Vulnerabilities > Hylafax > Hylafax > 4.1.2

DATE CVE VULNERABILITY TITLE RISK
2004-12-31 CVE-2004-1182 Unspecified vulnerability in Hylafax
hfaxd in HylaFAX before 4.2.1, when installed with a "weak" hosts.hfaxd file, allows remote attackers to authenticate and bypass intended access restrictions via a crafted (1) username or (2) hostname that satisfies a regular expression that is matched against a hosts.hfaxd entry without a password.
network
low complexity
hylafax
7.5
2003-12-01 CVE-2003-0886 Unspecified vulnerability in Hylafax
Format string vulnerability in hfaxd for Hylafax 4.1.7 and earlier allows remote attackers to execute arbitrary code.
network
low complexity
hylafax
critical
10.0
2002-10-04 CVE-2002-1050 Remote Buffer Overflow vulnerability in Hylafax Oversized Scan Line
Buffer overflow in HylaFAX faxgetty before 4.1.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long line of image data.
network
low complexity
hylafax
7.5
2002-10-04 CVE-2002-1049 Denial Of Service vulnerability in Hylafax Incoming TSI Format String
Format string vulnerability in HylaFAX faxgetty before 4.1.3 allows remote attackers to cause a denial of service (crash) via the TSI data element.
network
low complexity
hylafax
5.0