Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown
CVE-2020-15397
Disclosure Date: June 30, 2020 (last updated February 21, 2025)
HylaFAX+ through 7.0.2 and HylaFAX Enterprise have scripts that execute binaries from directories writable by unprivileged users (e.g., locations under /var/spool/hylafax that are writable by the uucp account). This allows these users to execute code in the context of the user calling these binaries (often root).
0
Attacker Value
Unknown
CVE-2020-15396
Disclosure Date: June 30, 2020 (last updated February 21, 2025)
In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning a race, a local attacker could use this to escalate his privileges to root.
0
Attacker Value
Unknown
CVE-2020-11766
Disclosure Date: May 19, 2020 (last updated February 21, 2025)
sendfax.php in iFAX AvantFAX before 3.3.6 and HylaFAX Enterprise Web Interface before 0.2.5 allows authenticated Command Injection.
0
Attacker Value
Unknown
CVE-2014-6879
Disclosure Date: October 02, 2014 (last updated October 05, 2023)
The Equifax Mobile (aka com.equifax) application 1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2005-3538
Disclosure Date: December 31, 2005 (last updated October 04, 2023)
hfaxd in HylaFAX 4.2.3, when PAM support is disabled, accepts arbitrary passwords, which allows remote attackers to gain privileges.
0