ClamAV(Clam AntiVirus)是ClamAV团队的一套免费且开源的杀毒软件。该软件用于检测木马、病毒、恶意软件和其他恶意威胁。 ClamAV存在安全漏洞,该漏洞源于XML外部实体注入,未经身份验证的远程攻击者利用该漏洞可以访问受影响设备上的敏感信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cisco | Cisco Secure Endpoint | 6.0.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CVE-2023-20052, information leak vulnerability in the DMG file parser of ClamAV | https://github.com/nokn0wthing/CVE-2023-20052 | POC Details |
| 2 | CVE-2023-20052 information leak vulnerability in the DMG file parser of ClamAV | https://github.com/cY83rR0H1t/CVE-2023-20052 | POC Details |
| 3 | None | https://github.com/MOHITSINGHPAPOLA/CVE-2023-20052 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2023-20032 | 9.8 CRITICAL | ClamAV 缓冲区错误漏洞 |
| CVE-2023-25653 | 7.5 HIGH | Improper calculations in ECC implementation can trigger a Denial-of-Service (DoS) |
| CVE-2023-20014 | 7.5 HIGH | Cisco Nexus Dashboard 资源管理错误漏洞 |
| CVE-2023-20009 | 6.5 MEDIUM | Cisco Secure Email 代码问题漏洞 |
| CVE-2023-20085 | 6.1 MEDIUM | Cisco Identity Services Engine 跨站脚本漏洞 |
| CVE-2023-20053 | 6.1 MEDIUM | Cisco Nexus Dashboard 跨站脚本漏洞 |
| CVE-2023-20075 | 6.0 MEDIUM | Cisco Secure Email 操作系统命令注入漏洞 |
| CVE-2022-20952 | 5.3 MEDIUM | Cisco Secure Web Appliance 输入验证错误漏洞 |
No comments yet