Sploitus

CVE-2008-5050

No indexed exploits for CVE-2008-5050 yet

Off-by-one error in the get_unicode_name function (libclamav/vba_extract.c) in Clam Anti-Virus (ClamAV) before 0.94.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted VBA project file, which triggers a heap-based buffer overflow.

Affected products
Clamav
Clam Anti-virus Clamav
≤ 0.94, 0.01, 0.02, 0.03, 0.04, 0.05, 0.06, 0.10, 0.11, 0.12, 0.13, 0.14, 0.15, 0.20, 0.21, 0.22, 0.23, 0.24, 0.51, 0.52, 0.53, 0.54, 0.60, 0.60p, 0.65, 0.67, 0.68, 0.68.1, 0.70, 0.71, 0.72, 0.73, 0.74, 0.75, 0.75.1, 0.80, 0.80_rc1, 0.80_rc2, 0.80_rc3, 0.80_rc4
Fix
Available
CVSS 2.0
9.3 HIGH
EPSS
8.3% (94th percentile)
Weakness
CWE-119
NVD status
Modified
Published
2008-11-13
CVE-2008-5050 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2008-5050 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2008-5050 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.