VDB
CVE-2004-0845
CVE-2004-0845
PUBLISHED
CVSS 6.400000095367432 MEDIUM
Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.
EPSS 38.96% · 97.4th percentile
Risk Scores
CVSS 2.0
6.400000095367432
EPSS Score
38.96%
97.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| microsoft | internet_explorer | 5.01, 5.5 |
| microsoft | ie | 6 |
| n/a | n/a | n/a |
Timeline
- Oct 16, 2004 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- oval:org.mitre.oval:def:2219 vdb
- oval:org.mitre.oval:def:5150 vdb
- ie-cache-ssl-obtain-information(17654) vdb
- oval:org.mitre.oval:def:5740 vdb
- MS04-038 vendor-advisory
- oval:org.mitre.oval:def:5520 vdb
- oval:org.mitre.oval:def:3872 vdb
- 20041013 ACROS Security: Poisoning Cached HTTPS Documents in Internet Explorer mailing-list
- TA04-293A third-party-advisory
- ie-ms04038-patch(17651) vdb
- VU#795720 third-party-advisory
- http://www.acrossecurity.com/aspr/ASPR-2004-10-13-1-PUB.txt url
- oval:org.mitre.oval:def:7611 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2004-0845 advisory