulnerability in the PDF parsing module in Clam AntiVirus (ClamAV) S ...

CVSS3: 7.5
0%
Низкий
почти 5 лет назад
fstec логотип
BDU:2021-02218

Уязвимость модуля синтаксического анализа PDF-файлов пакета антивирусных программ ClamAV, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
0%
Низкий
почти 5 лет назад
suse-cvrf логотип
openSUSE-SU-2021:0555-1

Security update for clamav

почти 5 лет назад
suse-cvrf логотип
SUSE-SU-2021:14692-1

Security update for clamav

почти 5 лет назад
suse-cvrf логотип
SUSE-SU-2021:1190-1

Security update for clamav

почти 5 лет назад
suse-cvrf логотип
SUSE-SU-2021:1189-1

Security update for clamav

почти 5 лет назад
suse-cvrf логотип
SUSE-SU-2021:1174-1

Security update for clamav

почти 5 лет назад

Уязвимостей на страницу