Known vulnerabilities in libclamav12

Vendor: SUSE
Software: libclamav12
Software CPE: cpe:2.3:o:suse:libclamav12:*:*:*:*:*:suse_linux:*:*
Total vulnerabilities: 15
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting libclamav12 libclamav12 is affected by 15 known vulnerabilities: 3 high, 10 medium, 2 low Critical High Medium Low

Vulnerabilities (15)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU136659 - Release of invalid pointer or reference
CVE-2026-20217
CWE-763 Medium
No
No
1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1 01.07.2026 SB2026070169
SB2026070205
SB2026070876
and 7 more
#VU136660 - Integer overflow
CVE-2026-20213
CWE-190 High
No
No
1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1 01.07.2026 SB2026070169
SB2026070205
SB2026070876
and 3 more
#VU136661 - Allocation of Resources Without Limits or Throttling
CVE-2026-20216
CWE-770 Medium
No
No
1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1 01.07.2026 SB2026070169
SB2026070205
SB2026070876
and 7 more
#VU136662 - Integer underflow
CVE-2026-20214
CWE-191 High
No
No
1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1 01.07.2026 SB2026070169
SB2026070205
SB2026070876
and 7 more
#VU136663 - Improper input validation
CVE-2026-20243
CWE-20 Medium
No
No
1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1 01.07.2026 SB2026070169
SB2026070205
SB2026070876
and 3 more
#VU136664 - Integer overflow
CVE-2026-20215
CWE-190 High
No
No
1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1 01.07.2026 SB2026070169
SB2026070205
SB2026070876
and 7 more
#VU136665 - Improper input validation
CVE-2026-20244
CWE-20 Medium
No
No
1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1 01.07.2026 SB2026070169
SB2026070205
SB2026070876
and 7 more
#VU126498 - Out-of-bounds write
CVE-2026-41676
CWE-787 Medium
No
No
1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1 20.04.2026 SB2026042021
SB2026061905
SB2026061906
and 46 more
#VU123663 - Error Handling
CVE-2026-20031
CWE-388 Medium
No
No
1.5.2-3.53.1, 1.5.2-150400.13.5.1, 1.5.2-150600.18.25.1 10.03.2026 SB2026031002
SB2026031769
SB2026041506
and 6 more
#VU103240 - Heap-based Buffer Overflow
CVE-2025-20128
CWE-122 Medium
No
No
1.4.2-3.36.1, 1.4.2-150200.8.3.1, 1.4.2-150600.18.6.1 22.01.2025 SB2025012288
SB2025012289
SB2025012778
and 5 more
#VU96825 - Out-of-bounds read
CVE-2024-20505
CWE-125 Medium
No
No
1.4.2-3.36.1, 1.4.2-150200.8.3.1, 1.4.2-150600.18.6.1 05.09.2024 SB2024090511
SB20240905109
SB20240905110
and 16 more
#VU96824 - UNIX Symbolic Link (Symlink) Following
CVE-2024-20506
CWE-61 Low
No
No
1.4.2-3.36.1, 1.4.2-150200.8.3.1, 1.4.2-150600.18.6.1 05.09.2024 SB2024090511
SB20240905109
SB20240905110
and 13 more
#VU88800 - Improper input validation
CVE-2024-20380
CWE-20 Medium
No
No
1.4.2-3.36.1, 1.4.2-150200.8.3.1, 1.4.2-150600.18.6.1 17.04.2024 SB20240417143
SB2025020361
SB2025020362
and 2 more
#VU79633 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2023-20197
CWE-835 Medium
No
No
1.4.2-3.36.1, 1.4.2-150200.8.3.1, 1.4.2-150600.18.6.1 16.08.2023 SB20230816163
SB20230821217
SB20230821218
and 21 more
#VU14162 - Stack-based buffer overflow
CVE-2018-14679
CWE-121 Low
No
No
1.4.2-3.36.1, 1.4.2-150200.8.3.1, 1.4.2-150600.18.6.1 01.08.2018 SB2018080114
SB2018080302
SB2018080606
and 21 more