← All CVEs

CVE-2010-1127

medium · 5

Microsoft Internet Explorer 6 and 7 does not initialize certain data structures during execution of the createElement method, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted JavaScript code, as demonstrated by setting the (1) outerHTML or (2) value property of an object returned by createElement.

5
CVSS
18.3%
EPSS (exploit prob.)
97th
EPSS percentile
2010-03-26
Published

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

VendorProductAffected versions
microsoftinternet_explorer6.0
microsoftinternet_explorer6.00.2462.0000
microsoftinternet_explorer6.00.2479.0006
microsoftinternet_explorer6.0.2600
microsoftinternet_explorer6.00.2600.0000
microsoftinternet_explorer6.0.2800
microsoftinternet_explorer6.0.2800.1106
microsoftinternet_explorer6.00.2800.1106
microsoftinternet_explorer6.0.2900
microsoftinternet_explorer6.0.2900.2180
microsoftinternet_explorer6.00.2900.2180
microsoftinternet_explorer6.00.3663.0000
microsoftinternet_explorer6.00.3718.0000
microsoftinternet_explorer6.00.3790.0000
microsoftinternet_explorer6.00.3790.1830
microsoftinternet_explorer6.00.3790.3959
microsoftinternet_explorer7.0
microsoftinternet_explorer7.0
microsoftinternet_explorer7.0
microsoftinternet_explorer7.0
microsoftinternet_explorer7.0
microsoftinternet_explorer7.0.5730
microsoftinternet_explorer7.0.5730.11
microsoftinternet_explorer7.00.5730.1100
microsoftinternet_explorer7.00.6000.16386
microsoftinternet_explorer7.00.6000.16441

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2010-1127