Products: 2
    Vulnerabilities: 3
    Known Exploited: 0
    0
    Critical Level Threats
    3
    High Level Threats
    0
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2020-15397

    HylaFAX+ through 7.0.2 and HylaFAX Enterprise have scripts that execute binaries from directories writable by unprivileged users (e.g., locations under /var/spool/hylafax that are writable by the uucp account). This allows these users to execute code in the context of the user calling these binaries (often root).

    Last Modified: Nov 21, 2024
    Published: Jun 30, 2020

    CVE-2020-15396

    In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning a race, a local attacker could use this to escalate his privileges to root.

    Last Modified: Nov 21, 2024
    Published: Jun 30, 2020

    CVE-2020-11766

    sendfax.php in iFAX AvantFAX before 3.3.6 and HylaFAX Enterprise Web Interface before 0.2.5 allows authenticated Command Injection.

    Last Modified: Nov 21, 2024
    Published: May 19, 2020
    Items Per Page