5.8

CVE-2009-2057

Exploit

Microsoft Internet Explorer before 8 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MicrosoftIe Version5.0 Updatesp1
MicrosoftIe Version5.0 Updatesp4
MicrosoftIe Version5.22
MicrosoftIe Version6.0 Updatesp1
MicrosoftIe Version6.0 Updatesp2
MicrosoftInternet Explorer Version3.0
MicrosoftInternet Explorer Version3.0.1
MicrosoftInternet Explorer Version3.0.2
MicrosoftInternet Explorer Version3.1
MicrosoftInternet Explorer Version3.2
MicrosoftInternet Explorer Version4.0
MicrosoftInternet Explorer Version4.0.1
MicrosoftInternet Explorer Version4.0.1 Updatesp1
MicrosoftInternet Explorer Version4.0.1 Updatesp2
MicrosoftInternet Explorer Version4.01
MicrosoftInternet Explorer Version4.1
MicrosoftInternet Explorer Version4.01 Updatesp1
MicrosoftInternet Explorer Version4.5
MicrosoftInternet Explorer Version4.40.308
MicrosoftInternet Explorer Version4.40.520
MicrosoftInternet Explorer Version4.70.1155
MicrosoftInternet Explorer Version4.70.1158
MicrosoftInternet Explorer Version4.70.1215
MicrosoftInternet Explorer Version4.70.1300
MicrosoftInternet Explorer Version4.71.544
MicrosoftInternet Explorer Version4.71.1008.3
MicrosoftInternet Explorer Version4.71.1712.6
MicrosoftInternet Explorer Version4.72.2106.8
MicrosoftInternet Explorer Version4.72.3110.8
MicrosoftInternet Explorer Version4.72.3612.1713
MicrosoftInternet Explorer Version5.0
MicrosoftInternet Explorer Version5.0.1
MicrosoftInternet Explorer Version5.0.1 Updatesp1
MicrosoftInternet Explorer Version5.0.1 Updatesp2
MicrosoftInternet Explorer Version5.0.1 Updatesp3
MicrosoftInternet Explorer Version5.0.1 Updatesp4
MicrosoftInternet Explorer Version5.00.0518.10
MicrosoftInternet Explorer Version5.00.0910.1309
MicrosoftInternet Explorer Version5.00.2014.0216
MicrosoftInternet Explorer Version5.00.2314.1003
MicrosoftInternet Explorer Version5.00.2614.3500
MicrosoftInternet Explorer Version5.00.2919.800
MicrosoftInternet Explorer Version5.00.2919.3800
MicrosoftInternet Explorer Version5.00.2919.6307
MicrosoftInternet Explorer Version5.00.2920.0000
MicrosoftInternet Explorer Version5.00.3103.1000
MicrosoftInternet Explorer Version5.00.3105.0106
MicrosoftInternet Explorer Version5.00.3314.2101
MicrosoftInternet Explorer Version5.00.3315.1000
MicrosoftInternet Explorer Version5.00.3502.1000
MicrosoftInternet Explorer Version5.00.3700.1000
MicrosoftInternet Explorer Version5.01
MicrosoftInternet Explorer Version5.1
MicrosoftInternet Explorer Version5.01 Updatesp1
MicrosoftInternet Explorer Version5.01 Updatesp2
MicrosoftInternet Explorer Version5.01 Updatesp3
MicrosoftInternet Explorer Version5.01 Updatesp4
MicrosoftInternet Explorer Version5.2.3
MicrosoftInternet Explorer Version5.5
MicrosoftInternet Explorer Version5.5 Updatepreview
MicrosoftInternet Explorer Version5.5 Updatesp1
MicrosoftInternet Explorer Version5.5 Updatesp2
MicrosoftInternet Explorer Version5.50.3825.1300
MicrosoftInternet Explorer Version5.50.4030.2400
MicrosoftInternet Explorer Version5.50.4134.0600
MicrosoftInternet Explorer Version5.50.4308.2900
MicrosoftInternet Explorer Version5.50.4522.1800
MicrosoftInternet Explorer Version5.50.4807.2300
MicrosoftInternet Explorer Version6 Updatesp1
MicrosoftInternet Explorer Version6.0
MicrosoftInternet Explorer Version6.00.2462.0000
MicrosoftInternet Explorer Version6.00.2479.0006
MicrosoftInternet Explorer Version6.0.2600
MicrosoftInternet Explorer Version6.0.2800
MicrosoftInternet Explorer Version6.0.2800.1106
MicrosoftInternet Explorer Version6.00.2800.1106
MicrosoftInternet Explorer Version6.0.2900
MicrosoftInternet Explorer Version6.0.2900.2180
MicrosoftInternet Explorer Version6.00.2900.2180
MicrosoftInternet Explorer Version6.00.3663.0000
MicrosoftInternet Explorer Version6.00.3790.0000
MicrosoftInternet Explorer Version6.00.3790.1830
MicrosoftInternet Explorer Version6.00.3790.3959
MicrosoftInternet Explorer Version7.0
MicrosoftInternet Explorer Version7.0 Updatebeta
MicrosoftInternet Explorer Version7.0 Updatebeta1
MicrosoftInternet Explorer Version7.0 Updatebeta3
MicrosoftInternet Explorer Version7.0.5730.11
MicrosoftInternet Explorer Version7.00.5730.1100
MicrosoftInternet Explorer Version7.00.6000.16386
MicrosoftInternet Explorer Version7.00.6000.16441
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 11.95% 0.931
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.