CVE-2008-0582
Estado: ModificadaMedia (4.3)—
Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.1 through 3.6.0.244 on Windows allows remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Full Name field of a reviewer of a business item entry, accessible through (1) the SkypeFind dialog and (2) a skype:?skypefind URI for the skype: URI handler.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.21%
- Percentil entre todas las CVEs puntuadas: 67
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-94
Referencias
- http://aviv.raffon.net/2008/01/31/AttackersCanSkypeFindYou.aspx
- http://www.kb.cert.org/vuls/id/794236
- http://www.securityfocus.com/archive/1/487370/100/0/threaded
- http://www.securityfocus.com/bid/27338
- http://aviv.raffon.net/2008/01/31/AttackersCanSkypeFindYou.aspx
- http://www.kb.cert.org/vuls/id/794236
- http://www.securityfocus.com/archive/1/487370/100/0/threaded
- http://www.securityfocus.com/bid/27338
JSON original (NVD)
Mostrar
{
"id": "CVE-2008-0582",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-02-05T03:00:00.000",
"references": [
{
"url": "http://aviv.raffon.net/2008/01/31/AttackersCanSkypeFindYou.aspx",
"source": "cve@mitre.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/794236",
"tags": [
"US Government Resource"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/487370/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/27338",
"source": "cve@mitre.org"
},
{
"url": "http://aviv.raffon.net/2008/01/31/AttackersCanSkypeFindYou.aspx",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/794236",
"tags": [
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/487370/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/27338",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-94"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.1 through 3.6.0.244 on Windows allows remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Full Name field of a reviewer of a business item entry, accessible through (1) the SkypeFind dialog and (2) a skype:?skypefind URI for the skype: URI handler."
},
{
"lang": "es",
"value": "Vulnerabilidad de secuencias de comandos en zonas cruzadas en el control web Internet Explorer en Skype 3.1 hasta 3.6.0.244 en Windows permite a atacantes remotos inyectar web script o HTML de su elección en Local Machine Zone mediante el campo Full Name de un revisor de una entrada de negocios, accesible a través de (1) el diálogo SkypeFind y (2) un skype:?URI de skypefind para el skype: URI handler.\r\n"
}
],
"lastModified": "2026-06-16T22:49:55.177",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:skype_technologies:skype:3.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DE256FC0-DDAD-48E3-A5EF-C1DC7C65825C"
},
{
"criteria": "cpe:2.3:a:skype_technologies:skype:3.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DC3B8FD1-C61B-45E5-B8E0-3CEFA92A6489"
},
{
"criteria": "cpe:2.3:a:skype_technologies:skype:3.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D09CC031-8F8F-4BC4-AEFF-4FD98411B272"
},
{
"criteria": "cpe:2.3:a:skype_technologies:skype:3.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AD01462B-281F-4299-8D85-3FC6E6D392A8"
},
{
"criteria": "cpe:2.3:a:skype_technologies:skype:3.6.0.244:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "95648140-386E-4D8B-BE7E-9542333F0A8C"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}