← Back

CVE-2009-2057

nvd nist
Published: Jun 15, 2009Modified: Apr 23, 2026

JSON object

Loading...
5.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:N
Exploitability: 8.6 / Impact: 4.9
Source: NVD

Description

Microsoft Internet Explorer before 8 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.

Affected (94)

2 products
Ie
Internet Explorer
Configuration A
94 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Version 5.0 sp1
Version 5.0 sp4
Version 5.22
Version 6.0 sp1
Version 6.0 sp2
Microsoft
Version 3.0.1
Version 3.0.2
Version 3.0
Version 3.1
Version 3.2
Version 4.0.1
Version 4.0.1 sp1
Version 4.0.1 sp2
Version 4.01
Version 4.01 sp1
Version 4.0
Version 4.1
Version 4.40.308
Version 4.40.520
Version 4.5
Version 4.70.1155
Version 4.70.1158
Version 4.70.1215
Version 4.70.1300
Version 4.71.1008.3
Version 4.71.1712.6
Version 4.71.544
Version 4.72.2106.8
Version 4.72.3110.8
Version 4.72.3612.1713
Version 5.0.1
Version 5.0.1 sp1
Version 5.0.1 sp2
Version 5.0.1 sp3
Version 5.0.1 sp4
Version 5.00.0518.10
Version 5.00.0910.1309
Version 5.00.2014.0216
Version 5.00.2314.1003
Version 5.00.2614.3500
Version 5.00.2919.3800
Version 5.00.2919.6307
Version 5.00.2919.800
Version 5.00.2920.0000
Version 5.00.3103.1000
Version 5.00.3105.0106
Version 5.00.3314.2101
Version 5.00.3315.1000
Version 5.00.3502.1000
Version 5.00.3700.1000
Version 5.01
Version 5.01 sp1
Version 5.01 sp2
Version 5.01 sp3
Version 5.01 sp4
Version 5.0
Version 5.1
Version 5.2.3
Version 5.50.3825.1300
Version 5.50.4030.2400
Version 5.50.4134.0600
Version 5.50.4308.2900
Version 5.50.4522.1800
Version 5.50.4807.2300
Version 5.5
Version 5.5 preview
Version 5.5 sp1
Version 5.5 sp2
Version 5
Version 6.0.2600
Version 6.0.2800.1106
Version 6.0.2800
Version 6.0.2900.2180
Version 6.0.2900
Version 6.00.2462.0000
Version 6.00.2479.0006
Version 6.00.2800.1106
Version 6.00.2900.2180
Version 6.00.3663.0000
Version 6.00.3790.0000
Version 6.00.3790.1830
Version 6.00.3790.3959
Version 6.0
Version 6
Version 6 sp1
Version 7.0.5730.11
Version 7.00.5730.1100
Version 7.00.6000.16386
Version 7.00.6000.16441
Version 7.0
Version 7.0 beta1
Version 7.0 beta3
Version 7.0 beta
Version 7

Timeline

No history available yet.