CVE-2010-1127
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/03/2010
Last modified:
11/04/2025
Description
Microsoft Internet Explorer 6 and 7 does not initialize certain data structures during execution of the createElement method, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted JavaScript code, as demonstrated by setting the (1) outerHTML or (2) value property of an object returned by createElement.
Impact
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:microsoft:internet_explorer:6.00.2462.0000:*:*:*:*:*:*:* | ||
| cpe:2.3:a:microsoft:internet_explorer:6.00.2479.0006:*:*:*:*:*:*:* | ||
| cpe:2.3:a:microsoft:internet_explorer:6.0.2600:*:*:*:*:*:*:* | ||
| cpe:2.3:a:microsoft:internet_explorer:6.00.2600.0000:*:*:*:*:*:*:* | ||
| cpe:2.3:a:microsoft:internet_explorer:6.0.2800:*:*:*:*:*:*:* | ||
| cpe:2.3:a:microsoft:internet_explorer:6.0.2800.1106:*:*:*:*:*:*:* | ||
| cpe:2.3:a:microsoft:internet_explorer:6.00.2800.1106:*:*:*:*:*:*:* | ||
| cpe:2.3:a:microsoft:internet_explorer:6.0.2900:*:*:*:*:*:*:* | ||
| cpe:2.3:a:microsoft:internet_explorer:6.0.2900.2180:*:*:*:*:*:*:* | ||
| cpe:2.3:a:microsoft:internet_explorer:6.00.2900.2180:*:*:*:*:*:*:* | ||
| cpe:2.3:a:microsoft:internet_explorer:6.00.3663.0000:*:*:*:*:*:*:* | ||
| cpe:2.3:a:microsoft:internet_explorer:6.00.3718.0000:*:*:*:*:*:*:* | ||
| cpe:2.3:a:microsoft:internet_explorer:6.00.3790.0000:*:*:*:*:*:*:* | ||
| cpe:2.3:a:microsoft:internet_explorer:6.00.3790.1830:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://archives.neohapsis.com/archives/bugtraq/2010-01/0237.html
- http://archives.neohapsis.com/archives/bugtraq/2010-01/0278.html
- http://securityreason.com/exploitalert/7731
- http://archives.neohapsis.com/archives/bugtraq/2010-01/0237.html
- http://archives.neohapsis.com/archives/bugtraq/2010-01/0278.html
- http://securityreason.com/exploitalert/7731



