CVE-2009-2057

CVSS V2 Medium 5.8 CVSS V3 None
Description
Microsoft Internet Explorer before 8 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.
Overview
  • CVE ID
  • CVE-2009-2057
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2009-06-15T19:30:00
  • Last Modified Date
  • 2021-07-23T15:06:52
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:microsoft:ie:5.0:sp1:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:ie:5.0:sp4:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:ie:5.22:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:ie:6.0:sp2:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:3.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:3.0.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:3.0.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:3.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:3.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:4.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:4.0.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:4.0.1:sp1:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:4.0.1:sp2:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:4.01:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:4.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:4.01:sp1:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:4.5:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:4.40.308:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:4.40.520:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:4.70.1155:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:4.70.1158:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:4.70.1215:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:4.70.1300:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:4.71.544:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:4.71.1008.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:4.71.1712.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:4.72.2106.8:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:4.72.3110.8:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:4.72.3612.1713:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.0.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp1:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp2:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp3:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp4:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.00.0518.10:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.00.0910.1309:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.00.2014.0216:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.00.2314.1003:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.00.2614.3500:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.00.2919.800:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.00.2919.3800:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.00.2919.6307:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.00.2920.0000:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.00.3103.1000:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.00.3105.0106:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.00.3314.2101:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.00.3315.1000:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.00.3502.1000:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.00.3700.1000:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.01:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.01:sp1:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.01:sp2:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.01:sp3:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.01:sp4:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.2.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.5:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.5:preview:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.5:sp1:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.5:sp2:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.50.3825.1300:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.50.4030.2400:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.50.4134.0600:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.50.4308.2900:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.50.4522.1800:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:5.50.4807.2300:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:6:sp1:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:6.00.2462.0000:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:6.00.2479.0006:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:6.0.2600:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:6.0.2800:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:6.0.2800.1106:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:6.00.2800.1106:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:6.0.2900:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:6.0.2900.2180:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:6.00.2900.2180:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:6.00.3663.0000:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:6.00.3790.0000:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:6.00.3790.1830:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:6.00.3790.3959:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:7:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:7.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:7.0:beta:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:7.0:beta1:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:7.0:beta3:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:7.0.5730.11:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:7.00.5730.1100:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:7.00.6000.16386:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:microsoft:internet_explorer:7.00.6000.16441:*:*:*:*:*:*:* 1 OR
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:N/AC:M/Au:N/C:P/I:P/A:N
  • Access Vector
  • NETWORK
  • Access Compatibility
  • MEDIUM
  • Authentication
  • NONE
  • Confidentiality Impact
  • PARTIAL
  • Integrity Impact
  • PARTIAL
  • Availability Impact
  • NONE
  • Base Score
  • 5.8
  • Severity
  • MEDIUM
  • Exploitability Score
  • 8.6
  • Impact Score
  • 4.9
History
Created Old Value New Value Data Type Notes
2022-05-10 15:53:23 Added to TrackCVE