Search Results (59 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-26911 1 Microsoft 2 Lync Server, Skype For Business Server 2025-01-02 6.5 Medium
Skype for Business Information Disclosure Vulnerability
CVE-2022-26910 1 Microsoft 1 Skype For Business Server 2025-01-02 5.3 Medium
Skype for Business and Lync Spoofing Vulnerability
CVE-2021-26422 1 Microsoft 2 Lync Server, Skype For Business Server 2024-11-21 7.2 High
Skype for Business and Lync Remote Code Execution Vulnerability
CVE-2021-26421 1 Microsoft 2 Lync Server, Skype For Business Server 2024-11-21 6.5 Medium
Skype for Business and Lync Spoofing Vulnerability
CVE-2021-24099 1 Microsoft 2 Lync Server, Skype For Business Server 2024-11-21 6.5 Medium
Skype for Business and Lync Denial of Service Vulnerability
CVE-2021-24073 1 Microsoft 2 Lync Server, Skype For Business Server 2024-11-21 6.5 Medium
Skype for Business and Lync Spoofing Vulnerability
CVE-2020-24003 1 Microsoft 1 Skype 2024-11-21 3.3 Low
Microsoft Skype through 8.59.0.77 on macOS has the disable-library-validation entitlement, which allows a local process (with the user's privileges) to obtain unprompted microphone and camera access by loading a crafted library and thereby inheriting Skype Client's microphone and camera access.
CVE-2020-1025 1 Microsoft 7 Lync, Lync Server, Sharepoint Enterprise Server and 4 more 2024-11-21 9.8 Critical
An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation. An attacker who successfully exploited the vulnerability could bypass authentication and achieve improper access. To exploit this vulnerability, an attacker would need to modify the token. The update addresses the vulnerability by modifying how Microsoft SharePoint Server and Skype for Business Server validate tokens.
CVE-2019-1490 1 Microsoft 1 Skype For Business 2024-11-21 5.4 Medium
A spoofing vulnerability exists when a Skype for Business Server does not properly sanitize a specially crafted request, aka 'Skype for Business Server Spoofing Vulnerability'.
CVE-2019-1084 1 Microsoft 9 Exchange Server, Lync, Lync Basic and 6 more 2024-11-21 N/A
An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security update addresses the issue by validating display names upon creation in Microsoft Exchange, and by rendering invalid display names correctly in Microsoft Outlook clients., aka 'Microsoft Exchange Information Disclosure Vulnerability'.
CVE-2019-0932 1 Microsoft 1 Skype 2024-11-21 N/A
An information disclosure vulnerability exists in Skype for Android, aka 'Skype for Android Information Disclosure Vulnerability'.
CVE-2019-0798 1 Microsoft 2 Lync Server, Skype For Business Server 2024-11-21 N/A
A spoofing vulnerability exists when a Lync Server or Skype for Business Server does not properly sanitize a specially crafted request, aka 'Skype for Business and Lync Spoofing Vulnerability'.
CVE-2019-0624 1 Microsoft 1 Skype For Business 2024-11-21 N/A
A spoofing vulnerability exists when a Skype for Business 2015 server does not properly sanitize a specially crafted request, aka "Skype for Business 2015 Spoofing Vulnerability." This affects Skype.
CVE-2019-0622 1 Microsoft 1 Skype 2024-11-21 N/A
An elevation of privilege vulnerability exists when Skype for Andriod fails to properly handle specific authentication requests, aka "Skype for Android Elevation of Privilege Vulnerability." This affects Skype 8.35.
CVE-2018-8546 1 Microsoft 6 Lync, Lync Basic, Office and 3 more 2024-11-21 N/A
A denial of service vulnerability exists in Skype for Business, aka "Microsoft Skype for Business Denial of Service Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Lync, Skype.
CVE-2018-8311 1 Microsoft 2 Lync, Skype For Business 2024-11-21 N/A
A remote code execution vulnerability exists when Skype for Business and Microsoft Lync clients fail to properly sanitize specially crafted content, aka "Remote Code Execution Vulnerability in Skype For Business and Lync." This affects Skype, Microsoft Lync.
CVE-2018-8238 1 Microsoft 2 Lync, Skype For Business 2024-11-21 N/A
A security feature bypass vulnerability exists when Skype for Business or Lync do not properly parse UNC path links shared via messages, aka "Skype for Business and Lync Security Feature Bypass Vulnerability." This affects Skype, Microsoft Lync.
CVE-2018-0595 1 Microsoft 2 Skype, Windows 2024-11-21 N/A
Untrusted search path vulnerability in the installer of Skype for Windows allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
CVE-2018-0594 1 Microsoft 2 Skype, Windows 2024-11-21 N/A
Untrusted search path vulnerability in Skype for Windows allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.