Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Filtered by product Skype For Business Server Subscription Edition
Total 10 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-69646 1 Microsoft 2 Skype For Business Server, Skype For Business Server Subscription Edition 2026-09-16 N/A 8.3 HIGH
Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.
CVE-2026-69642 1 Microsoft 2 Skype For Business Server, Skype For Business Server Subscription Edition 2026-09-16 N/A 6.5 MEDIUM
Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-66308 1 Microsoft 2 Skype For Business Server, Skype For Business Server Subscription Edition 2026-09-16 N/A 6.5 MEDIUM
Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network.
CVE-2026-66307 1 Microsoft 2 Skype For Business Server, Skype For Business Server Subscription Edition 2026-09-16 N/A 7.5 HIGH
Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.
CVE-2026-66306 1 Microsoft 2 Skype For Business Server, Skype For Business Server Subscription Edition 2026-09-16 N/A 6.5 MEDIUM
Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.
CVE-2026-66305 1 Microsoft 2 Skype For Business Server, Skype For Business Server Subscription Edition 2026-09-16 N/A 7.1 HIGH
Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network.
CVE-2026-66304 1 Microsoft 2 Skype For Business Server, Skype For Business Server Subscription Edition 2026-09-16 N/A 7.5 HIGH
Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.
CVE-2026-66303 1 Microsoft 2 Skype For Business Server, Skype For Business Server Subscription Edition 2026-09-16 N/A 6.5 MEDIUM
Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.
CVE-2026-66302 1 Microsoft 2 Skype For Business Server, Skype For Business Server Subscription Edition 2026-09-16 N/A 9.8 CRITICAL
External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.
CVE-2026-63523 1 Microsoft 2 Skype For Business Server, Skype For Business Server Subscription Edition 2026-09-16 N/A 6.5 MEDIUM
Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.