Skip to main content

Vendor/product archive

apache / spamassassin CVEs

Beta · best-effort

13 CVEs tagged to apache / spamassassin2 Critical, 5 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2020-1931

Published Jan 30, 2020

A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious Configuration (.cf) files can be configured to run system commands similar t…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1930

Published Jan 30, 2020

A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious rule configuration (.cf) files can be configured to run system commands simi…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12420

Published Dec 12, 2019

In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the recommended fix but details wil…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11805

Published Dec 12, 2019

In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of s…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0451

Published Feb 16, 2007

Apache SpamAssassin before 3.1.8 allows remote attackers to cause a denial of service via long URLs in malformed HTML, which triggers "massive memory usage."

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2447

Published Jun 6, 2006

SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute arbitrary commands via a crafted message that is not properl…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3351

Published Nov 20, 2005

SpamAssassin 3.0.4 allows attackers to bypass spam detection via an e-mail with a large number of recipients ("To" addresses), which triggers a bus error in Perl.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1266

Published Jun 15, 2005

Apache SpamAssassin 3.0.1, 3.0.2, and 3.0.3 allows remote attackers to cause a denial of service (CPU consumption and slowdown) via a message with a long Content-Type header witho…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1