See how qmail project compares to other vendors in security performance
Integer overflow in the strallocreadyplus function in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large SMTP request.
Denial of service in Qmail by specifying a large number of recipients with the RCPT command.