Clamav is a widely embedded antivirus engine and command-line scanner deployed across mail gateways, file-sharing systems, and content-filtering appliances to detect malware and suspicious files. Despite its narrow product footprint—the project centers on the core Clamav scanner itself—the software's deep integration into enterprise infrastructure and its role as a de facto standard in open-source mail and web filtering gives it prominence beyond typical single-product vendors. Vulnerabilities affecting the engine lean toward moderate severity and recur through weakness classes dominated by memory-safety issues: out-of-bounds reads and writes, buffer-boundary violations, and input-validation gaps that arise from parsing complex file formats and archive structures. These weakness patterns reflect the inherent parsing complexity of a signature-based scanner that must safely examine untrusted, often compressed or obfuscated files across numerous formats. Defenders should track Clamav updates as a supply-chain dependency wherever the scanner is embedded; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Clamav over time
Signals from CVEs in this vendor scope (105 CVEs).
105 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-1459MEDIUM The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10 | Mar 21, 2012 | 4.3 | 71 | NO | NO |
CVE-2012-1457MEDIUM The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka | Mar 21, 2012 | 4.3 | 70 | NO | NO |
CVE-2012-1443MEDIUM The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protectio | Mar 21, 2012 | 4.3 | 69 | NO | NO |
CVE-2024-20328MEDIUM A vulnerability in the VirusEvent feature of ClamAV could allow a local attacker to inject arbitrary commands with the privileges of the application service account.The vulnerabili | Mar 1, 2024 | 5.3 | 58 | NO | NO |
CVE-2012-1458MEDIUM The Microsoft CHM file parser in ClamAV 0.96.4 and Sophos Anti-Virus 4.61.0 allows remote attackers to bypass malware detection via a crafted reset interval in the LZXC header of a | Mar 21, 2012 | 4.3 | 56 | NO | NO |
CVE-2023-20032CRITICAL On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed:
A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earli | Mar 1, 2023 | 9.8 | 48 | NO | NO |
CVE-2026-20213HIGH A vulnerability in the PE file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from | Jul 1, 2026 | 7.5 | 37 | NO | NO |
CVE-2006-4018HIGH Heap-based buffer overflow in the pefromupx function in libclamav/upx.c in Clam AntiVirus (ClamAV) 0.81 through 0.88.3 allows remote attackers to execute arbitrary code via a craft | Aug 8, 2006 | 7.5 | 37 | NO | YES |
CVE-2026-20214HIGH A vulnerability in the FSG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from | Jul 1, 2026 | 7.5 | 36 | NO | NO |
CVE-2012-1419MEDIUM The TAR file parser in ClamAV 0.96.4 and Quick Heal (aka Cat QuickHeal) 11.00 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial [aliases] cha | Mar 21, 2012 | 4.3 | 36 | NO | NO |
Signals from CVEs in this vendor scope (105 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Clamav.
Media articles that mention a CVE ID that affects a product developed by Clamav — matched by CVE ID, not by vendor name.