ClamAV是ClamAV组织开源的一套杀毒软件。该软件用于检测木马、病毒、恶意软件和其他恶意威胁。 ClamAV 存在缓冲区错误漏洞,该漏洞源于GPT文件格式解析器对端序转换操作的不当处理,可能导致越界写入,攻击者可通过提交特制的GPT文件导致ClamAV扫描进程终止,造成拒绝服务。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Cisco | Cisco Secure Endpoint | 1.12.3 |
affected |
1.8.0 |
affected | ||
1.11.1 |
affected | ||
1.12.4 |
affected | ||
1.10.0 |
affected | ||
1.12.0 |
affected | ||
1.8.1 |
affected | ||
1.10.1 |
affected | ||
| … +21 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cisco | Cisco Secure Endpoint | 1.12.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-20348 | 7.5 HIGH | ClamAV XAR File Format Processing Memory Corruption Vulnerability |
| CVE-2026-20339 | 7.5 HIGH | ClamAV PESpin File Format Processing Integer Overflow Vulnerability |
| CVE-2026-20347 | 7.5 HIGH | ClamAV Mach-O File Format Processing Memory Corruption Vulnerability |
| CVE-2026-20346 | 7.5 HIGH | ClamAV PDF File Format Processing Memory Corruption Vulnerability |
| CVE-2026-20338 | 7.5 HIGH | ClamAV ZIP File Format Processing Memory Corruption Vulnerability |
| CVE-2026-20337 | 7.5 HIGH | ClamAV ZIP File Format Processing Memory Corruption Vulnerability |
No comments yet