CVE-2009-2064
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
15/06/2009
Last modified:
09/04/2025
Description
Microsoft Internet Explorer 8, and possibly other versions, detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying an http page to include an https iframe that references a script file on an http site, related to "HTTP-Intended-but-HTTPS-Loadable (HPIHSL) pages."
Impact
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:microsoft:internet_explorer:*:beta2:*:*:*:*:*:* | 8 (including) | |
cpe:2.3:a:microsoft:internet_explorer:5:*:*:*:*:*:*:* | ||
cpe:2.3:a:microsoft:internet_explorer:5.01:sp4:*:*:*:*:*:* | ||
cpe:2.3:a:microsoft:internet_explorer:6:*:*:*:*:*:*:* | ||
cpe:2.3:a:microsoft:internet_explorer:6:sp1:*:*:*:*:*:* | ||
cpe:2.3:a:microsoft:internet_explorer:6:sp2:*:*:*:*:*:* | ||
cpe:2.3:a:microsoft:internet_explorer:7:*:*:*:*:*:*:* | ||
cpe:2.3:a:microsoft:internet_explorer:7.0.5730:*:*:*:*:*:*:* | ||
cpe:2.3:a:microsoft:internet_explorer:8:*:*:*:*:*:*:* | ||
cpe:2.3:a:microsoft:internet_explorer:8:beta1:*:*:*:*:*:* | ||
cpe:2.3:a:microsoft:internet_explorer:8.0b:*:*:*:*:*:*:* | ||
cpe:2.3:a:microsoft:pocket_ie:1.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:microsoft:pocket_ie:1.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:microsoft:pocket_ie:2.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:microsoft:pocket_ie:3.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://research.microsoft.com/apps/pubs/default.aspx?id=79323
- http://research.microsoft.com/pubs/79323/pbp-final-with-update.pdf
- http://www.securityfocus.com/bid/35403
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51186
- http://research.microsoft.com/apps/pubs/default.aspx?id=79323
- http://research.microsoft.com/pubs/79323/pbp-final-with-update.pdf
- http://www.securityfocus.com/bid/35403
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51186