CVE-2008-3914 details multiple unspecified vulnerabilities in ClamAV versions prior to 0.94, specifically involving file descriptor leaks in libclamav/others.c and libclamav/sis.c. This vulnerability carries a critical CVSS score of 10.0, indicating a network-based attack with low complexity, requiring no authentication, and leading to complete compromise of confidentiality, integrity, and availability. Despite its severity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.93.3CPE matchmatch criteria | cpe:2.3:a:clamav:clamav:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2008-3914
Oct 13, 2020Multiple unspecified vulnerabilities in ClamAV before 0.94 have unknown impact and attack vectors related to file descriptor leaks on the "error path" in (1) libclamav/others.c and (2) libclamav/sis.c.
Sep 2, 2008