Vulnerability Details CVE-2008-2545
Skype 3.6.0.248, and other versions before 3.8.0.139, uses a case-sensitive comparison when checking for dangerous extensions, which allows user-assisted remote attackers to bypass warning dialogs and possibly execute arbitrary code via a file: URI with a dangerous extension that uses a different case.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.017
EPSS Ranking 81.4%
CVSS Severity
CVSS v2 Score 9.3
Products affected by CVE-2008-2545
-
cpe:2.3:a:skype_technologies:skype:*
-
cpe:2.3:a:skype_technologies:skype:3.0.0.106
-
cpe:2.3:a:skype_technologies:skype:3.0.0.123
-
cpe:2.3:a:skype_technologies:skype:3.0.0.137
-
cpe:2.3:a:skype_technologies:skype:3.0.0.154
-
cpe:2.3:a:skype_technologies:skype:3.0.0.190
-
cpe:2.3:a:skype_technologies:skype:3.0.0.198
-
cpe:2.3:a:skype_technologies:skype:3.0.0.205
-
cpe:2.3:a:skype_technologies:skype:3.0.0.209
-
cpe:2.3:a:skype_technologies:skype:3.0.0.214
-
cpe:2.3:a:skype_technologies:skype:3.0.0.216
-
cpe:2.3:a:skype_technologies:skype:3.0.0.217
-
cpe:2.3:a:skype_technologies:skype:3.0.0.218
-
cpe:2.3:a:skype_technologies:skype:3.1.0.112
-
cpe:2.3:a:skype_technologies:skype:3.1.0.134
-
cpe:2.3:a:skype_technologies:skype:3.1.0.144
-
cpe:2.3:a:skype_technologies:skype:3.1.0.147
-
cpe:2.3:a:skype_technologies:skype:3.1.0.150
-
cpe:2.3:a:skype_technologies:skype:3.1.0.152
-
cpe:2.3:a:skype_technologies:skype:3.2.0.115
-
cpe:2.3:a:skype_technologies:skype:3.2.0.145
-
cpe:2.3:a:skype_technologies:skype:3.2.0.148
-
cpe:2.3:a:skype_technologies:skype:3.2.0.152
-
cpe:2.3:a:skype_technologies:skype:3.2.0.158
-
cpe:2.3:a:skype_technologies:skype:3.2.0.163
-
cpe:2.3:a:skype_technologies:skype:3.2.0.175
-
cpe:2.3:a:skype_technologies:skype:3.2.0.53
-
cpe:2.3:a:skype_technologies:skype:3.2.0.63
-
cpe:2.3:a:skype_technologies:skype:3.2.0.82
-
cpe:2.3:a:skype_technologies:skype:3.5.0.107
-
cpe:2.3:a:skype_technologies:skype:3.5.0.158
-
cpe:2.3:a:skype_technologies:skype:3.5.0.178
-
cpe:2.3:a:skype_technologies:skype:3.5.0.202
-
cpe:2.3:a:skype_technologies:skype:3.5.0.214
-
cpe:2.3:a:skype_technologies:skype:3.5.0.229
-
cpe:2.3:a:skype_technologies:skype:3.5.0.234
-
cpe:2.3:a:skype_technologies:skype:3.5.0.239
-
cpe:2.3:a:skype_technologies:skype:3.6.0.127
-
cpe:2.3:a:skype_technologies:skype:3.6.0.159
-
cpe:2.3:a:skype_technologies:skype:3.6.0.216
-
cpe:2.3:a:skype_technologies:skype:3.6.0.244
-
cpe:2.3:a:skype_technologies:skype:3.6.0.248
-
cpe:2.3:a:skype_technologies:skype:3.8.0.96