CVE-2014-9050: Clamav

Medium severity, CVSS 5.0. EPSS: 4.9% chance of exploitation in the next 30 days.

Heap-based buffer overflow in the cli_scanpe function in libclamav/pe.c in ClamAV before 0.98.5 allows remote attackers to cause a denial of service (crash) via a crafted y0da Crypter PE file.

Affected products

  • Clamav Clamav: up to and including 0.94.3; version 0.01 only; version 0.02 only; version 0.3 only; version 0.03 only; version 0.05 only; …

Published 2014-12-01. Last modified 2026-06-17.