4 results (0.001 seconds)

CVSS: 9.8EPSS: 5%CPEs: 5EXPL: 0

31 Dec 2005 — Heap-based buffer overflow in bogofilter 0.96.2, 0.95.2, 0.94.14, 0.94.12, and other versions from 0.93.5 to 0.96.2, when using Unicode databases, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via "invalid input sequences" that lead to heap corruption when bogofilter or bogolexer converts character sets. • http://bogofilter.sourceforge.net/security/bogofilter-SA-2005-01 •

CVSS: 9.8EPSS: 4%CPEs: 5EXPL: 0

31 Dec 2005 — Heap-based buffer overflow in bogofilter and bogolexer 0.96.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via words that are longer than the input buffer used by flex. • http://bogofilter.sourceforge.net/security/bogofilter-SA-2005-02 •

CVSS: 7.5EPSS: 0%CPEs: 9EXPL: 0

04 Nov 2004 — The quoted-printable decoder in bogofilter 0.17.4 to 0.92.7 allows remote attackers to cause a denial of service (application crash) via mail headers that cause a line feed (LF) to be replaced by a null byte that is written to an incorrect memory address. • http://bogofilter.sourceforge.net/security/bogofilter-SA-2004-01 •

CVSS: 7.2EPSS: 0%CPEs: 1EXPL: 0

31 Dec 2002 — bogopass in bogofilter 0.9.0.4 allows local users to overwrite arbitrary files via a symlink attack on the bogopass temporary file. • http://archives.neohapsis.com/archives/bugtraq/2002-11/0367.html •