5.8
CVE-2009-2057
- EPSS 3.03%
- Veröffentlicht 15.06.2009 19:30:00
- Zuletzt bearbeitet 16.06.2026 23:08:40
- Erkennungen
Microsoft Internet Explorer before 8 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Internet Explorer Version 3.0
Microsoft ≫ Internet Explorer Version 3.0.1
Microsoft ≫ Internet Explorer Version 3.0.2
Microsoft ≫ Internet Explorer Version 3.1
Microsoft ≫ Internet Explorer Version 3.2
Microsoft ≫ Internet Explorer Version 4.0
Microsoft ≫ Internet Explorer Version 4.0.1
Microsoft ≫ Internet Explorer Version 4.0.1 Update sp1
Microsoft ≫ Internet Explorer Version 4.0.1 Update sp2
Microsoft ≫ Internet Explorer Version 4.01
Microsoft ≫ Internet Explorer Version 4.1
Microsoft ≫ Internet Explorer Version 4.01 Update sp1
Microsoft ≫ Internet Explorer Version 4.5
Microsoft ≫ Internet Explorer Version 4.40.308
Microsoft ≫ Internet Explorer Version 4.40.520
Microsoft ≫ Internet Explorer Version 4.70.1155
Microsoft ≫ Internet Explorer Version 4.70.1158
Microsoft ≫ Internet Explorer Version 4.70.1215
Microsoft ≫ Internet Explorer Version 4.70.1300
Microsoft ≫ Internet Explorer Version 4.71.544
Microsoft ≫ Internet Explorer Version 4.71.1008.3
Microsoft ≫ Internet Explorer Version 4.71.1712.6
Microsoft ≫ Internet Explorer Version 4.72.2106.8
Microsoft ≫ Internet Explorer Version 4.72.3110.8
Microsoft ≫ Internet Explorer Version 4.72.3612.1713
Microsoft ≫ Internet Explorer Version 5
Microsoft ≫ Internet Explorer Version 5.0
Microsoft ≫ Internet Explorer Version 5.0.1
Microsoft ≫ Internet Explorer Version 5.0.1 Update sp1
Microsoft ≫ Internet Explorer Version 5.0.1 Update sp2
Microsoft ≫ Internet Explorer Version 5.0.1 Update sp3
Microsoft ≫ Internet Explorer Version 5.0.1 Update sp4
Microsoft ≫ Internet Explorer Version 5.00.0518.10
Microsoft ≫ Internet Explorer Version 5.00.0910.1309
Microsoft ≫ Internet Explorer Version 5.00.2014.0216
Microsoft ≫ Internet Explorer Version 5.00.2314.1003
Microsoft ≫ Internet Explorer Version 5.00.2614.3500
Microsoft ≫ Internet Explorer Version 5.00.2919.800
Microsoft ≫ Internet Explorer Version 5.00.2919.3800
Microsoft ≫ Internet Explorer Version 5.00.2919.6307
Microsoft ≫ Internet Explorer Version 5.00.2920.0000
Microsoft ≫ Internet Explorer Version 5.00.3103.1000
Microsoft ≫ Internet Explorer Version 5.00.3105.0106
Microsoft ≫ Internet Explorer Version 5.00.3314.2101
Microsoft ≫ Internet Explorer Version 5.00.3315.1000
Microsoft ≫ Internet Explorer Version 5.00.3502.1000
Microsoft ≫ Internet Explorer Version 5.00.3700.1000
Microsoft ≫ Internet Explorer Version 5.01
Microsoft ≫ Internet Explorer Version 5.1
Microsoft ≫ Internet Explorer Version 5.01 Update sp1
Microsoft ≫ Internet Explorer Version 5.01 Update sp2
Microsoft ≫ Internet Explorer Version 5.01 Update sp3
Microsoft ≫ Internet Explorer Version 5.01 Update sp4
Microsoft ≫ Internet Explorer Version 5.2.3
Microsoft ≫ Internet Explorer Version 5.5
Microsoft ≫ Internet Explorer Version 5.5 Update preview
Microsoft ≫ Internet Explorer Version 5.5 Update sp1
Microsoft ≫ Internet Explorer Version 5.5 Update sp2
Microsoft ≫ Internet Explorer Version 5.50.3825.1300
Microsoft ≫ Internet Explorer Version 5.50.4030.2400
Microsoft ≫ Internet Explorer Version 5.50.4134.0600
Microsoft ≫ Internet Explorer Version 5.50.4308.2900
Microsoft ≫ Internet Explorer Version 5.50.4522.1800
Microsoft ≫ Internet Explorer Version 5.50.4807.2300
Microsoft ≫ Internet Explorer Version 6
Microsoft ≫ Internet Explorer Version 6 Update sp1
Microsoft ≫ Internet Explorer Version 6.0
Microsoft ≫ Internet Explorer Version 6.00.2462.0000
Microsoft ≫ Internet Explorer Version 6.00.2479.0006
Microsoft ≫ Internet Explorer Version 6.0.2600
Microsoft ≫ Internet Explorer Version 6.0.2800
Microsoft ≫ Internet Explorer Version 6.0.2800.1106
Microsoft ≫ Internet Explorer Version 6.00.2800.1106
Microsoft ≫ Internet Explorer Version 6.0.2900
Microsoft ≫ Internet Explorer Version 6.0.2900.2180
Microsoft ≫ Internet Explorer Version 6.00.2900.2180
Microsoft ≫ Internet Explorer Version 6.00.3663.0000
Microsoft ≫ Internet Explorer Version 6.00.3790.0000
Microsoft ≫ Internet Explorer Version 6.00.3790.1830
Microsoft ≫ Internet Explorer Version 6.00.3790.3959
Microsoft ≫ Internet Explorer Version 7
Microsoft ≫ Internet Explorer Version 7.0
Microsoft ≫ Internet Explorer Version 7.0 Update beta
Microsoft ≫ Internet Explorer Version 7.0 Update beta1
Microsoft ≫ Internet Explorer Version 7.0 Update beta3
Microsoft ≫ Internet Explorer Version 7.0.5730.11
Microsoft ≫ Internet Explorer Version 7.00.5730.1100
Microsoft ≫ Internet Explorer Version 7.00.6000.16386
Microsoft ≫ Internet Explorer Version 7.00.6000.16441
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.03% | 0.857 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:P/I:P/A:N
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
http://research.microsoft.com/apps/pubs/default.aspx?id=79323
http://research.microsoft.com/pubs/79323/pbp-final-with-update.pdf