Buffer overflow in the handling of command line arguments in Skype 1.0.x.94 through 1.0.x.98 allows remote attackers to execute arbitrary code via a callto:// URL with a long non-existent username, a different vulnerability than CVE-2004-1777.
2005-01-10T05:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 9.3 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | skype_technologies | skype | 1.0.0.9 | Yes |
Application | skype_technologies | skype | 1.0.0.10 | Yes |
Application | skype_technologies | skype | 1.0.0.18 | Yes |
Application | skype_technologies | skype | 1.0.0.29 | Yes |
Application | skype_technologies | skype | 1.0.0.94 | Yes |
Application | skype_technologies | skype | 1.0.0.97 | Yes |