{"api_version":"1","generated_at":"2026-07-23T11:31:23+00:00","cve":"CVE-2011-1717","urls":{"html":"https://cve.report/CVE-2011-1717","api":"https://cve.report/api/cve/CVE-2011-1717.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2011-1717","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2011-1717"},"summary":{"title":"CVE-2011-1717","description":"Skype for Android stores sensitive user data without encryption in sqlite3 databases that have weak permissions, which allows local applications to read user IDs, contacts, phone numbers, date of birth, instant message logs, and other private information.","state":"PUBLISHED","assigner":"mitre","published_at":"2011-04-18 18:55:02","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.1","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securitytracker.com/id?1025387","name":"http://www.securitytracker.com/id?1025387","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Skype for Android Lets Local Users Obtain Potentially Sensitive Information - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://blogs.skype.com/security/2011/04/privacy_vulnerability_in_skype.html","name":"http://blogs.skype.com/security/2011/04/privacy_vulnerability_in_skype.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Skype - Skype Security blog - [Fixed] Privacy vulnerability in Skype for Android","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.androidpolice.com/2011/04/14/exclusive-vulnerability-in-skype-for-android-is-exposing-your-name-phone-number-chat-logs-and-a-lot-more/","name":"http://www.androidpolice.com/2011/04/14/exclusive-vulnerability-in-skype-for-android-is-exposing-your-name-phone-number-chat-logs-and-a-lot-more/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"[Updated] Exclusive: Vulnerability In Skype For Android Is Exposing Your Name, Phone Number, Chat Logs, And A Lot More","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.theregister.co.uk/2011/04/15/skype_for_android_vulnerable/","name":"http://www.theregister.co.uk/2011/04/15/skype_for_android_vulnerable/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Skype for Android is vulnerable • The Register","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2011-1717","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-1717","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2011","cve_id":"1717","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"skype","cpe5":"skype_for_android","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T22:37:25.531Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.androidpolice.com/2011/04/14/exclusive-vulnerability-in-skype-for-android-is-exposing-your-name-phone-number-chat-logs-and-a-lot-more/"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://blogs.skype.com/security/2011/04/privacy_vulnerability_in_skype.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.theregister.co.uk/2011/04/15/skype_for_android_vulnerable/"},{"name":"1025387","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1025387"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2011-04-15T00:00:00.000Z","descriptions":[{"lang":"en","value":"Skype for Android stores sensitive user data without encryption in sqlite3 databases that have weak permissions, which allows local applications to read user IDs, contacts, phone numbers, date of birth, instant message logs, and other private information."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2011-05-12T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://www.androidpolice.com/2011/04/14/exclusive-vulnerability-in-skype-for-android-is-exposing-your-name-phone-number-chat-logs-and-a-lot-more/"},{"tags":["x_refsource_CONFIRM"],"url":"http://blogs.skype.com/security/2011/04/privacy_vulnerability_in_skype.html"},{"tags":["x_refsource_MISC"],"url":"http://www.theregister.co.uk/2011/04/15/skype_for_android_vulnerable/"},{"name":"1025387","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1025387"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2011-1717","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Skype for Android stores sensitive user data without encryption in sqlite3 databases that have weak permissions, which allows local applications to read user IDs, contacts, phone numbers, date of birth, instant message logs, and other private information."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.androidpolice.com/2011/04/14/exclusive-vulnerability-in-skype-for-android-is-exposing-your-name-phone-number-chat-logs-and-a-lot-more/","refsource":"MISC","url":"http://www.androidpolice.com/2011/04/14/exclusive-vulnerability-in-skype-for-android-is-exposing-your-name-phone-number-chat-logs-and-a-lot-more/"},{"name":"http://blogs.skype.com/security/2011/04/privacy_vulnerability_in_skype.html","refsource":"CONFIRM","url":"http://blogs.skype.com/security/2011/04/privacy_vulnerability_in_skype.html"},{"name":"http://www.theregister.co.uk/2011/04/15/skype_for_android_vulnerable/","refsource":"MISC","url":"http://www.theregister.co.uk/2011/04/15/skype_for_android_vulnerable/"},{"name":"1025387","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1025387"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2011-1717","datePublished":"2011-04-18T18:00:00.000Z","dateReserved":"2011-04-18T00:00:00.000Z","dateUpdated":"2024-08-06T22:37:25.531Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2011-04-18 18:55:02","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:skype:skype_for_android:*:*:*:*:*:*:*:*","matchCriteriaId":"54DDA959-111A-438A-A24F-4FFBD371ACE1"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2011","CveId":"1717","Ordinal":"1","Title":"CVE-2011-1717","CVE":"CVE-2011-1717","Year":"2011"},"notes":[{"CveYear":"2011","CveId":"1717","Ordinal":"1","NoteData":"Skype for Android stores sensitive user data without encryption in sqlite3 databases that have weak permissions, which allows local applications to read user IDs, contacts, phone numbers, date of birth, instant message logs, and other private information.","Type":"Description","Title":"CVE-2011-1717"},{"CveYear":"2011","CveId":"1717","Ordinal":"2","NoteData":"2011-04-18","Type":"Other","Title":"Published"},{"CveYear":"2011","CveId":"1717","Ordinal":"3","NoteData":"2011-05-12","Type":"Other","Title":"Modified"}]}}}