>> Skype "skype4com" URI Handler Remote Heap Corruption Vulnerability
Title : Skype "skype4com" URI Handler Remote Heap Corruption Vulnerability VUPEN ID : VUPEN/ADV-2007-4110 CVE ID : CVE-2007-5989
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-12-07
Technical Description
A vulnerability has been identified in Skype, which could be exploited by attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a memory corruption error within the "skype4com" URI handler when processing short string values, which could be exploited by attackers to crash an affected application or execute arbitrary code by tricking a user into visiting a specially crafted web page.