Known Vulnerabilities for products from Hylafax

Listed below are 10 of the newest known vulnerabilities associated with the vendor "Hylafax".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2025-1782 json Not Provided 2025-04-14 2026-05-26
CVE-2018-17141 json HylaFAX 6.0.6 and HylaFAX+ 5.6.0 allow remote attackers to execute arbitrary code via a dial-in session that provides a FAX p... 9.8 - CRITICAL 2018-09-21 2023-11-07
CVE-2005-3539 json Multiple eval injection vulnerabilities in HylaFAX 4.2.3 and earlier allow remote attackers to execute arbitrary commands via... Not Provided 2005-12-31 2025-04-03
CVE-2005-3070 json HylaFax 4.2.1 and earlier does not create or verify ownership of the UNIX domain socket, which might allow local users to rea... Not Provided 2005-09-27 2025-04-03
CVE-2005-3069 json xferfaxstats in HylaFax 4.2.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on the xferfax... Not Provided 2005-09-27 2025-04-03
CVE-2004-1182 json hfaxd in HylaFAX before 4.2.1, when installed with a "weak" hosts.hfaxd file, allows remote attackers to authenticate and byp... Not Provided 2004-12-31 2025-04-03
CVE-2003-0886 json Format string vulnerability in hfaxd for Hylafax 4.1.7 and earlier allows remote attackers to execute arbitrary code. Not Provided 2003-12-01 2025-04-03
CVE-2002-1050 json Buffer overflow in HylaFAX faxgetty before 4.1.3 allows remote attackers to cause a denial of service, and possibly execute a... Not Provided 2002-10-04 2025-04-03
CVE-2002-1049 json Format string vulnerability in HylaFAX faxgetty before 4.1.3 allows remote attackers to cause a denial of service (crash) via... Not Provided 2002-10-04 2025-04-03
CVE-2001-0387 json Format string vulnerability in hfaxd in HylaFAX before 4.1.b2_2 allows local users to gain privileges via the -q command line... Not Provided 2001-07-02 2025-04-03
CVE-1999-1340 json Buffer overflow in faxalter in hylafax 4.0.2 allows local users to gain privileges via a long -m command line argument. Not Provided 1999-11-04 2025-04-03

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report