Known vulnerabilities in clamav (Ubuntu package)

Software CPE: cpe:2.3:o:canonical:clamav_ubuntu_package:*:*:*:*:*:ubuntu:*:*
Total vulnerabilities: 34
Public exploits: 3
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting clamav (Ubuntu package) clamav (Ubuntu package) is affected by 34 known vulnerabilities: 2 critical, 7 high, 22 medium, 3 low Critical High Medium Low

Vulnerabilities (34)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU136659 - Release of invalid pointer or reference
CVE-2026-20217
CWE-763 Medium
No
No
1.5.3+dfsg-0ubuntu0.22.04.2, 1.5.3+dfsg-0ubuntu0.24.04.1, 1.5.3+dfsg-0ubuntu0.26.04.1 01.07.2026 SB2026070169
SB2026070205
SB2026070876
and 7 more
#VU136660 - Integer overflow
CVE-2026-20213
CWE-190 High
No
No
1.5.3+dfsg-0ubuntu0.22.04.2, 1.5.3+dfsg-0ubuntu0.24.04.1, 1.5.3+dfsg-0ubuntu0.26.04.1 01.07.2026 SB2026070169
SB2026070205
SB2026070876
and 3 more
#VU136661 - Allocation of Resources Without Limits or Throttling
CVE-2026-20216
CWE-770 Medium
No
No
1.5.3+dfsg-0ubuntu0.22.04.2, 1.5.3+dfsg-0ubuntu0.24.04.1, 1.5.3+dfsg-0ubuntu0.26.04.1 01.07.2026 SB2026070169
SB2026070205
SB2026070876
and 7 more
#VU136662 - Integer underflow
CVE-2026-20214
CWE-191 High
No
No
1.5.3+dfsg-0ubuntu0.22.04.2, 1.5.3+dfsg-0ubuntu0.24.04.1, 1.5.3+dfsg-0ubuntu0.26.04.1 01.07.2026 SB2026070169
SB2026070205
SB2026070876
and 7 more
#VU136663 - Improper input validation
CVE-2026-20243
CWE-20 Medium
No
No
1.5.3+dfsg-0ubuntu0.22.04.2, 1.5.3+dfsg-0ubuntu0.24.04.1, 1.5.3+dfsg-0ubuntu0.26.04.1 01.07.2026 SB2026070169
SB2026070205
SB2026070876
and 3 more
#VU136664 - Integer overflow
CVE-2026-20215
CWE-190 High
No
No
1.5.3+dfsg-0ubuntu0.22.04.2, 1.5.3+dfsg-0ubuntu0.24.04.1, 1.5.3+dfsg-0ubuntu0.26.04.1 01.07.2026 SB2026070169
SB2026070205
SB2026070876
and 7 more
#VU136665 - Improper input validation
CVE-2026-20244
CWE-20 Medium
No
No
1.5.3+dfsg-0ubuntu0.22.04.2, 1.5.3+dfsg-0ubuntu0.24.04.1, 1.5.3+dfsg-0ubuntu0.26.04.1 01.07.2026 SB2026070169
SB2026070205
SB2026070876
and 7 more
#VU111271 - Out-of-bounds read
CVE-2025-20234
CWE-125 High
No
No
1.4.3+dfsg-0ubuntu0.20.04.1+esm1, 1.4.3+dfsg-0ubuntu0.22.04.1, 1.4.3+dfsg-0ubuntu0.24.04.1, 1.4.3+dfsg-0ubuntu0.24.10.1, 1.4.3+dfsg-0ubuntu0.25.04.1 18.06.2025 SB2025061842
SB2025061845
SB20250620165
and 8 more
#VU111270 - Out-of-bounds write
CVE-2025-20260
CWE-787 Critical
No
No
1.4.3+dfsg-0ubuntu0.20.04.1+esm1, 1.4.3+dfsg-0ubuntu0.22.04.1, 1.4.3+dfsg-0ubuntu0.24.04.1, 1.4.3+dfsg-0ubuntu0.24.10.1, 1.4.3+dfsg-0ubuntu0.25.04.1 18.06.2025 SB2025061842
SB20250620165
SB20250620166
and 13 more
#VU103240 - Heap-based Buffer Overflow
CVE-2025-20128
CWE-122 Medium
No
No
