Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3186 articles · 183331 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-20244
cis · secure_endpoint

ClamAV DMG File Processing Denial of Service Vulnerability

Description

A vulnerability in the DMG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in DMG files during scanning, which may result in an integer overflow on 32-bit platforms only. An attacker could exploit this vulnerability by submitting a crafted file that contains DMG content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.

Affected Products

VendorProductVersions
cissecure_endpoint7.0.5, 6.2.19, 7.3.3, 7.2.13, 6.1.5, 6.3.1, 6.2.5, 7.3.5, 6.2.1, 7.2.7, 7.1.1, 6.3.5, 6.2.9, 7.3.1, 6.1.7, 7.2.11, 7.2.3, 7.1.5, 6.3.3, 7.3.9, 6.2.3, 6.1.9, 6.0.9, 7.2.5, 6.0.7, 6.3.7, 1.12.3, 1.8.0, 1.11.1, 1.12.4, 1.10.0, 1.12.0, 1.8.1, 1.10.1, 1.12.1, 1.12.6, 1.14.0, 1.10.2, 1.12.7, 1.12.2, 1.6.0, 1.9.0, 1.11.0, 1.7.0, 1.13.0, 1.8.4, 1.13.1, 1.9.1, 1.12.5, 1.13.2, 8.1.7.21512, 8.1.7, 8.1.5, 8.1.3.21242, 8.1.3, 8.1.5.21322, 8.1.7.21417, 1.14.1, 1.15.1, 1.15.2, 1.15.3, 1.15.4, 1.15.5, 1.15.6, 1.16.0, 1.16.1, 1.16.2, 1.16.3, 1.18.0, 1.18.1, 1.20.0, 1.21.0, 1.21.1, 1.21.2, 1.21.3, 1.22.0, 1.22.1, 1.22.2, 1.22.3, 1.22.4, 1.24.0, 1.24.1, 1.24.2, 1.24.3, 1.24.4, 1.26.0, 1.24.5, 1.26.1, 1.27.0, 1.15.0, 1.17.0, 1.17.1, 1.17.2, 1.19.0, 1.20.1, 1.20.2, 1.20.3, 1.20.4, 1.20.5, 1.20.6, 1.23.0, 1.23.1, 1.20.7, 1.20.8, 1.25.0, 1.25.1, 1.25.2, 1.27.1, 1.27.2, 7.3.13, 7.3.15, 7.4.1, 7.4.1.20425, 7.4.1.20439, 7.4.3, 7.4.3.20679, 7.4.5, 7.5.1.20813, 7.5.1.20833, 7.5.3, 7.5.5, 8.0.1.21160, 8.0.1.21164, 7.5.7, 7.5.9, 7.5.11, 8.1.7.21585, 7.5.13.21586, 7.5.13.21598, 8.2.1.21612, 8.2.1.21650, 7.5.15.21611, 7.5.17.21680, 8.2.3.30119, 8.2.4.30130, 8.4.0, 7.5.19, 8.4.1.30298, 8.4.2.30317, 8.4.1.30307, 7.5.20, 8.4.3, 8.4.4.30419, 8.4.4.30467, 7.5.21.21732, 8.4.5.30483

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
clamavclamavcve_cpe95%
open sourceclamavcert_advisory90%

References

  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-88cFYyxR

Related News (7 articles)

Tier A
Microsoft MSRC23d ago
CVE-2026-20244 ClamAV DMG File Processing Denial of Service Vulnerability
→ No new info (linked only)
Tier D
Help Net Security28d ago
New ClamAV security patch closes seven scanner bugs dating back two decades
→ No new info (linked only)
Tier B
BSI Advisories32d ago
[NEU] [mittel] ClamAV: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR32d ago
Multiples vulnérabilités dans les produits Cisco (02 juillet 2026)
→ No new info (linked only)
Tier B
CERT-FR32d ago
Multiples vulnérabilités dans ClamAV (02 juillet 2026)
→ No new info (linked only)
Tier C
VulDB32d ago
CVE-2026-20244 | Cisco Secure Endpoint up to 8.4.5.30483 DMG File Format Parser buffer overflow (cisco-sa-clamav-88cFYyxR)
→ No new info (linked only)
Tier A
Cisco Security32d ago
ClamAV Vulnerabilities Affecting Cisco Products: July 2026
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited❌ No
CWECWE-120
PublishedJul 1, 2026
Last enriched32d agov2
Trending Score6
Source articles7
Independent6
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-20316
Cisco Secure Firewall Management Center Software Static Credential Vulnerability
Trending: 78
HIGHCVE-2026-20157
Cisco RoomOS Security Hardening Release - Missing Encryption Vulnerabilities
Trending: 6
HIGHCVE-2026-20215
ClamAV 7Zip File Format Processing Out-of-Bounds Memory Corruption Vulnerability
Trending: 6
HIGHCVE-2026-20216
ClamAV InstallShield File Format Processing Resource Exhaustion Vulnerability
Trending: 5
HIGHCVE-2026-20243
ClamAV ALZ Archive Processing Denial of Service Vulnerability
Trending: 5

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 1, 2026
Discovered by ZDM
Jul 1, 2026
Updated: description, severity
Jul 1, 2026

Version History

v2
Last enriched 32d ago
v2Tier C32d ago

Updated severity to CRITICAL, corrected vendor and product names, and provided a new description with details about the buffer overflow vulnerability.

descriptionseverity
via VulDB
v132d ago

Initial creation