Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2009-2069


Microsoft Internet Explorer before 8 displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which allows man-in-the-middle attackers to spoof an arbitrary https site by letting a browser obtain a valid certificate from this site during one request, and then sending the browser a crafted 502 response page upon a subsequent request.


Published

2009-06-15T19:30:05.687

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 5.8 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application microsoft ie 5.0 Yes
Application microsoft ie 5.0 Yes
Application microsoft ie 5.22 Yes
Application microsoft ie 6.0 Yes
Application microsoft ie 6.0 Yes
Application microsoft internet_explorer 3.0 Yes
Application microsoft internet_explorer 3.0.1 Yes
Application microsoft internet_explorer 3.0.2 Yes
Application microsoft internet_explorer 3.1 Yes
Application microsoft internet_explorer 3.2 Yes
Application microsoft internet_explorer 4.0 Yes
Application microsoft internet_explorer 4.0.1 Yes
Application microsoft internet_explorer 4.0.1 Yes
Application microsoft internet_explorer 4.0.1 Yes
Application microsoft internet_explorer 4.01 Yes
Application microsoft internet_explorer 4.1 Yes
Application microsoft internet_explorer 4.01 Yes
Application microsoft internet_explorer 4.5 Yes
Application microsoft internet_explorer 4.40.308 Yes
Application microsoft internet_explorer 4.40.520 Yes
Application microsoft internet_explorer 4.70.1155 Yes
Application microsoft internet_explorer 4.70.1158 Yes
Application microsoft internet_explorer 4.70.1215 Yes
Application microsoft internet_explorer 4.70.1300 Yes
Application microsoft internet_explorer 4.71.544 Yes
Application microsoft internet_explorer 4.71.1008.3 Yes
Application microsoft internet_explorer 4.71.1712.6 Yes
Application microsoft internet_explorer 4.72.2106.8 Yes
Application microsoft internet_explorer 4.72.3110.8 Yes
Application microsoft internet_explorer 4.72.3612.1713 Yes
Application microsoft internet_explorer 5 Yes
Application microsoft internet_explorer 5.0 Yes
Application microsoft internet_explorer 5.0.1 Yes
Application microsoft internet_explorer 5.0.1 Yes
Application microsoft internet_explorer 5.0.1 Yes
Application microsoft internet_explorer 5.0.1 Yes
Application microsoft internet_explorer 5.0.1 Yes
Application microsoft internet_explorer 5.00.0518.10 Yes
Application microsoft internet_explorer 5.00.0910.1309 Yes
Application microsoft internet_explorer 5.00.2014.0216 Yes
Application microsoft internet_explorer 5.00.2314.1003 Yes
Application microsoft internet_explorer 5.00.2614.3500 Yes
Application microsoft internet_explorer 5.00.2919.800 Yes
Application microsoft internet_explorer 5.00.2919.3800 Yes
Application microsoft internet_explorer 5.00.2919.6307 Yes
Application microsoft internet_explorer 5.00.2920.0000 Yes
Application microsoft internet_explorer 5.00.3103.1000 Yes
Application microsoft internet_explorer 5.00.3105.0106 Yes
Application microsoft internet_explorer 5.00.3314.2101 Yes
Application microsoft internet_explorer 5.00.3315.1000 Yes
Application microsoft internet_explorer 5.00.3502.1000 Yes
Application microsoft internet_explorer 5.00.3700.1000 Yes
Application microsoft internet_explorer 5.01 Yes
Application microsoft internet_explorer 5.1 Yes
Application microsoft internet_explorer 5.01 Yes
Application microsoft internet_explorer 5.01 Yes
Application microsoft internet_explorer 5.01 Yes
Application microsoft internet_explorer 5.01 Yes
Application microsoft internet_explorer 5.2.3 Yes
Application microsoft internet_explorer 5.5 Yes
Application microsoft internet_explorer 5.5 Yes
Application microsoft internet_explorer 5.5 Yes
Application microsoft internet_explorer 5.5 Yes
Application microsoft internet_explorer 5.50.3825.1300 Yes
Application microsoft internet_explorer 5.50.4030.2400 Yes
Application microsoft internet_explorer 5.50.4134.0600 Yes
Application microsoft internet_explorer 5.50.4308.2900 Yes
Application microsoft internet_explorer 5.50.4522.1800 Yes
Application microsoft internet_explorer 5.50.4807.2300 Yes
Application microsoft internet_explorer 6 Yes
Application microsoft internet_explorer 6 Yes
Application microsoft internet_explorer 6.0 Yes
Application microsoft internet_explorer 6.00.2462.0000 Yes
Application microsoft internet_explorer 6.00.2479.0006 Yes
Application microsoft internet_explorer 6.0.2600 Yes
Application microsoft internet_explorer 6.0.2800 Yes
Application microsoft internet_explorer 6.0.2800.1106 Yes
Application microsoft internet_explorer 6.00.2800.1106 Yes
Application microsoft internet_explorer 6.0.2900 Yes
Application microsoft internet_explorer 6.0.2900.2180 Yes
Application microsoft internet_explorer 6.00.2900.2180 Yes
Application microsoft internet_explorer 6.00.3663.0000 Yes
Application microsoft internet_explorer 6.00.3790.0000 Yes
Application microsoft internet_explorer 6.00.3790.1830 Yes
Application microsoft internet_explorer 6.00.3790.3959 Yes
Application microsoft internet_explorer 7 Yes
Application microsoft internet_explorer 7.0 Yes
Application microsoft internet_explorer 7.0 Yes
Application microsoft internet_explorer 7.0 Yes
Application microsoft internet_explorer 7.0 Yes
Application microsoft internet_explorer 7.0.5730.11 Yes
Application microsoft internet_explorer 7.00.5730.1100 Yes
Application microsoft internet_explorer 7.00.6000.16386 Yes
Application microsoft internet_explorer 7.00.6000.16441 Yes

References