Known vulnerabilities in ClamAV

Vendor: ClamAV
Software: ClamAV
Software CPE: cpe:2.3:a:clamav:clamav_antivirus:*:*:*:*:*:*:*:*
Total vulnerabilities: 84
Public exploits: 1
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting ClamAV ClamAV is affected by 84 known vulnerabilities: 3 critical, 17 high, 46 medium, 18 low Critical High Medium Low

Vulnerabilities (84)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU141296 - Out-of-bounds write
CVE-2026-20337
CWE-787 Medium
No
No
1.5.4 07.08.2026 SB2026080781
#VU141297 - Out-of-bounds write
CVE-2026-20345
CWE-787 Medium
No
No
1.4.6, 1.5.4 07.08.2026 SB2026080781
#VU141298 - Integer overflow
CVE-2026-20339
CWE-190 Medium
No
No
1.4.6, 1.5.4 07.08.2026 SB2026080781
#VU141299 - Double Free
CVE-2026-20338
CWE-415 Medium
No
No
1.5.4 07.08.2026 SB2026080781
#VU141300 - Integer underflow
CVE-2026-20346
CWE-191 Medium
No
No
1.4.6, 1.5.4 07.08.2026 SB2026080781
#VU141301 - Integer overflow
CVE-2026-20347
CWE-190 Medium
No
No
1.4.6, 1.5.4 07.08.2026 SB2026080781
#VU141302 - Allocation of Resources Without Limits or Throttling
CVE-2026-20348
CWE-770 Medium
No
No
1.4.6, 1.5.4 07.08.2026 SB2026080781
#VU141303 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CWE-362 Low
No
No
1.4.6, 1.5.4 07.08.2026 SB2026080781
#VU141304 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CWE-362 Low
No
No
1.4.6, 1.5.4 07.08.2026 SB2026080781
#VU141305 - Missing release of memory after effective lifetime
CWE-401 Low
No
No
1.5.4 07.08.2026 SB2026080781
#VU136659 - Release of invalid pointer or reference
CVE-2026-20217
CWE-763 Medium
No
No
1.4.5, 1.5.3 01.07.2026 SB2026070169
SB2026070205
SB2026070876
and 7 more
#VU136660 - Integer overflow
CVE-2026-20213
CWE-190 High
No
No
1.4.5, 1.5.3 01.07.2026 SB2026070169
SB2026070205
SB2026070876
and 3 more
#VU136661 - Allocation of Resources Without Limits or Throttling
CVE-2026-20216
CWE-770 Medium
No
No
1.4.5, 1.5.3 01.07.2026 SB2026070169
SB2026070205
SB2026070876
and 7 more
#VU136662 - Integer underflow
CVE-2026-20214
CWE-191 High
No
No
1.4.5, 1.5.3 01.07.2026 SB2026070169
SB2026070205
SB2026070876
and 7 more
#VU136663 - Improper input validation
CVE-2026-20243
CWE-20 Medium
No
No
1.4.5, 1.5.3 01.07.2026 SB2026070169
SB2026070205
SB2026070876
and 3 more
#VU136664 - Integer overflow
CVE-2026-20215
CWE-190 High
No
No
1.4.5, 1.5.3 01.07.2026 SB2026070169
SB2026070205
SB2026070876
and 7 more
#VU136665 - Improper input validation
CVE-2026-20244
CWE-20 Medium
No
No
1.4.5, 1.5.3 01.07.2026 SB2026070169
SB2026070205
SB2026070876
and 7 more
#VU126498 - Out-of-bounds write
CVE-2026-41676
CWE-787 Medium
No
No
1.4.5, 1.5.3 20.04.2026 SB2026042021
SB2026061905
SB2026061906
and 46 more
#VU123663 - Error Handling
CVE-2026-20031
CWE-388 Medium
No
No
1.4.4, 1.5.2 10.03.2026 SB2026031002
SB2026031769
SB2026041506
and 6 more
#VU113784 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-8088
CWE-22 Critical
Available
Exploited
1.4.6, 1.5.4 09.08.2025 SB2025080901
SB2025100738
SB2026080781


Showing elements 1 - 20 out of 84