VulnerabilityModified
CVE-2007-5989
Unspecified vulnerability in the skype4com URI handler in Skype before 3.6 GOLD allows remote attackers to execute arbitrary code via "short string values" that result in heap corruption.
MEDIUM 6.8EPSS 4.42%
Does this matter?
Lower severity and a low EPSS score (4.42%). Track it; it rarely justifies an emergency change on its own.
Description
Unspecified vulnerability in the skype4com URI handler in Skype before 3.6 GOLD allows remote attackers to execute arbitrary code via "short string values" that result in heap corruption.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 4.42% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- skype technologies/skype
- Source
- cve@mitre.org
References
- http://osvdb.org/39170
- http://secunia.com/advisories/27934Vendor Advisory
- http://securityreason.com/securityalert/3440
- http://securitytracker.com/id?1019056
- http://www.securityfocus.com/archive/1/484703/100/0/threaded
- http://www.securityfocus.com/bid/26748
- http://www.vupen.com/english/advisories/2007/4110
- http://www.zerodayinitiative.com/advisories/ZDI-07-070.html
- http://osvdb.org/39170
- http://secunia.com/advisories/27934Vendor Advisory
- http://securityreason.com/securityalert/3440
- http://securitytracker.com/id?1019056
- http://www.securityfocus.com/archive/1/484703/100/0/threaded
- http://www.securityfocus.com/bid/26748
- http://www.vupen.com/english/advisories/2007/4110
- http://www.zerodayinitiative.com/advisories/ZDI-07-070.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.