Spamassassin

Vendor:

First CVE: Jun 15, 2005 · Active for 21 years

13
Total CVEs
More Total CVEs than 91% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Spamassassin over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 15, 2005
21 years ago
Most Recent CVE
Mar 25, 2021
1,947 days ago

CVE Severity & Scoring

Spamassassin13 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local3 (23.1%)
Network6 (46.2%)
Unknown4 (30.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (53.8%)
High2 (15.4%)
Unknown4 (30.8%)
User Interaction
None9 (69.2%)
Unknown4 (30.8%)
Required0 (0.0%)
Privileges Required
Low2 (15.4%)
High1 (7.7%)
None6 (46.2%)
Unknown4 (30.8%)

Top CVEs

Signals from CVEs in this product scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute arbitrary commands via a crafted message that is not properly
Jun 6, 20065.172NOYES
A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2.
Sep 17, 20189.837NONO
In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. With this, exploits can be inje
Mar 25, 20219.832NONO
In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the recommended fix but details will
Dec 12, 20197.528NONO
Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax.
Sep 17, 20187.826NONO
A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious Configuration (.cf) files can be configured to run system commands similar to
Jan 30, 20208.123NONO
A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious rule configuration (.cf) files can be configured to run system commands simil
Jan 30, 20208.123NONO
In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of sc
Dec 12, 20196.723NONO
A denial of service vulnerability was identified that exists in Apache SpamAssassin before 3.4.2. The vulnerability arises with certain unclosed tags in emails that cause markup to
Sep 17, 20185.323NONO
(1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (4) cpan/CPAN/scripts/cpan, (5) cpan/Digest-SHA/shasum, (6) cpan/Encode/bin/enc
Aug 2, 20167.823NONO

Exploit Exposure

Signals from CVEs in this product scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
7.7% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
7.7% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (13 CVEs).

Media Mentions

Signals from CVEs in this product scope (13 CVEs).

Top CNAs Publishing CVEs For Spamassassin

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.1.224.740.7%01
3.1.124.740.7%01
3.1.024.740.7%01
3.0.424.77.0%00
3.0.324.77.5%00
3.0.224.77.5%00
3.0.124.77.5%00