CVE-2016-1405: Cisco Email Security Appliance
High severity, CVSS 7.5. EPSS: 3.4% chance of exploitation in the next 30 days.
libclamav in ClamAV (aka Clam AntiVirus), as used in Advanced Malware Protection (AMP) on Cisco Email Security Appliance (ESA) devices before 9.7.0-125 and Web Security Appliance (WSA) devices before 9.0.1-135 and 9.1.x before 9.1.1-041, allows remote attackers to cause a denial of service (AMP process restart) via a crafted document, aka Bug IDs CSCuv78533 and CSCuw60503.
Affected products
- Cisco Email Security Appliance: version 9.6.0-042 only
- Cisco Web Security Appliance: version 8.8.0-085 only; version 9.1.0-070 only; version 9.5.0-284 only
- Clamav Clamav: any version
Published 2016-06-08. Last modified 2026-06-17.