CVE-2006-5084
Skype Technologies Skype 1.5 - NSRunAlertPanel Remote Format String
Severity Score
7.5
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Format string vulnerability in the NSRunAlertPanel function in eBay Skype for Mac 1.5.*.79 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed Skype URL, as originally reported to involve a null dereference.
Vulnerabilidad de formato de cadena en la función NSRunAlertPanel en eBay Skype para Mac 1.5.*.79 y versiones anteriores permite a atacantes remotos provocar una denegación de servicio (caída de aplicación) y posiblemente ejecutar código arbitrario a través de una URL de Skype mal formada, como se reportó originalmente para involucrar una referencia null.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2006-09-26 First Exploit
- 2006-09-28 CVE Reserved
- 2006-09-29 CVE Published
- 2023-06-25 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/22185 | Third Party Advisory | |
http://security-protocols.com/vids/skype_osx_0day.htm | X_refsource_misc | |
http://securitytracker.com/id?1016966 | Vdb Entry | |
http://www.kb.cert.org/vuls/id/202604 | Third Party Advisory | |
http://www.security-protocols.com/modules.php?name=News&file=article&sid=3259 | X_refsource_misc | |
http://www.securityfocus.com/bid/20218 | Vdb Entry | |
http://www.skype.com/security/skype-sb-2006-002.html | X_refsource_confirm |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/28710 | 2006-09-26 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.vupen.com/english/advisories/2006/3895 | 2016-12-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Skype Technologies Search vendor "Skype Technologies" | Skype Search vendor "Skype Technologies" for product "Skype" | <= 1.5.0.79 Search vendor "Skype Technologies" for product "Skype" and version " <= 1.5.0.79" | - |
Affected
|