2.1
CVE-2011-1717
- EPSS 0.29%
- Veröffentlicht 18.04.2011 18:55:02
- Zuletzt bearbeitet 16.06.2026 23:29:53
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Skype for Android stores sensitive user data without encryption in sqlite3 databases that have weak permissions, which allows local applications to read user IDs, contacts, phone numbers, date of birth, instant message logs, and other private information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.29% | 0.207 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:P/I:N/A:N
|
http://blogs.skype.com/security/2011/04/privacy_vulnerability_in_skype.html
http://www.androidpolice.com/2011/04/14/exclusive-vulnerability-in-skype-for-android-is-exposing-your-name-phone-number-chat-logs-and-a-lot-more/
http://www.securitytracker.com/id?1025387
http://www.theregister.co.uk/2011/04/15/skype_for_android_vulnerable/