Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2013-1450

EPSS 16.55% · P95
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2013-1450

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Microsoft Internet Explorer 8 and 9, when the Proxy Settings configuration has the same Proxy address and Port values in the HTTP and Secure rows, does not properly reuse TCP sessions to the proxy server, which allows remote attackers to obtain sensitive information intended for a specific host via a crafted HTML document that triggers many HTTPS requests and then triggers an HTTP request to that host, as demonstrated by reading a Cookie header, aka MSRC 12096gd.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Microsoft Internet Explorer 配置错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Microsoft Internet Explorer是美国微软(Microsoft)公司发布的Windows操作系统中默认捆绑的Web浏览器。 Microsoft Internet Explorer 8和9版本中存在漏洞,该漏洞源于在代理配置的HTTP和安全行中具有同样的代理地址和端口值的情况下,程序没有正确地对代理服务器重用TCP会话。通过特制的HTML文档触发向任意主机发送多个HTTPS请求,随后再向某可信主机发送一个HTTPS请求且向某不可信主机发送一个HTTP请求(如读取Cookie头文件),远
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2013-1450

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2013-1450

登录查看更多情报信息。

Same Patch Batch · n/a · 2013-01-29 · 18 CVEs total

CVE-2013-0955Apple iOS WebKit 拒绝服务漏洞
CVE-2013-0974Apple iOS StoreKit 安全绕过漏洞
CVE-2013-0968Apple iOS WebKit 任意代码执行漏洞
CVE-2013-0964Apple iOS/Apple TV 内核安全漏洞
CVE-2013-0963Apple iOS Identity Services 认证绕过漏洞
CVE-2013-0962Apple iOS WebKit 跨站脚本漏洞
CVE-2013-0959Apple iOS WebKit 内存破坏漏洞
CVE-2013-0958Apple iOS WebKit 内存破坏漏洞
CVE-2013-0956Apple iOS WebKit 内存破坏漏洞
CVE-2013-1451Microsoft Internet Explorer 配置错误漏洞
CVE-2013-0954Apple iOS 内存破坏漏洞
CVE-2013-0953Apple iOS 内存破坏漏洞
CVE-2013-0952Apple iOS WebKit 任意代码执行漏洞
CVE-2013-0951Apple iOS WebKit 内存破坏漏洞
CVE-2013-0950Apple iOS WebKit 内存破坏漏洞
CVE-2013-0949Apple iOS WebKit 内存破坏漏洞
CVE-2013-0948Apple iOS WebKit 内存破坏漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2013-1450

No comments yet


Leave a comment