CVE-2008-1805
- EPSS 1.69%
- Published 06.06.2008 22:32:00
- Last modified 09.04.2025 00:30:58
Incomplete blacklist vulnerability in Skype 3.6.0.248, and other versions before 3.8.0.139, allows user-assisted remote attackers to bypass warning dialogs and possibly execute arbitrary code via a file: URI that ends in an executable extension that ...
CVE-2008-2545
- EPSS 1.69%
- Published 06.06.2008 22:32:00
- Last modified 09.04.2025 00:30:58
Skype 3.6.0.248, and other versions before 3.8.0.139, uses a case-sensitive comparison when checking for dangerous extensions, which allows user-assisted remote attackers to bypass warning dialogs and possibly execute arbitrary code via a file: URI w...
CVE-2008-0582
- EPSS 0.68%
- Published 05.02.2008 03:00:00
- Last modified 09.04.2025 00:30:58
Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.1 through 3.6.0.244 on Windows allows remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Full Name field of a reviewer of a busi...
CVE-2008-0583
- EPSS 0.67%
- Published 05.02.2008 03:00:00
- Last modified 09.04.2025 00:30:58
Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via th...
CVE-2008-0454
- EPSS 41.32%
- Published 25.01.2008 01:00:00
- Last modified 09.04.2025 00:30:58
Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via th...
CVE-2007-5989
- EPSS 6.06%
- Published 13.12.2007 21:46:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in the skype4com URI handler in Skype before 3.6 GOLD allows remote attackers to execute arbitrary code via "short string values" that result in heap corruption.
- EPSS 2.3%
- Published 20.08.2007 19:17:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in Skype allows remote attackers to cause a denial of service (server hang) via unknown vectors related to sending long URIs, as claimed to be actively exploited on 20070817 using a "call to a specific number." NOTE: this i...
CVE-2006-5084
- EPSS 27.94%
- Published 29.09.2006 00:07:00
- Last modified 09.04.2025 00:30:58
Format string vulnerability in the NSRunAlertPanel function in eBay Skype for Mac 1.5.*.79 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed Skype URL, as original...
CVE-2005-3265
- EPSS 35.55%
- Published 27.10.2005 10:02:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in Skype for Windows 1.1.x.0 through 1.4.x.83 allows remote attackers to execute arbitrary code via (1) callto:// and (2) skype:// links, or (3) a non-standard VCARD, possibly due to an underlying error in the SysUtils.WideFmtStr Delp...
- EPSS 18.24%
- Published 27.10.2005 10:02:00
- Last modified 03.04.2025 01:03:51
Integer overflow in Skype client before 1.4.x.84 on Windows, before 1.3.x.17 on Mac OS, before 1.2.x.18 on Linux, and 1.1.x.6 and earlier allows remote attackers to cause a denial of service (crash) via crafted network data with a large Object Counte...