Known vulnerabilities in libclamav12
Vendor:
SUSE
Software:
libclamav12
Software CPE:
cpe:2.3:o:suse:libclamav12:*:*:*:*:*:suse_linux:*:*
Website:
https://www.suse.com/
Total vulnerabilities:
15
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
Vulnerabilities (15)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU136659 - Release of invalid pointer or reference CVE-2026-20217 |
CWE-763 | Medium | 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1 | 01.07.2026 |
SB2026070169 SB2026070205 SB2026070876 and 7 more |
||
| #VU136660 - Integer overflow CVE-2026-20213 |
CWE-190 | High | 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1 | 01.07.2026 |
SB2026070169 SB2026070205 SB2026070876 and 3 more |
||
| #VU136661 - Allocation of Resources Without Limits or Throttling CVE-2026-20216 |
CWE-770 | Medium | 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1 | 01.07.2026 |
SB2026070169 SB2026070205 SB2026070876 and 7 more |
||
| #VU136662 - Integer underflow CVE-2026-20214 |
CWE-191 | High | 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1 | 01.07.2026 |
SB2026070169 SB2026070205 SB2026070876 and 7 more |
||
| #VU136663 - Improper input validation CVE-2026-20243 |
CWE-20 | Medium | 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1 | 01.07.2026 |
SB2026070169 SB2026070205 SB2026070876 and 3 more |
||
| #VU136664 - Integer overflow CVE-2026-20215 |
CWE-190 | High | 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1 | 01.07.2026 |
SB2026070169 SB2026070205 SB2026070876 and 7 more |
||
| #VU136665 - Improper input validation CVE-2026-20244 |
CWE-20 | Medium | 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1 | 01.07.2026 |
SB2026070169 SB2026070205 SB2026070876 and 7 more |
||
| #VU126498 - Out-of-bounds write CVE-2026-41676 |
CWE-787 | Medium | 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1 | 20.04.2026 |
SB2026042021 SB2026061905 SB2026061906 and 46 more |
||
| #VU123663 - Error Handling CVE-2026-20031 |
CWE-388 | Medium | 1.5.2-3.53.1, 1.5.2-150400.13.5.1, 1.5.2-150600.18.25.1 | 10.03.2026 |
SB2026031002 SB2026031769 SB2026041506 and 6 more |
||
| #VU103240 - Heap-based Buffer Overflow CVE-2025-20128 |
CWE-122 | Medium | 1.4.2-3.36.1, 1.4.2-150200.8.3.1, 1.4.2-150600.18.6.1 | 22.01.2025 |
SB2025012288 SB2025012289 SB2025012778 and 5 more |
||
| #VU96825 - Out-of-bounds read CVE-2024-20505 |
CWE-125 | Medium | 1.4.2-3.36.1, 1.4.2-150200.8.3.1, 1.4.2-150600.18.6.1 | 05.09.2024 |
SB2024090511 SB20240905109 SB20240905110 and 16 more |
||
| #VU96824 - UNIX Symbolic Link (Symlink) Following CVE-2024-20506 |
CWE-61 | Low | 1.4.2-3.36.1, 1.4.2-150200.8.3.1, 1.4.2-150600.18.6.1 | 05.09.2024 |
SB2024090511 SB20240905109 SB20240905110 and 13 more |
||
| #VU88800 - Improper input validation CVE-2024-20380 |
CWE-20 | Medium | 1.4.2-3.36.1, 1.4.2-150200.8.3.1, 1.4.2-150600.18.6.1 | 17.04.2024 |
SB20240417143 SB2025020361 SB2025020362 and 2 more |
||
| #VU79633 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2023-20197 |
CWE-835 | Medium | 1.4.2-3.36.1, 1.4.2-150200.8.3.1, 1.4.2-150600.18.6.1 | 16.08.2023 |
SB20230816163 SB20230821217 SB20230821218 and 21 more |
||
| #VU14162 - Stack-based buffer overflow CVE-2018-14679 |
CWE-121 | Low | 1.4.2-3.36.1, 1.4.2-150200.8.3.1, 1.4.2-150600.18.6.1 | 01.08.2018 |
SB2018080114 SB2018080302 SB2018080606 and 21 more |