9.3
CVSSv2

CVE-2009-1547

Published: 14/10/2009 Updated: 07/12/2023
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 940
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote malicious users to execute arbitrary code via a crafted data stream header that triggers memory corruption, aka "Data Stream Header Corruption Vulnerability."

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft internet_explorer 5.01

microsoft internet_explorer 6

microsoft windows_2000

microsoft windows_server_2003

microsoft windows_xp

microsoft windows_xp -

microsoft internet_explorer 7

microsoft windows_server_2008

microsoft windows_server_2008 -

microsoft windows_vista

microsoft windows_vista -

microsoft internet_explorer 8

microsoft windows_7 -

Exploits

Microsoft Internet Explorer suffers from a Content-Encoding: deflate memory corruption vulnerability ...
MSIE Content-Encoding: deflate memory corruption vulnerability (aka MSRC 8769, MS09-054, CVE-2009-1547, “Data Stream Header Corruption Vulnerability”) Microsoft fixed a bug in Internet Explorer’s “Content-Encoding:deflate” implementation Here are two HTTP replies that trigger the bug: HTTP/\nContent-Encoding:deflate\r\t\n\r\n\x20\ ...
source: wwwsecurityfocuscom/bid/36622/info Microsoft Internet Explorer is prone to a remote code-execution vulnerability Attackers can exploit this issue to execute arbitrary code in the context of the user running the application Successful exploits will compromise the application and possibly the computer Failed attacks may cause de ...