An annoying user only knowing the username of another user can use the "Lost password" procedure to send him/her a lot of mails.
Besides being annoyed by those emails, there is not much risk with them: the content of the emails is not under the control of the annoying user and it is not a DoS risk (password procedure still works and the legitimate user can still login).
Credits
Issue has been reported by Ronit Bhatt via the security bug report procedure.