
CVE-2005-3070
https://notcve.org/view.php?id=CVE-2005-3070
27 Sep 2005 — HylaFax 4.2.1 and earlier does not create or verify ownership of the UNIX domain socket, which might allow local users to read faxes and cause a denial of service by creating the socket using the hyla.unix temporary file. • http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=329384 •

CVE-2002-1049
https://notcve.org/view.php?id=CVE-2002-1049
04 Oct 2002 — Format string vulnerability in HylaFAX faxgetty before 4.1.3 allows remote attackers to cause a denial of service (crash) via the TSI data element. • http://archives.neohapsis.com/archives/bugtraq/2002-07/0358.html •

CVE-2002-1050
https://notcve.org/view.php?id=CVE-2002-1050
04 Oct 2002 — Buffer overflow in HylaFAX faxgetty before 4.1.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long line of image data. • http://archives.neohapsis.com/archives/bugtraq/2002-07/0358.html •

CVE-1999-1340 – Hylafax Hylafax 4.0.2 - Local Buffer Overflow
https://notcve.org/view.php?id=CVE-1999-1340
04 Nov 1999 — Buffer overflow in faxalter in hylafax 4.0.2 allows local users to gain privileges via a long -m command line argument. • https://www.exploit-db.com/exploits/19590 •