peter bassill · operator
$ cve CVE-2009-1140 JSON

CVE-2009-1140 EXPLOIT

7.1
HIGH · CVSS 2.0 · EPSS 24.8% (pctl 98)

Patch early

A public exploit exists.

Description

Microsoft Internet Explorer 5.01 SP4; 6 SP1; 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 does not prevent HTML rendering of cached content, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Cross-Domain Information Disclosure Vulnerability."

Scoring

CVSS7.1 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:N/A:N
EPSS24.76% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploityes
Published2009-06-10
Last modified2026-06-16

Affected (6)

VendorProduct
microsoftinternet explorer
microsoftwindows 2000
microsoftwindows server 2003
microsoftwindows server 2008
microsoftwindows vista
microsoftwindows xp

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD