Sky Software develops a focused set of ActiveX controls for Windows file-browsing and UI components, including FileView, ShComboBox, and Shell MegaPack. The vendor's disclosures relate to control-layer weaknesses typical of legacy component-based development; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sky Software over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-3890HIGH Stack-based buffer overflow in the Sky Software FileView ActiveX control, as used in WinZip 10 before build 7245 and in certain other applications, allows remote attackers to execu | Nov 21, 2006 | 9.3 | 40 | NO | YES |
CVE-2007-2848HIGH Stack-based buffer overflow in the SetPath function in the shComboBox ActiveX control (shcmb80.ocx) in Sky Software Shell MegaPack ActiveX 8.0 allows remote attackers to execute ar | May 24, 2007 | 10.0 | 26 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sky Software.
Media articles that mention a CVE ID that affects a product developed by Sky Software — matched by CVE ID, not by vendor name.