CVE-2010-1127

Microsoft Internet Explorer 6-7 - DoS

Title source: llm
STIX 2.1

Description

Microsoft Internet Explorer 6 and 7 does not initialize certain data structures during execution of the createElement method, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted JavaScript code, as demonstrated by setting the (1) outerHTML or (2) value property of an object returned by createElement.

References (3)

Core 3
Core References
Exploit mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2010-01/0237.html
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2010-01/0278.html

Scores

EPSS 0.1827
EPSS Percentile 96.9%

Details

Status published
Products (22)
microsoft/internet_explorer 6.0
microsoft/internet_explorer 6.00.2462.0000
microsoft/internet_explorer 6.00.2479.0006
microsoft/internet_explorer 6.0.2600
microsoft/internet_explorer 6.00.2600.0000
microsoft/internet_explorer 6.0.2800
microsoft/internet_explorer 6.0.2800.1106
microsoft/internet_explorer 6.00.2800.1106
microsoft/internet_explorer 6.0.2900
microsoft/internet_explorer 6.0.2900.2180
... and 12 more
Published Mar 26, 2010
Tracked Since Feb 18, 2026