SpamAssassin is a widely embedded email filtering and anti-spam utility deployed across mail servers and messaging gateways to classify and block unwanted messages. Its vulnerability exposure centers on the core filtering product and reflects memory-safety and operational-bounds issues characteristic of mail-processing software that handles untrusted input at scale. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Spamassassin over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-1557HIGH Off-by-one buffer overflow in spamc of SpamAssassin 2.40 through 2.43, when using BSMTP mode ("-B"), allows remote attackers to execute arbitrary code via email containing headers | Dec 31, 2003 | 7.6 | 21 | NO | NO |
CVE-2004-0796MEDIUM SpamAssassin 2.5x, and 2.6x before 2.64, allows remote attackers to cause a denial of service via certain malformed messages. | Oct 20, 2004 | 5.0 | 15 | NO | NO |
SpamAssassin 3.1.x, 3.2.0, and 3.2.1 before 20070611, when running as root in unusual configurations using vpopmail or virtual users, allows local users to cause a denial of servic | Jun 11, 2007 | 1.9 | 11 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Spamassassin.
Media articles that mention a CVE ID that affects a product developed by Spamassassin — matched by CVE ID, not by vendor name.