Spamassassin
Vendor:
First CVE: Jun 15, 2005 · Active for 21 years
13
Total CVEs
More Total CVEs than 91% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Spamassassin over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 15, 2005
21 years ago
Most Recent CVE
Mar 25, 2021
1,947 days ago
CVE Severity & Scoring
Spamassassin13 CVEs
46%
38%
15%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (23.1%)
Network6 (46.2%)
Unknown4 (30.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (53.8%)
High2 (15.4%)
Unknown4 (30.8%)
User Interaction
None9 (69.2%)
Unknown4 (30.8%)
Required0 (0.0%)
Privileges Required
Low2 (15.4%)
High1 (7.7%)
None6 (46.2%)
Unknown4 (30.8%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-2447MEDIUM SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute arbitrary commands via a crafted message that is not properly | Jun 6, 2006 | 5.1 | 72 | NO | YES |
CVE-2018-11780CRITICAL A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2. | Sep 17, 2018 | 9.8 | 37 | NO | NO |
CVE-2020-1946CRITICAL In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. With this, exploits can be inje | Mar 25, 2021 | 9.8 | 32 | NO | NO |
CVE-2019-12420HIGH In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the recommended fix but details will | Dec 12, 2019 | 7.5 | 28 | NO | NO |
CVE-2018-11781HIGH Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax. | Sep 17, 2018 | 7.8 | 26 | NO | NO |
CVE-2020-1931HIGH A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious Configuration (.cf) files can be configured to run system commands similar to | Jan 30, 2020 | 8.1 | 23 | NO | NO |
CVE-2020-1930HIGH A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious rule configuration (.cf) files can be configured to run system commands simil | Jan 30, 2020 | 8.1 | 23 | NO | NO |
CVE-2018-11805MEDIUM In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of sc | Dec 12, 2019 | 6.7 | 23 | NO | NO |
CVE-2017-15705MEDIUM A denial of service vulnerability was identified that exists in Apache SpamAssassin before 3.4.2. The vulnerability arises with certain unclosed tags in emails that cause markup to | Sep 17, 2018 | 5.3 | 23 | NO | NO |
CVE-2016-1238HIGH (1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (4) cpan/CPAN/scripts/cpan, (5) cpan/Digest-SHA/shasum, (6) cpan/Encode/bin/enc | Aug 2, 2016 | 7.8 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
7.7% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
7.7% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For Spamassassin
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.1.2 | 2 | 4.7 | 40.7% | 0 | 1 |
| 3.1.1 | 2 | 4.7 | 40.7% | 0 | 1 |
| 3.1.0 | 2 | 4.7 | 40.7% | 0 | 1 |
| 3.0.4 | 2 | 4.7 | 7.0% | 0 | 0 |
| 3.0.3 | 2 | 4.7 | 7.5% | 0 | 0 |
| 3.0.2 | 2 | 4.7 | 7.5% | 0 | 0 |
| 3.0.1 | 2 | 4.7 | 7.5% | 0 | 0 |