CVE-2011-2074 describes an unspecified vulnerability in Skype 5.x before version 5.1.0.922 on Mac OS X. This flaw allows remote authenticated users to execute arbitrary code or trigger a denial of service (application crash) through a specially crafted message. With a CVSS score of 8.5, this vulnerability is considered highly severe, indicating a network-based attack with medium complexity that could lead to complete compromise of confidentiality, integrity, and availability. While the EPSS score is low, suggesting limited real-world exploitation, there is no public exploit intelligence available, nor is it listed in CISA's KEV catalog. Community discussion and media coverage for this CVE are minimal, which is typical for the vast majority of reported vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.0.0.105CPE matchmatch criteria | cpe:2.3:a:skype:skype:5.0.0.105:*:*:*:*:*:*:* | ||
5.0.0.105CPE matchmatch criteria | cpe:2.3:a:skype:skype:5.0.0.105:beta:*:*:*:*:*:* | ||
5.0.0.123CPE matchmatch criteria | cpe:2.3:a:skype:skype:5.0.0.123:beta:*:*:*:*:*:* | ||
5.0.0.152CPE matchmatch criteria | cpe:2.3:a:skype:skype:5.0.0.152:*:*:*:*:*:*:* | ||
5.0.0.156CPE matchmatch criteria | cpe:2.3:a:skype:skype:5.0.0.156:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:S/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.