VendorsSkype Technologiesskype3.6.0.244
Vulnerabilities

Skype Technologies Skype 3.6.0.244

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2008-2545
Skype 3.6.0.248, and other versions before 3.8.0.139, uses a case-sensitive comparison when checking for dangerous extensions, which allows user-assisted remote attackers to bypass warning dialogs and possibly execute arbitrary code via a file: URI with a dangerous extension that uses a different case.
Published 2008-06-06 · Modified
9.3EPSS 0.042
CVE-2008-1805
Incomplete blacklist vulnerability in Skype 3.6.0.248, and other versions before 3.8.0.139, allows user-assisted remote attackers to bypass warning dialogs and possibly execute arbitrary code via a file: URI that ends in an executable extension that is not covered by the blacklist.
Published 2008-06-06 · Modified
9.3EPSS 0.039
CVE-2008-0582
Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.1 through 3.6.0.244 on Windows allows remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Full Name field of a reviewer of a business item entry, accessible through (1) the SkypeFind dialog and (2) a skype:?skypefind URI for the skype: URI handler.
Published 2008-02-05 · Modified
4.3EPSS 0.012