Bogofilter is a lightweight, open-source email filtering tool designed to detect spam through statistical analysis, with a narrow but established deployment across mail systems and personal email clients. The project's disclosures center on its core filtering engine and reflect buffer-management weaknesses characteristic of C-based text-processing utilities. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bogofilter Project over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-5468HIGH Heap-based buffer overflow in iconvert.c in the bogolexer component in Bogofilter before 1.2.3 allows remote attackers to cause a denial of service (crash) and possibly execute arb | Dec 18, 2012 | 7.5 | 27 | NO | NO |
CVE-2005-4591HIGH Heap-based buffer overflow in bogofilter 0.96.2, 0.95.2, 0.94.14, 0.94.12, and other versions from 0.93.5 to 0.96.2, when using Unicode databases, allows remote attackers to cause | Dec 31, 2005 | 7.5 | 21 | NO | NO |
CVE-2005-4592HIGH Heap-based buffer overflow in bogofilter and bogolexer 0.96.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via words that are lo | Dec 31, 2005 | 7.5 | 21 | NO | NO |
CVE-2010-2494MEDIUM Multiple buffer underflows in the base64 decoder in base64.c in (1) bogofilter and (2) bogolexer in bogofilter before 1.2.2 allow remote attackers to cause a denial of service (hea | Jul 8, 2010 | 5.0 | 19 | NO | NO |
CVE-2002-2267HIGH bogopass in bogofilter 0.9.0.4 allows local users to overwrite arbitrary files via a symlink attack on the bogopass temporary file. | Dec 31, 2002 | 7.2 | 18 | NO | NO |
CVE-2004-1007MEDIUM The quoted-printable decoder in bogofilter 0.17.4 to 0.92.7 allows remote attackers to cause a denial of service (application crash) via mail headers that cause a line feed (LF) to | Mar 1, 2005 | 5.0 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bogofilter Project.
Media articles that mention a CVE ID that affects a product developed by Bogofilter Project — matched by CVE ID, not by vendor name.