<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 22:14:46 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-04766</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-04766</link>
      <description>bdu:2023-04766</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-04766</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0658 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits Cisco&lt;/span&gt;. Certaines d'entre…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0658</link>
      <description>certfr-2023-avi-0658</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0658</guid>
    </item>
    <item>
      <title>cisco-sa-clamav-rNwNEEee — ClamAV HFS+ File Scanning Infinite Loop Denial of Service Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-clamav-rnwneeee</link>
      <description>&lt;p&gt;A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.&#13;
&#13;
This vulnerability is due to an incorrect check for completion when a file is decompressed, which may result in a loop condition that could cause the affected software to stop responding. An attacker could exploit this vulnerability by submitting a crafted HFS+ filesystem image to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to stop responding, resulting in a DoS condition on the affected software and consuming available system resources.&#13;
&#13;
For a description of this vulnerability, see the ClamAV blog [&amp;#34;https://blog.clamav.net/2023/07/2023-08-16-releases.html&amp;#34;].&#13;
&#13;
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.&#13;
&#13;
This vulnerability is due to an incorrect check for completion when a file is decompressed, which may result in a loop condition that could cause the affected software to stop responding. An attacker could exploit this vulnerability by submitting a crafted HFS+ filesystem image to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to stop responding, resulting in a DoS condition on the affected software and consuming available system resources.&#13;
&#13;
For a description of this vulnerability, see the ClamAV blog [&amp;#34;https://blog.clamav.net/2023/07/2023-08-16-releases.html&amp;#34;].&#13;
&#13;
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-clamav-rnwneeee</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-LA13761 — vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a denia…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-la13761</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: clamav&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the clamav package. A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: clamav&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the clamav package. A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-la13761</guid>
    </item>
    <item>
      <title>EUVD-2026-7944</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-7944</link>
      <description>EUVD-2026-7944</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-7944</guid>
    </item>
    <item>
      <title>fkie_cve-2023-20197</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-20197</link>
      <description>&lt;p&gt;A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.&#13;
&#13; This vulnerability is due to an incorrect check for completion when a file is decompressed, which may result in a loop condition that could cause the affected software to stop responding. An attacker could exploit this vulnerability by submitting a crafted HFS+ filesystem image to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to stop responding, resulting in a DoS condition on the affected software and consuming available system resources.&#13;
&#13; For a description of this vulnerability, see the ClamAV blog .&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.&#13;
&#13; This vulnerability is due to an incorrect check for completion when a file is decompressed, which may result in a loop condition that could cause the affected software to stop responding. An attacker could exploit this vulnerability by submitting a crafted HFS+ filesystem image to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to stop responding, resulting in a DoS condition on the affected software and consuming available system resources.&#13;
&#13; For a description of this vulnerability, see the ClamAV blog .&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-20197</guid>
    </item>
    <item>
      <title>GHSA-r7mw-p665-4533</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r7mw-p665-4533</link>
      <description>&lt;p&gt;A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.&lt;/p&gt;
&lt;p&gt;This vulnerability is due to an incorrect check for completion when a file is decompressed, which may result in a loop condition that could cause the affected software to stop responding. An attacker could exploit this vulnerability by submitting a crafted HFS+ filesystem image to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to stop responding, resulting in a DoS condition on the affected software and consuming available system resources.&lt;/p&gt;
&lt;p&gt;For a description of this vulnerability, see the ClamAV blog .&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.&lt;/p&gt;
&lt;p&gt;This vulnerability is due to an incorrect check for completion when a file is decompressed, which may result in a loop condition that could cause the affected software to stop responding. An attacker could exploit this vulnerability by submitting a crafted HFS+ filesystem image to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to stop responding, resulting in a DoS condition on the affected software and consuming available system resources.&lt;/p&gt;
&lt;p&gt;For a description of this vulnerability, see the ClamAV blog .&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r7mw-p665-4533</guid>
    </item>
    <item>
      <title>gsd-2023-20197</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-20197</link>
      <description>gsd-2023-20197</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-20197</guid>
    </item>
    <item>
      <title>OESA-2023-1540 — clamav security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1540</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP2: clamav&lt;/p&gt;
&lt;p&gt;Clam AntiVirus (clamav) is an open source antivirus engine for detecting trojans,
viruses, malware &amp;amp;amp; other malicious threats. The main purpose of this software is
the integration with mail servers (attachment scanning). The package provides a
flexible and scalable multi-threaded daemon, a command line scanner, and a tool
for automatic updating via Internet. The programs are based on a shared library
distributed with the Clam AntiVirus package, which you can use with your own software.
