Vulnerabilities > Spamassassin

DATE CVE VULNERABILITY TITLE RISK
2007-06-11 CVE-2007-2873 Local Symlink Attack And Denial of Service vulnerability in SpamAssassin
SpamAssassin 3.1.x, 3.2.0, and 3.2.1 before 20070611, when running as root in unusual configurations using vpopmail or virtual users, allows local users to cause a denial of service (corrupt arbitrary files) via a symlink attack on a file that is used by spamd.
local
spamassassin
1.9
2004-10-20 CVE-2004-0796 Remote Denial Of Service vulnerability in SpamAssassin Malformed Email
SpamAssassin 2.5x, and 2.6x before 2.64, allows remote attackers to cause a denial of service via certain malformed messages.
network
low complexity
spamassassin
5.0
2003-12-31 CVE-2003-1557 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Spamassassin
Off-by-one buffer overflow in spamc of SpamAssassin 2.40 through 2.43, when using BSMTP mode ("-B"), allows remote attackers to execute arbitrary code via email containing headers with leading "." characters.
network
high complexity
spamassassin CWE-119
7.6