CVE-2011-4689
Microsoft Internet Explorer 6-9 - Cache Timing Side-Channel via IFRAME Same Origin Policy Violation
Title source: llmDescription
Microsoft Internet Explorer 6 through 9 does not prevent capture of data about the times of Same Origin Policy violations during IFRAME loading attempts, which makes it easier for remote attackers to determine whether a document exists in the browser cache via crafted JavaScript code.
References (2)
Core 2
Core References
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/47129
Exploit x_refsource_misc
http://lcamtuf.coredump.cx/cachetime/
Scores
EPSS
0.0940
EPSS Percentile
94.9%
Details
CWE
CWE-264
Status
published
Products (4)
microsoft/internet_explorer
6
microsoft/internet_explorer
7
microsoft/internet_explorer
8
microsoft/internet_explorer
9
Published
Dec 07, 2011
Tracked Since
Feb 18, 2026