Dismissed
(no matching packages found)
Permalink
CVE-2026-20345
7.5 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): None (N)
- Integrity (I): None (N)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): None (N)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): High (H)
Activity log
- Created & dismissed (no matching packages found) suggestion
ClamAV GPT File Format Processing Memory Corruption Vulnerability
A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper handling of an endian conversion operation, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted GPT file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
References
Affected products
Cisco Secure Endpoint
- ==1.6.0
- ==1.8.1
- ==1.11.0
- ==1.19.0
- ==1.14.0
- ==1.9.0
- ==1.8.4
- ==1.11.1
- ==1.24.5
- ==1.12.2
- ==1.10.2
- ==1.12.1
- ==1.9.1
- ==1.12.5
- ==2.0.2
- ==1.12.4
- ==1.12.3
- ==1.21.0
- ==1.12.6
- ==1.16.0
- ==1.15.2
- ==1.7.0
- ==1.8.0
- ==1.10.1
- ==1.1.0
- ==1.22.2
- ==1.10.0
- ==2.4.0
- ==1.12.0