Show filters
18 Total Results
Displaying 1-10 of 18
Sort by:
Attacker Value
Unknown
CVE-2020-15397
Disclosure Date: June 30, 2020 (last updated February 21, 2025)
HylaFAX+ through 7.0.2 and HylaFAX Enterprise have scripts that execute binaries from directories writable by unprivileged users (e.g., locations under /var/spool/hylafax that are writable by the uucp account). This allows these users to execute code in the context of the user calling these binaries (often root).
0
Attacker Value
Unknown
CVE-2020-15396
Disclosure Date: June 30, 2020 (last updated February 21, 2025)
In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning a race, a local attacker could use this to escalate his privileges to root.
0
Attacker Value
Unknown
CVE-2020-8024
Disclosure Date: June 15, 2020 (last updated February 21, 2025)
A Incorrect Default Permissions vulnerability in the packaging of hylafax+ of openSUSE Leap 15.2, openSUSE Leap 15.1, openSUSE Factory allows local attackers to escalate from user uucp to users calling hylafax binaries. This issue affects: openSUSE Leap 15.2 hylafax+ versions prior to 7.0.2-lp152.2.1. openSUSE Leap 15.1 hylafax+ version 5.6.1-lp151.3.7 and prior versions. openSUSE Factory hylafax+ versions prior to 7.0.2-2.1.
0
Attacker Value
Unknown
CVE-2020-11766
Disclosure Date: May 19, 2020 (last updated February 21, 2025)
sendfax.php in iFAX AvantFAX before 3.3.6 and HylaFAX Enterprise Web Interface before 0.2.5 allows authenticated Command Injection.
0
Attacker Value
Unknown
CVE-2018-17141
Disclosure Date: September 21, 2018 (last updated November 08, 2023)
HylaFAX 6.0.6 and HylaFAX+ 5.6.0 allow remote attackers to execute arbitrary code via a dial-in session that provides a FAX page with the JPEG bit enabled, which is mishandled in FaxModem::writeECMData() in the faxd/CopyQuality.c++ file.
0
Attacker Value
Unknown
CVE-2013-5680
Disclosure Date: April 06, 2014 (last updated October 05, 2023)
Heap-based buffer overflow in hfaxd in HylaFAX+ 5.2.4 through 5.5.3, when using LDAP authentication, might allow remote attackers to cause a denial of service (child hang) or execute arbitrary code via a long USER command.
0
Attacker Value
Unknown
CVE-2006-3126
Disclosure Date: September 06, 2006 (last updated October 04, 2023)
c2faxrecv in capi4hylafax 01.02.03 allows remote attackers to execute arbitrary commands via null (\0) and shell metacharacters in the TSI string, as demonstrated by a fax from an anonymous number.
0
Attacker Value
Unknown
CVE-2006-1231
Disclosure Date: March 14, 2006 (last updated October 04, 2023)
CAPI4HylaFAX 1.3, when compiled with GENERATE_DEBUGSFFDATAFILE set, allows local users to modify arbitrary files via a symlink attack on the c2faxrecv_dbgdatafile.sff temporary file.
0
Attacker Value
Unknown
CVE-2005-3538
Disclosure Date: December 31, 2005 (last updated October 04, 2023)
hfaxd in HylaFAX 4.2.3, when PAM support is disabled, accepts arbitrary passwords, which allows remote attackers to gain privileges.
0
Attacker Value
Unknown
CVE-2005-3539
Disclosure Date: December 31, 2005 (last updated October 04, 2023)
Multiple eval injection vulnerabilities in HylaFAX 4.2.3 and earlier allow remote attackers to execute arbitrary commands via (1) the notify script in HylaFAX 4.2.0 to 4.2.3 and (2) crafted CallID parameters to the faxrcvd script in HylaFAX 4.2.2 and 4.2.3.
0