Page 2 of 10 results (0.002 seconds)

CVSS: 9.3EPSS: 43%CPEs: 5EXPL: 0

Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Title field of a (1) Dailymotion and possibly (2) Metacafe movie in the Skype video gallery, accessible through a search within the "Add video to chat" dialog, aka "videomood XSS." Vulnerabilidad de secuencias de comandos en zonas cruzadas en el control web Internet Explorer de Skype 3.6.0.244, y versiones anteriores 3.5.x y 3.6.x en Windows, permite a atacantes remotos con la complicidad del usuario inyectar secuencias de comandos web o HTML de su elección en la Zona de Máquina Local mediante el campo Title de un (1) Dailymotion y posiblemente (2) una película Metacafe en la galería de vídeos de Skype, accesible a través de una búsqueda dentro del diálogo "Add video to chat", también conocido como "videomood XSS". • http://archives.neohapsis.com/archives/fulldisclosure/2008-01/0337.html http://archives.neohapsis.com/archives/fulldisclosure/2008-01/0363.html http://aviv.raffon.net/2008/01/17/SkypeCrosszoneScriptingVulnerability.aspx http://share.skype.com/sites/security/2008/01/skype_cross_zone_scripting_vul.html http://skype.com/security/skype-sb-2008-001-update1.html http://skype.com/security/skype-sb-2008-001.html http://www.critical.lt/?opinions/show/1470 http://www.gnucitizen.org/blog/vulnerabilit • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.5EPSS: 23%CPEs: 1EXPL: 1

Format string vulnerability in the NSRunAlertPanel function in eBay Skype for Mac 1.5.*.79 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed Skype URL, as originally reported to involve a null dereference. Vulnerabilidad de formato de cadena en la función NSRunAlertPanel en eBay Skype para Mac 1.5.*.79 y versiones anteriores permite a atacantes remotos provocar una denegación de servicio (caída de aplicación) y posiblemente ejecutar código arbitrario a través de una URL de Skype mal formada, como se reportó originalmente para involucrar una referencia null. • https://www.exploit-db.com/exploits/28710 http://secunia.com/advisories/22185 http://security-protocols.com/vids/skype_osx_0day.htm http://securitytracker.com/id?1016966 http://www.kb.cert.org/vuls/id/202604 http://www.security-protocols.com/modules.php?name=News&file=article&sid=3259 http://www.securityfocus.com/bid/20218 http://www.skype.com/security/skype-sb-2006-002.html http://www.vupen.com/english/advisories/2006/3895 • CWE-20: Improper Input Validation •

CVSS: 2.6EPSS: 2%CPEs: 3EXPL: 0

Argument injection vulnerability in the URI handler in Skype 2.0.*.104 and 2.5.*.0 through 2.5.*.78 for Windows allows remote authorized attackers to download arbitrary files via a URL that contains certain command-line switches. • http://archives.neohapsis.com/archives/fulldisclosure/2006-05/0549.html http://secunia.com/advisories/20154 http://www.kb.cert.org/vuls/id/466428 http://www.osvdb.org/25658 http://www.securityfocus.com/archive/1/434707/30/4860/threaded http://www.securityfocus.com/bid/18038 http://www.skype.com/security/skype-sb-2006-001.html http://www.vupen.com/english/advisories/2006/1871 https://exchange.xforce.ibmcloud.com/vulnerabilities/26557 • CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') •

CVSS: 2.1EPSS: 0%CPEs: 1EXPL: 1

Skype 1.1.0.20 and earlier allows local users to overwrite arbitrary files via a symlink attack on the skype_profile.jpg temporary file. Skype 1.1.0.20 y anteriores permite que usuarios locales sobreescriban ficheros arbitrarios mediante un ataque de enlaces simbólicos en el fichero temporal "skype_profile.jpg". • http://marc.info/?l=bugtraq&m=112156036013818&w=2 http://secunia.com/advisories/16105 http://www.zone-h.org/advisories/read/id=7808 •

CVSS: 5.0EPSS: 1%CPEs: 2EXPL: 2

A "range check error" in Skype for Windows before 0.98.0.28 allows local and remote attackers to cause a denial of service (application crash) via long command line arguments or a long callto:// URL, a different vulnerability than CVE-2004-1114. • http://lists.virus.org/bugtraq-0406/msg00221.html http://securitytracker.com/id?1010490 http://www.osvdb.org/11860 http://www.skype.com/security/ssa-2004-01.html • CWE-20: Improper Input Validation •