<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T10:57:18.617108+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-04766</id>
    <title>bdu:2023-04766</title>
    <updated>2026-10-04T10:57:18.904533+00:00</updated>
    <content>bdu:2023-04766</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-04766"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0658</id>
    <title>certfr-2023-avi-0658 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits Cisco&lt;/span&gt;. Certaines d'entre…</title>
    <updated>2026-10-04T10:57:18.904573+00:00</updated>
    <content>certfr-2023-avi-0658</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0658"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cisco-sa-clamav-rnwneeee</id>
    <title>cisco-sa-clamav-rNwNEEee — ClamAV HFS+ File Scanning Infinite Loop Denial of Service Vulnerability</title>
    <updated>2026-10-04T10:57:18.904592+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.

This vulnerability is due to an incorrect check for completion when a file is decompressed, which may result in a loop condition that could cause the affected software to stop responding. An attacker could exploit this vulnerability by submitting a crafted HFS+ filesystem image to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to stop responding, resulting in a DoS condition on the affected software and consuming available system resources.

For a description of this vulnerability, see the ClamAV blog ["https://blog.clamav.net/2023/07/2023-08-16-releases.html"].

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cisco-sa-clamav-rnwneeee"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-la13761</id>
    <title>Withdrawn: CLEANSTART-2026-LA13761 — vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a denia…</title>
    <updated>2026-10-04T10:57:18.904626+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: clamav</p>
<p>Multiple security vulnerabilities affect the clamav package. A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-la13761"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-7944</id>
    <title>EUVD-2026-7944</title>
    <updated>2026-10-04T10:57:18.904651+00:00</updated>
    <content>EUVD-2026-7944</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-7944"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-20197</id>
    <title>fkie_cve-2023-20197</title>
    <updated>2026-10-04T10:57:18.904663+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.

 This vulnerability is due to an incorrect check for completion when a file is decompressed, which may result in a loop condition that could cause the affected software to stop responding. An attacker could exploit this vulnerability by submitting a crafted HFS+ filesystem image to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to stop responding, resulting in a DoS condition on the affected software and consuming available system resources.

 For a description of this vulnerability, see the ClamAV blog .</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-20197"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r7mw-p665-4533</id>
    <title>GHSA-r7mw-p665-4533</title>
    <updated>2026-10-04T10:57:18.904696+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.</p>
<p>This vulnerability is due to an incorrect check for completion when a file is decompressed, which may result in a loop condition that could cause the affected software to stop responding. An attacker could exploit this vulnerability by submitting a crafted HFS+ filesystem image to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to stop responding, resulting in a DoS condition on the affected software and consuming available system resources.</p>
<p>For a description of this vulnerability, see the ClamAV blog .</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r7mw-p665-4533"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-20197</id>
    <title>gsd-2023-20197</title>
    <updated>2026-10-04T10:57:18.904717+00:00</updated>
    <content>gsd-2023-20197</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-20197"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1540</id>
    <title>OESA-2023-1540 — clamav security update</title>
    <updated>2026-10-04T10:57:18.904728+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP2: clamav</p>
<p>Clam AntiVirus (clamav) is an open source antivirus engine for detecting trojans,
viruses, malware &amp;amp; other malicious threats. The main purpose of this software is
the integration with mail servers (attachment scanning). The package provides a
flexible and scalable multi-threaded daemon, a command line scanner, and a tool
for automatic updating via Internet. The programs are based on a shared library
distributed with the Clam AntiVirus package, which you can use with your own software.
he virus database is based on the virus database from OpenAntiVirus, but contains
additional signatures and is KEPT UP TO DATE.</p>
<p>Security Fix(es):</p>
<p>A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.</p>
<p>This vulnerability is due to an incorrect check for completion when a file is decompressed, which may result in a loop condition that could cause the affected software to stop responding. An attacker could exploit this vulnerability by submitting a crafted HFS+ filesystem image to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to stop responding, resulting in a DoS condition on the affected software and consuming available system resources.</p>
<p>For a description of this vulnerability, see the ClamAV blog .(CVE-2023-20197)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1540"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13174-1</id>
    <title>openSUSE-SU-2024:13174-1 — clamav-0.103.9-1.1 on GA media</title>
    <updated>2026-10-04T10:57:18.904760+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>clamav-0.103.9-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13174-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2023:3435-1</id>
    <title>SUSE-SU-2023:3435-1 — Security update for clamav</title>
    <updated>2026-10-04T10:57:18.904776+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for clamav</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2023:3435-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-20197</id>
    <title>UBUNTU-CVE-2023-20197</title>
    <updated>2026-10-04T10:57:18.904790+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: clamav, Ubuntu:Pro:16.04:LTS: clamav, Ubuntu:Pro:18.04:LTS: clamav, Ubuntu:20.04:LTS: clamav, Ubuntu:22.04:LTS: clamav</p>
<p>A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.   This vulnerability is due to an incorrect check for completion when a file is decompressed, which may result in a loop condition that could cause the affected software to stop responding. An attacker could exploit this vulnerability by submitting a crafted HFS+ filesystem image to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to stop responding, resulting in a DoS condition on the affected software and consuming available system resources.   For a description of this vulnerability, see the ClamAV blog .</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-20197"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2090</id>
    <title>WID-SEC-W-2023-2090 — ClamAV &amp; Cisco Secure Endpoint: Mehrere Schwachstellen</title>
    <updated>2026-10-04T10:57:18.904818+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in ClamAV und Cisco Secure Endpoint ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2090"/>
  </entry>
</feed>
