CVE-2006-5295
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 11%
from disclosure to weapon1 days
Published on NVDOct 16
1st PoC+1d
exploitation probability
11%top 5% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Unspecified vulnerability in ClamAV before 0.88.5 allows remote attackers to cause a denial of service (scanning service crash) via a crafted Compressed HTML Help (CHM) file that causes ClamAV to "read an invalid memory location."
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/2586⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://kolab.org/security/kolab-vendor-notice-13.txthttp://labs.idefense.com/intelligence/vulnerabilities/display.php?id=423http://secunia.com/advisories/22370http://secunia.com/advisories/22421http://secunia.com/advisories/22488http://secunia.com/advisories/22498http://secunia.com/advisories/22537http://secunia.com/advisories/22551http://secunia.com/advisories/22626http://security.gentoo.org/glsa/glsa-200610-10.xmlhttp://securitytracker.com/id?1017068https://exchange.xforce.ibmcloud.com/vulnerabilities/29608