Show filters
85 Total Results
Displaying 71-80 of 85
Sort by:
Attacker Value
Unknown
CVE-2008-0582
Disclosure Date: February 05, 2008 (last updated October 04, 2023)
Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.1 through 3.6.0.244 on Windows allows remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Full Name field of a reviewer of a business item entry, accessible through (1) the SkypeFind dialog and (2) a skype:?skypefind URI for the skype: URI handler.
0
Attacker Value
Unknown
CVE-2008-0583
Disclosure Date: February 05, 2008 (last updated October 04, 2023)
Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Description and unspecified other metadata fields of a Metacafe movie submitted by Metacafe Pro to the Skype video gallery, accessible through a search within the (1) "Add video to chat" or (2) "Add video to mood" dialog, a different vector than CVE-2008-0454.
0
Attacker Value
Unknown
CVE-2008-0454
Disclosure Date: January 25, 2008 (last updated October 04, 2023)
Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Title field of a (1) Dailymotion and possibly (2) Metacafe movie in the Skype video gallery, accessible through a search within the "Add video to chat" dialog, aka "videomood XSS."
0
Attacker Value
Unknown
CVE-2007-5989
Disclosure Date: December 13, 2007 (last updated October 04, 2023)
Unspecified vulnerability in the skype4com URI handler in Skype before 3.6 GOLD allows remote attackers to execute arbitrary code via "short string values" that result in heap corruption.
0
Attacker Value
Unknown
CVE-2007-4429
Disclosure Date: August 20, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Skype allows remote attackers to cause a denial of service (server hang) via unknown vectors related to sending long URIs, as claimed to be actively exploited on 20070817 using a "call to a specific number." NOTE: this identifier is for the en.securitylab.ru disclosure. According to the vendor, this issue is separate from the "sign-on issues" that reduced Skype service on 20070817, which appears to be a site-specific problem. As of 20070821, it is not clear whether this issue is simply a symptom of the larger sign-on problem.
0
Attacker Value
Unknown
CVE-2006-5084
Disclosure Date: September 29, 2006 (last updated October 04, 2023)
Format string vulnerability in the NSRunAlertPanel function in eBay Skype for Mac 1.5.*.79 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed Skype URL, as originally reported to involve a null dereference.
0
Attacker Value
Unknown
CVE-2006-5038
Disclosure Date: September 27, 2006 (last updated October 04, 2023)
The FiWin SS28S WiFi VoIP SIP/Skype Phone, firmware version 01_02_07, has a hard-coded username and password, which allows remote attackers to gain administrative access via telnet.
0
Attacker Value
Unknown
CVE-2006-2312
Disclosure Date: May 19, 2006 (last updated February 14, 2024)
Argument injection vulnerability in the URI handler in Skype 2.0.*.104 and 2.5.*.0 through 2.5.*.78 for Windows allows remote authorized attackers to download arbitrary files via a URL that contains certain command-line switches.
0
Attacker Value
Unknown
CVE-2005-3265
Disclosure Date: October 27, 2005 (last updated February 22, 2025)
Buffer overflow in Skype for Windows 1.1.x.0 through 1.4.x.83 allows remote attackers to execute arbitrary code via (1) callto:// and (2) skype:// links, or (3) a non-standard VCARD, possibly due to an underlying error in the SysUtils.WideFmtStr Delphi routine.
0
Attacker Value
Unknown
CVE-2005-3267
Disclosure Date: October 27, 2005 (last updated February 22, 2025)
Integer overflow in Skype client before 1.4.x.84 on Windows, before 1.3.x.17 on Mac OS, before 1.2.x.18 on Linux, and 1.1.x.6 and earlier allows remote attackers to cause a denial of service (crash) via crafted network data with a large Object Counter value, which leads to a resultant heap-based buffer overflow.
0