he virus database is based on the virus database from OpenAntiVirus, but contains
additional signatures and is KEPT UP TO DATE.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.&lt;/p&gt;
&lt;p&gt;This vulnerability is due to an incorrect check for completion when a file is decompressed, which may result in a loop condition that could cause the affected software to stop responding. An attacker could exploit this vulnerability by submitting a crafted HFS+ filesystem image to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to stop responding, resulting in a DoS condition on the affected software and consuming available system resources.&lt;/p&gt;
&lt;p&gt;For a description of this vulnerability, see the ClamAV blog .(CVE-2023-20197)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP2: clamav&lt;/p&gt;
&lt;p&gt;Clam AntiVirus (clamav) is an open source antivirus engine for detecting trojans,
viruses, malware &amp;amp;amp; other malicious threats. The main purpose of this software is
the integration with mail servers (attachment scanning). The package provides a
flexible and scalable multi-threaded daemon, a command line scanner, and a tool
for automatic updating via Internet. The programs are based on a shared library
distributed with the Clam AntiVirus package, which you can use with your own software.
he virus database is based on the virus database from OpenAntiVirus, but contains
additional signatures and is KEPT UP TO DATE.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.&lt;/p&gt;
&lt;p&gt;This vulnerability is due to an incorrect check for completion when a file is decompressed, which may result in a loop condition that could cause the affected software to stop responding. An attacker could exploit this vulnerability by submitting a crafted HFS+ filesystem image to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to stop responding, resulting in a DoS condition on the affected software and consuming available system resources.&lt;/p&gt;
&lt;p&gt;For a description of this vulnerability, see the ClamAV blog .(CVE-2023-20197)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1540</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:13174-1 — clamav-0.103.9-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13174-1</link>
      <description>&lt;p&gt;clamav-0.103.9-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;clamav-0.103.9-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:13174-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2023:3435-1 — Security update for clamav</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2023:3435-1</link>
      <description>&lt;p&gt;Security update for clamav&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for clamav&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2023:3435-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-20197</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-20197</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: clamav, Ubuntu:Pro:16.04:LTS: clamav, Ubuntu:Pro:18.04:LTS: clamav, Ubuntu:20.04:LTS: clamav, Ubuntu:22.04:LTS: clamav&lt;/p&gt;
&lt;p&gt;A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.   This vulnerability is due to an incorrect check for completion when a file is decompressed, which may result in a loop condition that could cause the affected software to stop responding. An attacker could exploit this vulnerability by submitting a crafted HFS+ filesystem image to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to stop responding, resulting in a DoS condition on the affected software and consuming available system resources.   For a description of this vulnerability, see the ClamAV blog .&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: clamav, Ubuntu:Pro:16.04:LTS: clamav, Ubuntu:Pro:18.04:LTS: clamav, Ubuntu:20.04:LTS: clamav, Ubuntu:22.04:LTS: clamav&lt;/p&gt;
&lt;p&gt;A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.   This vulnerability is due to an incorrect check for completion when a file is decompressed, which may result in a loop condition that could cause the affected software to stop responding. An attacker could exploit this vulnerability by submitting a crafted HFS+ filesystem image to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to stop responding, resulting in a DoS condition on the affected software and consuming available system resources.   For a description of this vulnerability, see the ClamAV blog .&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-20197</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2090 — ClamAV &amp; Cisco Secure Endpoint: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2090</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in ClamAV und Cisco Secure Endpoint ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in ClamAV und Cisco Secure Endpoint ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2090</guid>
    </item>
  </channel>
</rss>
