CVE-2009-1140
HIGH 7.1EPSS 24.8%
Microsoft Internet Explorer 5.01 SP4; 6 SP1; 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 does not prevent HTML rendering of cached content, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Cross-Domain Information Disclosure Vulnerability."
- CVSS v2.0
- 7.1 HIGH
AV:N/AC:M/Au:N/C:C/I:N/A:N - EPSS
- 24.76% chance of exploitation in the next 30 days, 98th percentile
- Published
- 2009-06-10
- Updated
- 2024-08-07