5
CVSSv2

CVE-2010-1127

Published: 26/03/2010 Updated: 23/07/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Microsoft Internet Explorer 6 and 7 does not initialize certain data structures during execution of the createElement method, which allows remote malicious users to cause a denial of service (NULL pointer dereference and application crash) via crafted JavaScript code, as demonstrated by setting the (1) outerHTML or (2) value property of an object returned by createElement.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft internet explorer 6.0.2800

microsoft internet explorer 6.0.2800.1106

microsoft internet explorer 6.0.2900

microsoft internet explorer 6.0.2900.2180

microsoft internet explorer 7.0

microsoft internet explorer 6.0.2600

microsoft internet explorer 6.00.2462.0000

microsoft internet explorer 6.00.2600.0000

microsoft internet explorer 6.00.3790.3959

microsoft internet explorer 7.0.5730.11

microsoft internet explorer 7.00.6000.16386

microsoft internet explorer 6.00.2900.2180

microsoft internet explorer 6.00.3663.0000

microsoft internet explorer 6.00.3718.0000

microsoft internet explorer 6.00.3790.0000

microsoft internet explorer 6.00.3790.1830

microsoft internet explorer 6.0

microsoft internet explorer 6.00.2479.0006

microsoft internet explorer 6.00.2800.1106

microsoft internet explorer 7.0.5730

microsoft internet explorer 7.00.5730.1100

microsoft internet explorer 7.00.6000.16441