
CVE-2007-0451
https://notcve.org/view.php?id=CVE-2007-0451
16 Feb 2007 — Apache SpamAssassin before 3.1.8 allows remote attackers to cause a denial of service via long URLs in malformed HTML, which triggers "massive memory usage." Apache SpamAssassin versiones anteriores a 3.1.8, permite a atacantes remotos causar una denegación de servicio por medio de URLs largas en HTML malformado, que desencadena un "massive memory usage” • http://fedoranews.org/cms/node/2657 • CWE-399: Resource Management Errors •

CVE-2006-2447 – SpamAssassin spamd - Remote Command Execution
https://notcve.org/view.php?id=CVE-2006-2447
06 Jun 2006 — SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute arbitrary commands via a crafted message that is not properly handled when invoking spamd with the virtual pop username. • https://www.exploit-db.com/exploits/16920 •