Vulnerabilities > CVE-2004-0845 - Unspecified vulnerability in Microsoft IE and Internet Explorer

047910
CVSS 6.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
microsoft

Summary

Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.

Vulnerable Configurations

Part Description Count
Application
Microsoft
3

Oval

  • accepted2014-02-24T04:02:53.847-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameJohn Hoyland
      organizationCentennial Software
    • nameJohn Hoyland
      organizationCentennial Software
    • nameJeff Cheng
      organizationOpsware, Inc.
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionInternet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.
    familywindows
    idoval:org.mitre.oval:def:2219
    statusaccepted
    submitted2004-10-26T04:00:00.000-04:00
    titleIE v6.0 SSL Cached Content Vulnerability
    version70
  • accepted2014-02-24T04:03:17.096-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameJohn Hoyland
      organizationCentennial Software
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameJeff Cheng
      organizationOpsware, Inc.
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionInternet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.
    familywindows
    idoval:org.mitre.oval:def:3872
    statusaccepted
    submitted2004-10-26T12:00:00.000-04:00
    titleIE v6.0,SP1 (Server 2003) SSL Cached Content Vulnerability
    version70
  • accepted2014-02-24T04:03:21.476-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameJohn Hoyland
      organizationCentennial Software
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameJeff Cheng
      organizationOpsware, Inc.
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionInternet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.
    familywindows
    idoval:org.mitre.oval:def:5150
    statusaccepted
    submitted2005-01-18T12:00:00.000-04:00
    titleIE v5.01, SP4 SSL Cached Content Vulnerability
    version69
  • accepted2014-02-24T04:03:23.268-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameJohn Hoyland
      organizationCentennial Software
    • nameJeff Cheng
      organizationOpsware, Inc.
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionInternet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.
    familywindows
    idoval:org.mitre.oval:def:5520
    statusaccepted
    submitted2005-01-18T12:00:00.000-04:00
    titleIE v5.5, SP2 SSL Cached Content Vulnerability
    version69
  • accepted2014-02-24T04:03:23.836-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameJohn Hoyland
      organizationCentennial Software
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameJeff Cheng
      organizationOpsware, Inc.
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionInternet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.
    familywindows
    idoval:org.mitre.oval:def:5740
    statusaccepted
    submitted2004-10-26T02:20:00.000-04:00
    titleIE v6.0,SP1 SSL Cached Content Vulnerability
    version70
  • accepted2014-02-24T04:03:26.721-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameJohn Hoyland
      organizationCentennial Software
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameJeff Cheng
      organizationOpsware, Inc.
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionInternet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.
    familywindows
    idoval:org.mitre.oval:def:7611
    statusaccepted
    submitted2004-10-26T02:09:00.000-04:00
    titleIE v5.01,SP3 SSL Cached Content Vulnerability
    version69