2.1
CWE
200
Advisory Published
Updated

CVE-2008-2159: Infoleak

First published: Mon May 12 2008(Updated: )

Microsoft Internet Explorer 7 can save encrypted pages in the cache even when the DisableCachingOfSSLPages registry setting is enabled, which might allow local users to obtain sensitive information.

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
Internet Explorer=7

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2008-2159?

    CVE-2008-2159 has been assigned a moderate severity rating due to the potential exposure of sensitive information.

  • How can I fix CVE-2008-2159?

    To mitigate CVE-2008-2159, users should upgrade to a more recent version of Internet Explorer or apply any available security patches.

  • Who is affected by CVE-2008-2159?

    CVE-2008-2159 affects users of Microsoft Internet Explorer 7, particularly those who rely on the DisableCachingOfSSLPages registry setting.

  • What type of attack does CVE-2008-2159 facilitate?

    CVE-2008-2159 facilitates local information disclosure attacks by allowing unauthorized users to access sensitive data cached from encrypted pages.

  • Is CVE-2008-2159 still a relevant vulnerability?

    While CVE-2008-2159 is an older vulnerability, it remains relevant for systems that still run Internet Explorer 7.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203