Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xfmx-cx9c-559m

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Skype 3.6.0.248, and other versions before 3.8.0.139, uses a case-sensitive comparison when checking for dangerous extensions, which allows user-assisted remote attackers to bypass warning dialogs and possibly execute arbitrary code via a file: URI with a dangerous extension that uses a different case.

Skype 3.6.0.248, and other versions before 3.8.0.139, uses a case-sensitive comparison when checking for dangerous extensions, which allows user-assisted remote attackers to bypass warning dialogs and possibly execute arbitrary code via a file: URI with a dangerous extension that uses a different case.

EPSS

Процентиль: 82%
0.01687
Низкий

Дефекты

CWE-20

Связанные уязвимости

nvd
больше 17 лет назад

Skype 3.6.0.248, and other versions before 3.8.0.139, uses a case-sensitive comparison when checking for dangerous extensions, which allows user-assisted remote attackers to bypass warning dialogs and possibly execute arbitrary code via a file: URI with a dangerous extension that uses a different case.

EPSS

Процентиль: 82%
0.01687
Низкий

Дефекты

CWE-20