← Vulnerability feed

Vulnerability record · CVE-2008-3914 · published 11 September 2008

CVE-2008-3914: Clamav information exposure vulnerability

Clamav · Clamav

Multiple unspecified vulnerabilities in ClamAV before 0.94 have unknown impact and attack vectors related to file descriptor leaks on the "error path" in (1) libclamav/others.c and (2) libclamav/sis.c.

10.0 CVSS 2.0 High EPSS 3.6% · top 11.0% CWE-200 · Information exposure
10.0CVSS 2.0 base score
3.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
52References
16 Jun 2026Last modified by NVD

Description

Multiple unspecified vulnerabilities in ClamAV before 0.94 have unknown impact and attack vectors related to file descriptor leaks on the "error path" in (1) libclamav/others.c and (2) libclamav/sis.c.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://kolab.org/security/kolab-vendor-notice-22.txt Third Party Advisory
http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00004.html Mailing ListThird Party Advisory
http://secunia.com/advisories/31906 Third Party Advisory
http://secunia.com/advisories/31982 Third Party Advisory
http://secunia.com/advisories/32030 Third Party Advisory
http://secunia.com/advisories/32222 Third Party Advisory
http://secunia.com/advisories/32424 Third Party Advisory
http://secunia.com/advisories/32699 Third Party Advisory
http://security.gentoo.org/glsa/glsa-200809-18.xml Third Party Advisory
http://sourceforge.net/project/shownotes.php?group_id=86638&release_id=623661 PatchThird Party Advisory
http://support.apple.com/kb/HT3216 Third Party Advisory
http://svn.clamav.net/svn/clamav-devel/trunk/ChangeLog Vendor Advisory
http://www.debian.org/security/2008/dsa-1660 Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2008:189 Third Party Advisory
http://www.openwall.com/lists/oss-security/2008/09/03/2 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2008/09/04/13 Mailing List
http://www.securityfocus.com/bid/31051 PatchThird Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/31681 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1020828 Third Party AdvisoryVDB Entry
http://www.vupen.com/english/advisories/2008/2564 Permissions Required
http://www.vupen.com/english/advisories/2008/2780 Permissions Required
https://exchange.xforce.ibmcloud.com/vulnerabilities/45058 Third Party AdvisoryVDB Entry
https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00332.html Third Party Advisory
https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00348.html Third Party Advisory
https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1141 Issue Tracking
http://kolab.org/security/kolab-vendor-notice-22.txt Third Party Advisory
http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00004.html Mailing ListThird Party Advisory
http://secunia.com/advisories/31906 Third Party Advisory
http://secunia.com/advisories/31982 Third Party Advisory
http://secunia.com/advisories/32030 Third Party Advisory
http://secunia.com/advisories/32222 Third Party Advisory
http://secunia.com/advisories/32424 Third Party Advisory
http://secunia.com/advisories/32699 Third Party Advisory
http://security.gentoo.org/glsa/glsa-200809-18.xml Third Party Advisory
http://sourceforge.net/project/shownotes.php?group_id=86638&release_id=623661 PatchThird Party Advisory
http://support.apple.com/kb/HT3216 Third Party Advisory
http://svn.clamav.net/svn/clamav-devel/trunk/ChangeLog Vendor Advisory
http://www.debian.org/security/2008/dsa-1660 Third Party Advisory

Track CVE-2008-3914 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2010-0098Clamav vulnerabilityClamAV before 0.96 does not properly handle the (1) CAB and (2) 7z file formats, which allows remote attackers to bypass virus detection via a crafte…EPSS 4.9%10.0CVE-2009-1372Clamav memory buffer overflow vulnerabilityStack-based buffer overflow in the cli_url_canon function in libclamav/phishcheck.c in ClamAV before 0.95.1 allows remote attackers to cause a denial…EPSS 7.6%10.0CVE-2008-0728Clamav vulnerabilityThe unmew11 function in libclamav/mew.c in libclamav in ClamAV before 0.92.1 has unknown impact and attack vectors that trigger "heap corruption."EPSS 2.8%10.0CVE-2006-1615Clamav vulnerabilityMultiple format string vulnerabilities in the logging code in Clam AntiVirus (ClamAV) before 0.88.1 might allow remote attackers to execute arbitrary…EPSS 12%9.8CVE-2025-20260Clamav heap-based buffer overflow vulnerabilityA vulnerability in the PDF scanning processes of ClamAV could allow an unauthenticated, remote attacker to cause a buffer overflow condition, cause a…EPSS 1.6%9.8CVE-2023-20032Cisco secure endpoint classic buffer overflow vulnerabilityOn Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamA…EPSS 29%9.8CVE-2013-7087Clamav memory buffer overflow vulnerabilityClamAV before 0.97.7 has WWPack corrupt heap memoryEPSS 2.9%9.8CVE-2013-7088Clamav classic buffer overflow vulnerabilityClamAV before 0.97.7 has buffer overflow in the libclamav componentEPSS 3.1%

Source: NIST National Vulnerability Database (record CVE-2008-3914), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.