Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Hylafax

First CVE: Nov 4, 1999Active for: 27 yearsTotal CVEs: 10
55.3
VTI Score
TOP TARGET

Hylafax is a narrowly scoped fax-transmission software suite that, despite limited product breadth, occupies a specialized niche in legacy communication infrastructure and remains embedded in certain enterprise and government deployments. Its vulnerability profile centers on a single product and recurs through memory-safety weakness classes including access of uninitialized pointers and out-of-bounds writes, characteristic of C-based daemon software with long operational lifespans, and its disclosures have frequently acquired public exploit code. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
1.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Hylafax over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 4, 1999
26 years ago
Most Recent CVE
Sep 21, 2018
2,866 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2003-0886HIGH
Format string vulnerability in hfaxd for Hylafax 4.1.7 and earlier allows remote attackers to execute arbitrary code.
Dec 1, 200310.042NOYES
CVE-2005-3539HIGH
Multiple eval injection vulnerabilities in HylaFAX 4.2.3 and earlier allow remote attackers to execute arbitrary commands via (1) the notify script in HylaFAX 4.2.0 to 4.2.3 and (2
Dec 31, 20057.534NOYES
CVE-2018-17141CRITICAL
HylaFAX 6.0.6 and HylaFAX+ 5.6.0 allow remote attackers to execute arbitrary code via a dial-in session that provides a FAX page with the JPEG bit enabled, which is mishandled in F
Sep 21, 20189.833NONO
CVE-1999-1340HIGH
Buffer overflow in faxalter in hylafax 4.0.2 allows local users to gain privileges via a long -m command line argument.
Nov 4, 19997.227NOYES
CVE-2004-1182HIGH
hfaxd in HylaFAX before 4.2.1, when installed with a "weak" hosts.hfaxd file, allows remote attackers to authenticate and bypass intended access restrictions via a crafted (1) user
Dec 31, 20047.524NONO
CVE-2001-0387HIGH
Format string vulnerability in hfaxd in HylaFAX before 4.1.b2_2 allows local users to gain privileges via the -q command line argument.
Jul 2, 20017.223NONO
CVE-2002-1050HIGH
Buffer overflow in HylaFAX faxgetty before 4.1.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long line of image data.
Oct 4, 20027.521NONO
CVE-2002-1049MEDIUM
Format string vulnerability in HylaFAX faxgetty before 4.1.3 allows remote attackers to cause a denial of service (crash) via the TSI data element.
Oct 4, 20025.015NONO
CVE-2005-3070LOW
HylaFax 4.2.1 and earlier does not create or verify ownership of the UNIX domain socket, which might allow local users to read faxes and cause a denial of service by creating the s
Sep 27, 20053.613NONO
CVE-2005-3069LOW
xferfaxstats in HylaFax 4.2.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on the xferfax$$ temporary file.
Sep 27, 20052.111NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
20%
10%
60%
10%
Severity distribution among all CVEs352,727 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network1 (10.0%)
Unknown9 (90.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (10.0%)
High0 (0.0%)
Unknown9 (90.0%)
User Interaction
None1 (10.0%)
Unknown9 (90.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (10.0%)
Unknown9 (90.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
30.0% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Hylafax.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Hylafax — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Hylafax's Products

View all 2 CNAs →

Top CWEs