← All CVEs

CVE-2006-1615

high · 10

Multiple format string vulnerabilities in the logging code in Clam AntiVirus (ClamAV) before 0.88.1 might allow remote attackers to execute arbitrary code. NOTE: as of 20060410, it is unclear whether this is a vulnerability, as there is some evidence that the arguments are actually being sanitized properly.

10
CVSS
11.4%
EPSS (exploit prob.)
96th
EPSS percentile
2006-04-06
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-134

Affected products

VendorProductAffected versions
clamavclamav<= 0.88
clamavclamav0.01
clamavclamav0.02
clamavclamav0.3
clamavclamav0.03
clamavclamav0.05
clamavclamav0.8
clamavclamav0.10
clamavclamav0.12
clamavclamav0.13
clamavclamav0.14
clamavclamav0.14
clamavclamav0.15
clamavclamav0.20
clamavclamav0.21
clamavclamav0.22
clamavclamav0.23
clamavclamav0.24
clamavclamav0.51
clamavclamav0.52
clamavclamav0.53
clamavclamav0.54
clamavclamav0.60
clamavclamav0.60p
clamavclamav0.65
clamavclamav0.66
clamavclamav0.67
clamavclamav0.67-1
clamavclamav0.68
clamavclamav0.68.1
clamavclamav0.70
clamavclamav0.70
clamavclamav0.71
clamavclamav0.72
clamavclamav0.73
clamavclamav0.74
clamavclamav0.75
clamavclamav0.75.1
clamavclamav0.80
clamavclamav0.80

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2006-1615