445
VMScore

CVE-2016-1405

Published: 08/06/2016 Updated: 28/11/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

libclamav in ClamAV (aka Clam AntiVirus), as used in Advanced Malware Protection (AMP) on Cisco Email Security Appliance (ESA) devices prior to 9.7.0-125 and Web Security Appliance (WSA) devices prior to 9.0.1-135 and 9.1.x prior to 9.1.1-041, allows remote malicious users to cause a denial of service (AMP process restart) via a crafted document, aka Bug IDs CSCuv78533 and CSCuw60503.

Vulnerable Product Search on Vulmon Subscribe to Product

clamav clamav

cisco email_security_appliance 9.6.0-042

cisco web_security_appliance 9.5.0-284

cisco web_security_appliance 9.1.0-070

cisco web_security_appliance 8.8.0-085

Vendor Advisories

ClamAV could be made to crash or run programs if it processed a specially crafted file ...