Description
Microsoft Internet Explorer 6 and 7 does not initialize certain data structures during execution of the createElement method, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted JavaScript code, as demonstrated by setting the (1) outerHTML or (2) value property of an object returned by createElement.
References (3)
Core 3
Core References
Exploit mailing-list
x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2010-01/0237.html
Exploit x_refsource_misc
http://securityreason.com/exploitalert/7731
Third Party Advisory mailing-list
x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2010-01/0278.html
Scores
EPSS
0.1827
EPSS Percentile
96.9%
Details
Status
published
Products (22)
microsoft/internet_explorer
6.0
microsoft/internet_explorer
6.00.2462.0000
microsoft/internet_explorer
6.00.2479.0006
microsoft/internet_explorer
6.0.2600
microsoft/internet_explorer
6.00.2600.0000
microsoft/internet_explorer
6.0.2800
microsoft/internet_explorer
6.0.2800.1106
microsoft/internet_explorer
6.00.2800.1106
microsoft/internet_explorer
6.0.2900
microsoft/internet_explorer
6.0.2900.2180
... and 12 more
Published
Mar 26, 2010
Tracked Since
Feb 18, 2026