{"api_version":"1","generated_at":"2026-07-23T12:22:30+00:00","cve":"CVE-2009-4074","urls":{"html":"https://cve.report/CVE-2009-4074","api":"https://cve.report/api/cve/CVE-2009-4074.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-4074","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-4074"},"summary":{"title":"CVE-2009-4074","description":"The XSS Filter in Microsoft Internet Explorer 8 allows remote attackers to leverage the \"response-changing mechanism\" to conduct cross-site scripting (XSS) attacks against web sites that have no inherent XSS vulnerabilities, related to the details of output encoding and improper modification of an HTML attribute, aka \"XSS Filter Script Handling Vulnerability.\"","state":"PUBLISHED","assigner":"mitre","published_at":"2009-11-25 18:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7715","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7715","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/","name":"http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"hackademix.net » IE's XSS Filter Creates XSS Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.owasp.org/images/5/50/OWASP-Italy_Day_IV_Maone.pdf","name":"http://www.owasp.org/images/5/50/OWASP-Italy_Day_IV_Maone.pdf","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"application/pdf","httpstatus":"200","archivestatus":"200"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-002","name":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-002","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Security Bulletin MS10-002 - Critical | Microsoft Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/37135","name":"http://www.securityfocus.com/bid/37135","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Internet Explorer 8 Cross-Site Scripting Filter Cross-Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.theregister.co.uk/2009/11/20/internet_explorer_security_flaw/","name":"http://www.theregister.co.uk/2009/11/20/internet_explorer_security_flaw/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Major IE8 flaw makes 'safe' sites unsafe • The Register","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-4074","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-4074","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"4074","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T06:54:08.651Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"oval:org.mitre.oval:def:7715","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7715"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.theregister.co.uk/2009/11/20/internet_explorer_security_flaw/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.owasp.org/images/5/50/OWASP-Italy_Day_IV_Maone.pdf"},{"name":"37135","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/37135"},{"name":"MS10-002","tags":["vendor-advisory","x_refsource_MS","x_transferred"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-002"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-11-20T00:00:00.000Z","descriptions":[{"lang":"en","value":"The XSS Filter in Microsoft Internet Explorer 8 allows remote attackers to leverage the \"response-changing mechanism\" to conduct cross-site scripting (XSS) attacks against web sites that have no inherent XSS vulnerabilities, related to the details of output encoding and improper modification of an HTML attribute, aka \"XSS Filter Script Handling Vulnerability.\""}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-12T19:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"oval:org.mitre.oval:def:7715","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7715"},{"tags":["x_refsource_MISC"],"url":"http://www.theregister.co.uk/2009/11/20/internet_explorer_security_flaw/"},{"tags":["x_refsource_MISC"],"url":"http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/"},{"tags":["x_refsource_MISC"],"url":"http://www.owasp.org/images/5/50/OWASP-Italy_Day_IV_Maone.pdf"},{"name":"37135","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/37135"},{"name":"MS10-002","tags":["vendor-advisory","x_refsource_MS"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-002"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-4074","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The XSS Filter in Microsoft Internet Explorer 8 allows remote attackers to leverage the \"response-changing mechanism\" to conduct cross-site scripting (XSS) attacks against web sites that have no inherent XSS vulnerabilities, related to the details of output encoding and improper modification of an HTML attribute, aka \"XSS Filter Script Handling Vulnerability.\""}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"oval:org.mitre.oval:def:7715","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7715"},{"name":"http://www.theregister.co.uk/2009/11/20/internet_explorer_security_flaw/","refsource":"MISC","url":"http://www.theregister.co.uk/2009/11/20/internet_explorer_security_flaw/"},{"name":"http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/","refsource":"MISC","url":"http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/"},{"name":"http://www.owasp.org/images/5/50/OWASP-Italy_Day_IV_Maone.pdf","refsource":"MISC","url":"http://www.owasp.org/images/5/50/OWASP-Italy_Day_IV_Maone.pdf"},{"name":"37135","refsource":"BID","url":"http://www.securityfocus.com/bid/37135"},{"name":"MS10-002","refsource":"MS","url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-002"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-4074","datePublished":"2009-11-25T18:00:00.000Z","dateReserved":"2009-11-25T00:00:00.000Z","dateUpdated":"2024-08-07T06:54:08.651Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-11-25 18:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:8:*:*:*:*:*:*:*","matchCriteriaId":"A52E757F-9B41-43B4-9D67-3FEDACA71283"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"4074","Ordinal":"1","Title":"CVE-2009-4074","CVE":"CVE-2009-4074","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"4074","Ordinal":"1","NoteData":"The XSS Filter in Microsoft Internet Explorer 8 allows remote attackers to leverage the \"response-changing mechanism\" to conduct cross-site scripting (XSS) attacks against web sites that have no inherent XSS vulnerabilities, related to the details of output encoding and improper modification of an HTML attribute, aka \"XSS Filter Script Handling Vulnerability.\"","Type":"Description","Title":"CVE-2009-4074"},{"CveYear":"2009","CveId":"4074","Ordinal":"2","NoteData":"2009-11-25","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"4074","Ordinal":"3","NoteData":"2018-10-12","Type":"Other","Title":"Modified"}]}}}