CVE-2015-1461: Clamav

High severity, CVSS 7.5. EPSS: 2.8% chance of exploitation in the next 30 days.

ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted (1) Yoda's crypter or (2) mew packer file, related to a "heap out of bounds condition."

Affected products

  • Clamav Clamav: up to and including 0.98.5
  • Fedoraproject Fedora: version 20 only; version 21 only

Published 2015-02-03. Last modified 2026-06-17.