6.8

CVE-2009-2064

Microsoft Internet Explorer 8, and possibly other versions, detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying an http page to include an https iframe that references a script file on an http site, related to "HTTP-Intended-but-HTTPS-Loadable (HPIHSL) pages."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Internet Explorer Update beta2 Version <= 8
Microsoft ≫ Internet Explorer Version 5.01 Update sp4
Microsoft ≫ Internet Explorer Version 6 Update sp1
Microsoft ≫ Internet Explorer Version 6 Update sp2
Microsoft ≫ Internet Explorer Version 7.0.5730
Microsoft ≫ Internet Explorer Version 8 Update beta1
Microsoft ≫ Internet Explorer Version 8.0b
Microsoft ≫ Pocket Ie Version 1.0
Microsoft ≫ Pocket Ie Version 1.1
Microsoft ≫ Pocket Ie Version 2.0
Microsoft ≫ Pocket Ie Version 3.0
Microsoft ≫ Pocket Ie Version 4.0
Microsoft ≫ Pocket Ie Version 2002
Microsoft ≫ Pocket Ie Version 2003
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.27% 0.898
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

http://research.microsoft.com/apps/pubs/default.aspx?id=79323
http://research.microsoft.com/pubs/79323/pbp-final-with-update.pdf
http://www.securityfocus.com/bid/35403
https://exchange.xforce.ibmcloud.com/vulnerabilities/51186