Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Clamav

First CVE: Nov 5, 2005Active for: 21 yearsTotal CVEs: 105
51.8
VTI Score
TOP TARGET

Clamav is a widely embedded antivirus engine and command-line scanner deployed across mail gateways, file-sharing systems, and content-filtering appliances to detect malware and suspicious files. Despite its narrow product footprint—the project centers on the core Clamav scanner itself—the software's deep integration into enterprise infrastructure and its role as a de facto standard in open-source mail and web filtering gives it prominence beyond typical single-product vendors. Vulnerabilities affecting the engine lean toward moderate severity and recur through weakness classes dominated by memory-safety issues: out-of-bounds reads and writes, buffer-boundary violations, and input-validation gaps that arise from parsing complex file formats and archive structures. These weakness patterns reflect the inherent parsing complexity of a signature-based scanner that must safely examine untrusted, often compressed or obfuscated files across numerous formats. Defenders should track Clamav updates as a supply-chain dependency wherever the scanner is embedded; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
105
Total CVEs
More Total CVEs than 99% of tracked vendors
4.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Clamav over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 5, 2005
20 years ago
Most Recent CVE
Jul 1, 2026
23 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (105 CVEs).

105 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-1459MEDIUM
The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10
Mar 21, 20124.371NONO
CVE-2012-1457MEDIUM
The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka
Mar 21, 20124.370NONO
CVE-2012-1443MEDIUM
The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protectio
Mar 21, 20124.369NONO
CVE-2024-20328MEDIUM
A vulnerability in the VirusEvent feature of ClamAV could allow a local attacker to inject arbitrary commands with the privileges of the application service account.The vulnerabili
Mar 1, 20245.358NONO
CVE-2012-1458MEDIUM
The Microsoft CHM file parser in ClamAV 0.96.4 and Sophos Anti-Virus 4.61.0 allows remote attackers to bypass malware detection via a crafted reset interval in the LZXC header of a
Mar 21, 20124.356NONO
CVE-2023-20032CRITICAL
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earli
Mar 1, 20239.848NONO
CVE-2026-20213HIGH
A vulnerability in the PE file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from
Jul 1, 20267.537NONO
CVE-2006-4018HIGH
Heap-based buffer overflow in the pefromupx function in libclamav/upx.c in Clam AntiVirus (ClamAV) 0.81 through 0.88.3 allows remote attackers to execute arbitrary code via a craft
Aug 8, 20067.537NOYES
CVE-2026-20214HIGH
A vulnerability in the FSG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from
Jul 1, 20267.536NONO
CVE-2012-1419MEDIUM
The TAR file parser in ClamAV 0.96.4 and Quick Heal (aka Cat QuickHeal) 11.00 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial [aliases] cha
Mar 21, 20124.336NONO
View all 105 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products105 CVEs
45%
46%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local23 (21.9%)
Network39 (37.1%)
Unknown43 (41.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low62 (59.0%)
High0 (0.0%)
Unknown43 (41.0%)
User Interaction
None41 (39.0%)
Unknown43 (41.0%)
Required21 (20.0%)
Privileges Required
Low3 (2.9%)
High0 (0.0%)
None59 (56.2%)
Unknown43 (41.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (105 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
1.0% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Clamav.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Clamav — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Clamav's Products

View all 4 CNAs →

Top CWEs