9.3

CVE-2008-1805

Incomplete blacklist vulnerability in Skype 3.6.0.248, and other versions before 3.8.0.139, allows user-assisted remote attackers to bypass warning dialogs and possibly execute arbitrary code via a file: URI that ends in an executable extension that is not covered by the blacklist.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Skype TechnologiesSkype Version <= 3.8.0.115
Skype TechnologiesSkype Version3.0.0.106 Updatebeta
Skype TechnologiesSkype Version3.0.0.123 Updatebeta
Skype TechnologiesSkype Version3.0.0.137 Updatebeta
Skype TechnologiesSkype Version3.0.0.154 Updatebeta
Skype TechnologiesSkype Version3.0.0.190
Skype TechnologiesSkype Version3.0.0.198
Skype TechnologiesSkype Version3.0.0.205
Skype TechnologiesSkype Version3.0.0.209
Skype TechnologiesSkype Version3.0.0.214
Skype TechnologiesSkype Version3.0.0.216
Skype TechnologiesSkype Version3.0.0.217
Skype TechnologiesSkype Version3.0.0.218
Skype TechnologiesSkype Version3.1.0.112 Updatebeta
Skype TechnologiesSkype Version3.1.0.134 Updatebeta
Skype TechnologiesSkype Version3.1.0.144
Skype TechnologiesSkype Version3.1.0.147
Skype TechnologiesSkype Version3.1.0.150
Skype TechnologiesSkype Version3.1.0.152
Skype TechnologiesSkype Version3.2.0.53 Updatebeta
Skype TechnologiesSkype Version3.2.0.63 Updatebeta
Skype TechnologiesSkype Version3.2.0.82 Updatebeta
Skype TechnologiesSkype Version3.2.0.115 Updatebeta
Skype TechnologiesSkype Version3.2.0.145
Skype TechnologiesSkype Version3.2.0.148
Skype TechnologiesSkype Version3.2.0.152
Skype TechnologiesSkype Version3.2.0.158
Skype TechnologiesSkype Version3.2.0.163
Skype TechnologiesSkype Version3.2.0.175
Skype TechnologiesSkype Version3.5.0.107 Updatebeta
Skype TechnologiesSkype Version3.5.0.158 Updatebeta
Skype TechnologiesSkype Version3.5.0.178 Updatebeta
Skype TechnologiesSkype Version3.5.0.202
Skype TechnologiesSkype Version3.5.0.214
Skype TechnologiesSkype Version3.5.0.229
Skype TechnologiesSkype Version3.5.0.234
Skype TechnologiesSkype Version3.5.0.239
Skype TechnologiesSkype Version3.6.0.127 Updatebeta
Skype TechnologiesSkype Version3.6.0.159 Updatebeta
Skype TechnologiesSkype Version3.6.0.216
Skype TechnologiesSkype Version3.6.0.244
Skype TechnologiesSkype Version3.6.0.248
Skype TechnologiesSkype Version3.8.0.96 Updatebeta
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.69% 0.805
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.