CVE-2007-0451

Advisory lineage Upstream: 0 Downstream: 4
Modified
Published: 16 Feb 2007, 19:00
Last modified:07 Aug 2024, 12:19

Vulnerability Summary

Overall Risk (default)
low
24/100
CVSS Score
4.3 MEDIUM
v2.0 (nvd)
EPSS Score
33.37% HIGH
33% probability +4.02%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

16 Feb 2007, 19:00
Published
Vulnerability first disclosed
07 Aug 2024, 12:19
Last Modified
Vulnerability information updated

Description

Apache SpamAssassin before 3.1.8 allows remote attackers to cause a denial of service via long URLs in malformed HTML, which triggers "massive memory usage."

CVSS Metrics

  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 33.37% Percentile: 97%

Techniques & Countermeasures

  • CWE-399Resource Management Errors

    Weaknesses in this category are related to improper management of system resources.

Affected Systems

  • apachespamassassin

    ≤ 3.1.7 | 3.0.1 | 3.0.2 | 3.0.3 | 3.0.4 | 3.1.0 | 3.1.1 | 3.1.2

References (23)