Show filters
85 Total Results
Displaying 61-70 of 85
Sort by:
Attacker Value
Unknown

CVE-2015-2536

Disclosure Date: September 09, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Microsoft Lync Server 2013 and Skype for Business Server 2015 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Skype for Business Server and Lync Server XSS Elevation of Privilege Vulnerability."
0
Attacker Value
Unknown

CVE-2015-2531

Disclosure Date: September 09, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the jQuery engine in Microsoft Lync Server 2013 and Skype for Business Server 2015 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Skype for Business Server and Lync Server XSS Information Disclosure Vulnerability."
0
Attacker Value
Unknown

CVE-2014-6886

Disclosure Date: October 02, 2014 (last updated October 05, 2023)
The WePhone - phone calls vs skype (aka com.wephoneapp) application 1.03.00 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2011-2074

Disclosure Date: May 10, 2011 (last updated October 04, 2023)
Unspecified vulnerability in the client in Skype 5.x before 5.1.0.922 on Mac OS X allows remote authenticated users to execute arbitrary code or cause a denial of service (application crash) via a crafted message.
0
Attacker Value
Unknown

CVE-2011-1717

Disclosure Date: April 18, 2011 (last updated October 04, 2023)
Skype for Android stores sensitive user data without encryption in sqlite3 databases that have weak permissions, which allows local applications to read user IDs, contacts, phone numbers, date of birth, instant message logs, and other private information.
0
Attacker Value
Unknown

CVE-2010-3136

Disclosure Date: August 26, 2010 (last updated October 04, 2023)
Untrusted search path vulnerability in Skype 4.2.0.169 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse wab32.dll that is located in the same folder as a .skype file.
0
Attacker Value
Unknown

CVE-2009-4741

Disclosure Date: March 26, 2010 (last updated October 04, 2023)
Unspecified vulnerability in the Extras Manager before 2.0.0.67 in Skype before 4.1.0.179 on Windows has unknown impact and attack vectors.
0
Attacker Value
Unknown

CVE-2008-5697

Disclosure Date: December 22, 2008 (last updated October 04, 2023)
The skype_tool.copy_num method in the Skype extension BETA 2.2.0.95 for Firefox allows remote attackers to write arbitrary data to the clipboard via a string argument.
0
Attacker Value
Unknown

CVE-2008-2545

Disclosure Date: June 06, 2008 (last updated October 04, 2023)
Skype 3.6.0.248, and other versions before 3.8.0.139, uses a case-sensitive comparison when checking for dangerous extensions, which allows user-assisted remote attackers to bypass warning dialogs and possibly execute arbitrary code via a file: URI with a dangerous extension that uses a different case.
0
Attacker Value
Unknown

CVE-2008-1805

Disclosure Date: June 06, 2008 (last updated October 04, 2023)
Incomplete blacklist vulnerability in Skype 3.6.0.248, and other versions before 3.8.0.139, allows user-assisted remote attackers to bypass warning dialogs and possibly execute arbitrary code via a file: URI that ends in an executable extension that is not covered by the blacklist.
0