VDB
CVE-2011-1003
CVE-2011-1003
PUBLISHED
CVSS 6.800000190734863 MEDIUM
Double free vulnerability in the vba_read_project_strings function in vba_extract.c in libclamav in ClamAV before 0.97 might allow remote attackers to execute arbitrary code via crafted Visual Basic for Applications (VBA) data in a Microsoft Office document. NOTE: some of these details are obtained from third party information.
EPSS 9.44% · 93.0th percentile
Risk Scores
CVSS 2.0
6.800000190734863
EPSS Score
9.44%
93.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| clamav | clamav | 0.3, 0.03, 0.05 |
Timeline
- Feb 23, 2011 CVE Published
- Feb 4, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
- Nov 8, 2023 EPSS Score
References
- clamav-vbareadprojectstrings-dos(65544) vdb
- 1025100 vdb
- 46470 vdb
- http://git.clamav.net/gitweb?p=clamav-devel.git%3Ba=blob%3Bf=ChangeLog%3Bhb=clamav-0.97 url
- 70937 vdb
- [oss-security] 20110221 clamav 0.97 mailing-list
- http://git.clamav.net/gitweb?p=clamav-devel.git%3Ba=commit%3Bh=d21fb8d975f8c9688894a8cef4d50d977022e09f url
- ADV-2011-0458 vdb
- 43752 third-party-advisory
- ADV-2011-0453 vdb
- SUSE-SR:2011:005 vendor-advisory
- MDVA-2011:007 vendor-advisory
- https://wwws.clamav.net/bugzilla/show_bug.cgi?id=2486 url
- ADV-2011-0523 vdb
- FEDORA-2011-2743 vendor-advisory
- USN-1076-1 vendor-advisory
- [oss-security] 20110221 Re: clamav 0.97 mailing-list
- FEDORA-2011-2741 vendor-advisory
- 43392 third-party-advisory
- 43498 third-party-advisory
…and 3 more