CVE-2008-1805

Incomplete blacklist vulnerability in Skype 3.6.0.248, and other versions before 3.8.0.139, allows user-assisted remote attackers to bypass warning dialogs and possibly execute arbitrary code via a file: URI that ends in an executable extension that is not covered by the blacklist.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 81%
VendorProductVersion
skype_technologiesskype
𝑥
≤ 3.8.0.115
skype_technologiesskype
3.0.0.106:beta
skype_technologiesskype
3.0.0.123:beta
skype_technologiesskype
3.0.0.137:beta
skype_technologiesskype
3.0.0.154:beta
skype_technologiesskype
3.0.0.190
skype_technologiesskype
3.0.0.198
skype_technologiesskype
3.0.0.205
skype_technologiesskype
3.0.0.209
skype_technologiesskype
3.0.0.214
skype_technologiesskype
3.0.0.216
skype_technologiesskype
3.0.0.217
skype_technologiesskype
3.0.0.218
skype_technologiesskype
3.1.0.112:beta
skype_technologiesskype
3.1.0.134:beta
skype_technologiesskype
3.1.0.144
skype_technologiesskype
3.1.0.147
skype_technologiesskype
3.1.0.150
skype_technologiesskype
3.1.0.152
skype_technologiesskype
3.2.0.53:beta
skype_technologiesskype
3.2.0.63:beta
skype_technologiesskype
3.2.0.82:beta
skype_technologiesskype
3.2.0.115:beta
skype_technologiesskype
3.2.0.145
skype_technologiesskype
3.2.0.148
skype_technologiesskype
3.2.0.152
skype_technologiesskype
3.2.0.158
skype_technologiesskype
3.2.0.163
skype_technologiesskype
3.2.0.175
skype_technologiesskype
3.5.0.107:beta
skype_technologiesskype
3.5.0.158:beta
skype_technologiesskype
3.5.0.178:beta
skype_technologiesskype
3.5.0.202
skype_technologiesskype
3.5.0.214
skype_technologiesskype
3.5.0.229
skype_technologiesskype
3.5.0.234
skype_technologiesskype
3.5.0.239
skype_technologiesskype
3.6.0.127:beta
skype_technologiesskype
3.6.0.159:beta
skype_technologiesskype
3.6.0.216
skype_technologiesskype
3.6.0.244
skype_technologiesskype
3.6.0.248
skype_technologiesskype
3.8.0.96:beta
𝑥
= Vulnerable software versions