437
VMScore

CVE-2022-20796

Published: 04/05/2022 Updated: 07/11/2023
CVSS v2 Base Score: 4.9 | Impact Score: 6.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 437
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

On May 4, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and previous versions and 0.104.2 and previous versions was disclosed: A vulnerability in Clam AntiVirus (ClamAV) versions 0.103.4, 0.103.5, 0.104.1, and 0.104.2 could allow an authenticated, local malicious user to cause a denial of service condition on an affected device. For a description of this vulnerability, see the ClamAV blog.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

clamav clamav 0.103.4

clamav clamav 0.103.5

clamav clamav 0.104.1

clamav clamav 0.104.2

cisco secure endpoint

fedoraproject fedora 34

fedoraproject fedora 35

fedoraproject fedora 36

debian debian linux 9.0

Vendor Advisories

Several security issues were fixed in ClamAV ...
Several security issues were fixed in ClamAV ...
On April 20, 2022, the following vulnerability in the ClamAV scanning library versions 01035 and earlier and 01042 and earlier was disclosed: A vulnerability in CHM file parser of Clam AntiVirus (ClamAV) versions 01040 through 01042 and LTS version 01035 and prior versions could allow an unauthenticated, remote attacker to cause a denial ...
On May 4, 2022, the following vulnerability in the ClamAV scanning library versions 01035 and earlier and 01042 and earlier was disclosed: A vulnerability in Clam AntiVirus (ClamAV) versions 01034, 01035, 01041, and 01042 could allow an authenticated, local attacker to cause a denial of service condition on an affected device For a des ...
On May 4, 2022, the following vulnerability in the ClamAV scanning library versions 01035 and earlier and 01042 and earlier was disclosed: A vulnerability in Clam AntiVirus (ClamAV) versions 01034, 01035, 01041, and 01042 could allow an authenticated, local attacker to cause a denial of service condition on an affected device For a d ...
possible NULL-pointer dereference crash in the scan verdict cache check ...
A vulnerability in the OOXML parsing module in Clam AntiVirus (ClamAV) Software version 01041 and LTS version 01034 and prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device The vulnerability is due to improper checks that may result in an invalid pointer read An attacker c ...
ALAS-2022-229 Amazon Linux 2022 Security Advisory: ALAS-2022-229 Advisory Release Date: 2022-12-06 16:42 Pacific ...