Darold maintains a focused security scanning and filtering utility, SquidClamAV, that integrates antivirus capabilities with proxy caching for content filtering. The vendor's observed vulnerability footprint centers on web-layer input-handling and memory-safety issues, including cross-site scripting and buffer-boundary violations typical of integration-heavy filtering software; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Darold over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-3501MEDIUM The squidclamav_check_preview_handler function in squidclamav.c in SquidClamav 5.x before 5.8 and 6.x before 6.7 passes an unescaped URL to a system command call, which allows remo | Aug 25, 2012 | 5.0 | 19 | NO | NO |
CVE-2012-4667MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in SquidClamav 5.x before 5.8 allow remote attackers to inject arbitrary web script or HTML via the (1) url, (2) virus, (3) sour | Aug 25, 2012 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Darold.
Media articles that mention a CVE ID that affects a product developed by Darold — matched by CVE ID, not by vendor name.