Known vulnerabilities in clamav

Software: clamav
Software CPE: cpe:2.3:o:fedoraproject:clamav:*:*:*:*:*:fedora:*:*
Total vulnerabilities: 47
Public exploits: 3
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting clamav clamav is affected by 47 known vulnerabilities: 2 critical, 11 high, 19 medium, 15 low Critical High Medium Low

Vulnerabilities (47)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU136659 - Release of invalid pointer or reference
CVE-2026-20217
CWE-763 Medium
No
No
1.4.6-1.el8, 1.4.6-1.el9, 1.4.6-1.el10_3, 1.4.6-1.fc43 01.07.2026 SB2026070169
SB2026070205
SB2026070876
and 7 more
#VU136661 - Allocation of Resources Without Limits or Throttling
CVE-2026-20216
CWE-770 Medium
No
No
1.4.6-1.el8, 1.4.6-1.el9, 1.4.6-1.el10_3, 1.4.6-1.fc43 01.07.2026 SB2026070169
SB2026070205
SB2026070876
and 7 more
#VU136662 - Integer underflow
CVE-2026-20214
CWE-191 High
No
No
1.4.6-1.el8, 1.4.6-1.el9, 1.4.6-1.el10_3, 1.4.6-1.fc43 01.07.2026 SB2026070169
SB2026070205
SB2026070876
and 7 more
#VU136664 - Integer overflow
CVE-2026-20215
CWE-190 High
No
No
1.4.6-1.el8, 1.4.6-1.el9, 1.4.6-1.el10_3, 1.4.6-1.fc43 01.07.2026 SB2026070169
SB2026070205
SB2026070876
and 7 more
#VU136665 - Improper input validation
CVE-2026-20244
CWE-20 Medium
No
No
1.4.6-1.el8, 1.4.6-1.el9, 1.4.6-1.el10_3, 1.4.6-1.fc43 01.07.2026 SB2026070169
SB2026070205
SB2026070876
and 7 more
#VU123663 - Error Handling
CVE-2026-20031
CWE-388 Medium
No
No
1.4.6-1.el8, 1.4.6-1.el9, 1.4.6-1.el10_3, 1.4.6-1.fc43 10.03.2026 SB2026031002
SB2026031769
SB2026041506
and 6 more
#VU111271 - Out-of-bounds read
CVE-2025-20234
CWE-125 High
No
No
1.0.9-1.el8, 1.0.9-1.el9, 1.0.9-1.fc41, 1.4.3-1.el10_1 18.06.2025 SB2025061842
SB2025061845
SB20250620165
and 8 more
#VU111270 - Out-of-bounds write
CVE-2025-20260
CWE-787 Critical
No
No
1.0.9-1.el8, 1.0.9-1.el9, 1.0.9-1.fc41, 1.4.3-1.el10_1 18.06.2025 SB2025061842
SB20250620165
SB20250620166
and 13 more
#VU96825 - Out-of-bounds read
CVE-2024-20505
CWE-125 Medium
No
No
1.0.7-1.el8, 1.0.7-1.el9, 1.0.7-1.fc39, 1.0.7-1.fc40, 1.0.7-1.fc41 05.09.2024 SB2024090511
SB20240905109
SB20240905110
and 16 more
#VU96824 - UNIX Symbolic Link (Symlink) Following
CVE-2024-20506
CWE-61 Low
No
No
1.0.7-1.el8, 1.0.7-1.el9, 1.0.7-1.fc39, 1.0.7-1.fc40, 1.0.7-1.fc41 05.09.2024 SB2024090511
SB20240905109
SB20240905110
and 13 more
#VU86262 - Heap-based Buffer Overflow
CVE-2024-20290
CWE-122 Medium
No
No
1.0.5-1.el9, 1.0.5-1.fc38, 1.0.5-1.fc39 08.02.2024 SB2024020749
SB2024020841
SB2024020880
and 5 more
#VU86229 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-20328
CWE-78 High
No
No
1.0.5-1.el9, 1.0.5-1.fc38, 1.0.5-1.fc39 07.02.2024 SB2024020749
SB2024020880
SB2024020881
and 3 more
#VU79711 - Improper Validation of Array Index
CVE-2023-40477
CWE-129 High
Available
No
0.103.10-1.el7, 0.103.10-1.el8, 0.103.10-1.fc37 19.08.2023 SB2023081901
SB2023083134
SB2023083135
and 11 more
#VU79633 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2023-20197
CWE-835 Medium
No
No
0.103.9-1.el7, 0.103.9-1.el8, 0.103.9-1.fc37, 1.0.2-1.el9, 1.0.2-1.fc38 16.08.2023 SB20230816163
SB20230821217
SB20230821218
and 21 more
#VU72298 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2023-20052
CWE-611 Medium
Available
No
0.103.8-1.el7, 0.103.8-1.el8, 0.103.8-1.el9, 0.103.8-1.fc36, 0.103.8-1.fc37, 0.103.8-3.el7, 0.103.8-3.fc36 15.02.2023 SB2023021569
SB2023021570
SB2023022043
and 17 more
#VU72297 - Heap-based Buffer Overflow
CVE-2023-20032
CWE-122 Critical
No
No
0.103.8-1.el7, 0.103.8-1.el8, 0.103.8-1.el9, 0.103.8-1.fc36, 0.103.8-1.fc37, 0.103.8-3.el7, 0.103.8-3.el8, 0.103.8-3.fc36 15.02.2023 SB2023021569
SB2023021570
SB2023022043
and 18 more
#VU62802 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2022-20771
CWE-835 Medium
No
No
0.103.6-1.el7, 0.103.6-1.el8, 0.103.6-1.el9, 0.103.6-1.fc34, 0.103.6-1.fc35, 0.103.6-1.fc36 04.05.2022 SB2022050437
SB2022051732
SB2022051836
and 14 more
#VU62801 - NULL Pointer Dereference
CVE-2022-20796
CWE-476 Medium
No
No
0.103.6-1.el7, 0.103.6-1.el8, 0.103.6-1.el9, 0.103.6-1.fc34, 0.103.6-1.fc35, 0.103.6-1.fc36 04.05.2022 SB2022050437
SB2022051732
SB2022051836
and 11 more
#VU62800 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2022-20770
CWE-835 Medium
No
No
0.103.6-1.el7, 0.103.6-1.el8, 0.103.6-1.el9, 0.103.6-1.fc34, 0.103.6-1.fc35, 0.103.6-1.fc36 04.05.2022 SB2022050437
SB2022051732
SB2022051836
and 14 more
#VU62798 - Missing release of memory after effective lifetime
CVE-2022-20785
CWE-401 Medium
No
No
0.103.6-1.el7, 0.103.6-1.el8, 0.103.6-1.el9, 0.103.6-1.fc34, 0.103.6-1.fc35, 0.103.6-1.fc36 04.05.2022 SB2022050437
SB2022051732
SB2022051836
and 13 more


Showing elements 1 - 20 out of 47