1.0.8+dfsg-0ubuntu0.24.04.1, 1.4.2+dfsg-0ubuntu0.24.10.1 22.01.2025 SB2025012288
SB2025012289
SB2025012778
and 5 more
#VU96825 - Out-of-bounds read
CVE-2024-20505
CWE-125 Medium
No
No
Ubuntu Pro, 0.103.12+dfsg-0ubuntu0.20.04.1, 0.103.12+dfsg-0ubuntu0.22.04.1, 1.0.7+dfsg-0ubuntu0.24.04.1 05.09.2024 SB2024090511
SB20240905109
SB20240905110
and 16 more
#VU96824 - UNIX Symbolic Link (Symlink) Following
CVE-2024-20506
CWE-61 Low
No
No
Ubuntu Pro, 0.103.12+dfsg-0ubuntu0.20.04.1, 0.103.12+dfsg-0ubuntu0.22.04.1, 1.0.7+dfsg-0ubuntu0.24.04.1 05.09.2024 SB2024090511
SB20240905109
SB20240905110
and 13 more
#VU86262 - Heap-based Buffer Overflow
CVE-2024-20290
CWE-122 Medium
No
No
1.0.5+dfsg-0ubuntu0.23.10.1 08.02.2024 SB2024020749
SB2024020841
SB2024020880
and 5 more
#VU86229 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-20328
CWE-78 High
No
No
1.0.5+dfsg-0ubuntu0.23.10.1 07.02.2024 SB2024020749
SB2024020880
SB2024020881
and 3 more
#VU79711 - Improper Validation of Array Index
CVE-2023-40477
CWE-129 High
Available
No
0.103.11+dfsg-0ubuntu0.20.04.1, 0.103.11+dfsg-0ubuntu0.22.04.1, 0.103.11+dfsg-0ubuntu0.23.04.1, 1.0.4+dfsg-0ubuntu0.23.10.1 19.08.2023 SB2023081901
SB2023083134
SB2023083135
and 11 more
#VU79633 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2023-20197
CWE-835 Medium
No
No
Ubuntu Pro, 0.103.9+dfsg-0ubuntu0.20.04.1, 0.103.9+dfsg-0ubuntu0.22.04.1, 0.103.9+dfsg-0ubuntu0.23.04.1 16.08.2023 SB20230816163
SB20230821217
SB20230821218
and 21 more
#VU72298 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2023-20052
CWE-611 Medium
Available
No
Ubuntu Pro, 0.103.8+dfsg-0ubuntu0.18.04.1, 0.103.8+dfsg-0ubuntu0.20.04.1, 0.103.8+dfsg-0ubuntu0.22.04.1, 0.103.8+dfsg-0ubuntu0.22.10.1 15.02.2023 SB2023021569
SB2023021570
SB2023022043
and 17 more
#VU72297 - Heap-based Buffer Overflow
CVE-2023-20032
CWE-122 Critical
No
No
Ubuntu Pro, 0.103.8+dfsg-0ubuntu0.18.04.1, 0.103.8+dfsg-0ubuntu0.20.04.1, 0.103.8+dfsg-0ubuntu0.22.04.1, 0.103.8+dfsg-0ubuntu0.22.10.1 15.02.2023 SB2023021569
SB2023021570
SB2023022043
and 18 more
#VU62908 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-30333
CWE-22 Low
Available
Exploited
0.103.11+dfsg-0ubuntu0.20.04.1, 0.103.11+dfsg-0ubuntu0.22.04.1, 0.103.11+dfsg-0ubuntu0.23.04.1, 1.0.4+dfsg-0ubuntu0.23.10.1 10.05.2022 SB2022051004
SB2023091704
SB2024010819
and 3 more
#VU62801 - NULL Pointer Dereference
CVE-2022-20796
CWE-476 Medium
No
No
0.103.6+dfsg0ubuntu0.16.04.1+esm1, 0.103.6+dfsg-0ubuntu0.18.04.1, 0.103.6+dfsg-0ubuntu0.20.04.1, 0.103.6+dfsg-0ubuntu0.21.10.1, 0.103.6+dfsg-0ubuntu0.22.04.1 04.05.2022 SB2022050437
SB2022051732
SB2022051836
and 11 more


Showing elements 1 - 20 out of 34