Skype maintains a narrowly scoped vulnerability footprint centered on its voice, video, and messaging application and browser extensions, which remain widely deployed for workplace and personal communication. The recurring exposure clusters around configuration and argument-handling issues such as improper neutralization of command delimiters, incorrect default permissions, and insecure variable initialization, reflecting typical risks in application-layer boundary handling. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Skype over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-3136HIGH Untrusted search path vulnerability in Skype 4.2.0.169 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks vi | Aug 26, 2010 | 9.3 | 40 | NO | YES |
CVE-2024-21411HIGH Skype for Consumer Remote Code Execution Vulnerability | Mar 12, 2024 | 8.8 | 27 | NO | NO |
CVE-2009-4741HIGH Unspecified vulnerability in the Extras Manager before 2.0.0.67 in Skype before 4.1.0.179 on Windows has unknown impact and attack vectors. | Mar 26, 2010 | 10.0 | 27 | NO | NO |
CVE-2011-2074HIGH Unspecified vulnerability in the client in Skype 5.x before 5.1.0.922 on Mac OS X allows remote authenticated users to execute arbitrary code or cause a denial of service (applicat | May 10, 2011 | 8.5 | 25 | NO | NO |
CVE-2008-5697MEDIUM The skype_tool.copy_num method in the Skype extension BETA 2.2.0.95 for Firefox allows remote attackers to write arbitrary data to the clipboard via a string argument. | Dec 22, 2008 | 4.3 | 21 | NO | YES |
CVE-2004-1778MEDIUM Skype 0.92.0.12 and 1.0.0.1 for Linux, and possibly other versions, creates the /usr/share/skype/lang directory with world-writable permissions, which allows local users to modify | Dec 22, 2004 | 4.6 | 16 | NO | NO |
Skype for Android stores sensitive user data without encryption in sqlite3 databases that have weak permissions, which allows local applications to read user IDs, contacts, phone n | Apr 18, 2011 | 2.1 | 14 | NO | NO |
Argument injection vulnerability in the URI handler in Skype 2.0.*.104 and 2.5.*.0 through 2.5.*.78 for Windows allows remote authorized attackers to download arbitrary files via a | May 19, 2006 | 2.6 | 12 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Skype.
Media articles that mention a CVE ID that affects a product developed by Skype — matched by CVE ID, not by vendor name.