← Vulnerability feed

Vulnerability record · CVE-2007-0451 · published 16 February 2007

CVE-2007-0451: Apache spamassassin vulnerability

Apache · Spamassassin

Apache SpamAssassin before 3.1.8 allows remote attackers to cause a denial of service via long URLs in malformed HTML, which triggers "massive memory usage."

4.3 CVSS 2.0 Medium EPSS 6.9% · top 6.2% CWE-399 · CWE-399
4.3CVSS 2.0 base score
6.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
46References
16 Jun 2026Last modified by NVD

Description

Apache SpamAssassin before 3.1.8 allows remote attackers to cause a denial of service via long URLs in malformed HTML, which triggers "massive memory usage."

AV:N/AC:M/Au:N/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://fedoranews.org/cms/node/2657 Patch
http://fedoranews.org/cms/node/2659 Patch
http://osvdb.org/33207
http://rhn.redhat.com/errata/RHSA-2007-0074.html
http://secunia.com/advisories/24197 Vendor Advisory
http://secunia.com/advisories/24200 Vendor Advisory
http://secunia.com/advisories/24250 Vendor Advisory
http://secunia.com/advisories/24256 Vendor Advisory
http://secunia.com/advisories/24265 Vendor Advisory
http://secunia.com/advisories/24307 Vendor Advisory
http://secunia.com/advisories/24889 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200703-02.xml
http://spamassassin.apache.org/advisories/cve-2007-0451.txt
http://svn.apache.org/repos/asf/spamassassin/branches/3.1/build/announcements/3.1.8.txt
http://www.mandriva.com/security/advisories?name=MDKSA-2007:049
http://www.novell.com/linux/security/advisories/2007_6_sr.html
http://www.redhat.com/support/errata/RHSA-2007-0075.html
http://www.securityfocus.com/bid/22584 Patch
http://www.securitytracker.com/id?1017666
http://www.vupen.com/english/advisories/2007/0628 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/32536
https://issues.rpath.com/browse/RPL-1073
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10018
http://fedoranews.org/cms/node/2657 Patch
http://fedoranews.org/cms/node/2659 Patch
http://osvdb.org/33207
http://rhn.redhat.com/errata/RHSA-2007-0074.html
http://secunia.com/advisories/24197 Vendor Advisory
http://secunia.com/advisories/24200 Vendor Advisory
http://secunia.com/advisories/24250 Vendor Advisory
http://secunia.com/advisories/24256 Vendor Advisory
http://secunia.com/advisories/24265 Vendor Advisory
http://secunia.com/advisories/24307 Vendor Advisory
http://secunia.com/advisories/24889 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200703-02.xml
http://spamassassin.apache.org/advisories/cve-2007-0451.txt
http://svn.apache.org/repos/asf/spamassassin/branches/3.1/build/announcements/3.1.8.txt
http://www.mandriva.com/security/advisories?name=MDKSA-2007:049
http://www.novell.com/linux/security/advisories/2007_6_sr.html
http://www.redhat.com/support/errata/RHSA-2007-0075.html

Track CVE-2007-0451 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-1946Apache spamassassin os command injection vulnerabilityIn Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. …EPSS 6.1%9.8CVE-2018-11780Apache spamassassin code injection vulnerabilityA potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2.EPSS 11%8.1CVE-2020-1930Apache spamassassin os command injection vulnerabilityA command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious rule configuration (.cf) files can be configur…EPSS 7.1%8.1CVE-2020-1931Apache spamassassin os command injection vulnerabilityA command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious Configuration (.cf) files can be configured to…EPSS 6.5%7.8CVE-2018-11781Apache spamassassin code injection vulnerabilityApache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax.EPSS 0.98%7.8CVE-2016-1238Debian linux permissions and access controls vulnerability(1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (4) cpan/CPAN/scripts/cpan, (5) cpan/Digest-SHA/…EPSS 0.78%7.5CVE-2019-12420Apache spamassassin uncontrolled resource consumption vulnerabilityIn Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the r…EPSS 7.2%6.7CVE-2018-11805Apache spamassassin os command injection vulnerabilityIn Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits ca…EPSS 0.87%

Source: NIST National Vulnerability Database (record CVE-2007-0451), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.