Page 2 of 13 results (0.002 seconds)

CVSS: 9.8EPSS: 74%CPEs: 3EXPL: 2

06 Jun 2006 — SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute arbitrary commands via a crafted message that is not properly handled when invoking spamd with the virtual pop username. • https://www.exploit-db.com/exploits/16920 •

CVSS: 9.1EPSS: 19%CPEs: 1EXPL: 0

20 Nov 2005 — SpamAssassin 3.0.4 allows attackers to bypass spam detection via an e-mail with a large number of recipients ("To" addresses), which triggers a bus error in Perl. • http://issues.apache.org/SpamAssassin/show_bug.cgi?id=4570 •

CVSS: 7.5EPSS: 5%CPEs: 3EXPL: 0

15 Jun 2005 — Apache SpamAssassin 3.0.1, 3.0.2, and 3.0.3 allows remote attackers to cause a denial of service (CPU consumption and slowdown) via a message with a long Content-Type header without any boundaries. • http://bugs.gentoo.org/show_bug.cgi?id=94722 •