Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3v37-99mq-jmgr

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Incomplete blacklist vulnerability in Skype 3.6.0.248, and other versions before 3.8.0.139, allows user-assisted remote attackers to bypass warning dialogs and possibly execute arbitrary code via a file: URI that ends in an executable extension that is not covered by the blacklist.

Incomplete blacklist vulnerability in Skype 3.6.0.248, and other versions before 3.8.0.139, allows user-assisted remote attackers to bypass warning dialogs and possibly execute arbitrary code via a file: URI that ends in an executable extension that is not covered by the blacklist.

EPSS

Процентиль: 83%
0.02025
Низкий

Дефекты

CWE-20

Связанные уязвимости

nvd
больше 17 лет назад

Incomplete blacklist vulnerability in Skype 3.6.0.248, and other versions before 3.8.0.139, allows user-assisted remote attackers to bypass warning dialogs and possibly execute arbitrary code via a file: URI that ends in an executable extension that is not covered by the blacklist.

EPSS

Процентиль: 83%
0.02025
Низкий

Дефекты

CWE-20