CVE-2010-1127
Status: ModifiedMedium (5)—
Microsoft Internet Explorer 6 and 7 does not initialize certain data structures during execution of the createElement method, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted JavaScript code, as demonstrated by setting the (1) outerHTML or (2) value property of an object returned by createElement.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P
- Base score: 5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 19%
- Percentile among all scored CVEs: 97
- Score date: 10/9/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- NVD-CWE-Other
References
- http://archives.neohapsis.com/archives/bugtraq/2010-01/0237.html
- http://archives.neohapsis.com/archives/bugtraq/2010-01/0278.html
- http://securityreason.com/exploitalert/7731
- http://archives.neohapsis.com/archives/bugtraq/2010-01/0237.html
- http://archives.neohapsis.com/archives/bugtraq/2010-01/0278.html
- http://securityreason.com/exploitalert/7731
Raw JSON (NVD)
Show
{
"id": "CVE-2010-1127",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2010-03-26T20:30:00.843",
"references": [
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2010-01/0237.html",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2010-01/0278.html",
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/exploitalert/7731",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2010-01/0237.html",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2010-01/0278.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityreason.com/exploitalert/7731",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Microsoft Internet Explorer 6 and 7 does not initialize certain data structures during execution of the createElement method, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted JavaScript code, as demonstrated by setting the (1) outerHTML or (2) value property of an object returned by createElement."
},
{
"lang": "es",
"value": "Microsoft Internet Explorer 6 y 7 no inicializan ciertas estructuras durante la ejecución del método createElement, lo que permite a atacantes remotos provocar una denegación de servicio (desreferenciación de puntero nulo y caída de aplicación) a través de código JavaScript, como se demostró fijando el valor de (1) outerHTML o (2) propiedad valor de un objeto devuelto por createElement."
}
],
"lastModified": "2026-06-16T23:17:33.960",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A19F6133-25D1-44A5-B6B9-354703436783"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:6.00.2462.0000:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "314538E8-48EC-4869-9074-2A1F5B7CBB3C"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:6.00.2479.0006:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F56B3A72-7C5E-4F0C-BBC7-AA13DDFBEE70"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:6.0.2600:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "68656E52-AD8A-474E-9160-CD5F8857254B"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:6.00.2600.0000:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6876CE89-AA70-44C5-8A69-E2ED7A63F570"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:6.0.2800:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "93F47C82-E767-47A8-88DE-417B004ED7FC"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:6.0.2800.1106:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F86E7189-CE21-4007-A3FA-39A6B51A5AB9"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:6.00.2800.1106:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BCE2555F-C4BE-482F-8DD9-976D2026058C"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:6.0.2900:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7B90EA4B-DA10-44B7-BD3D-6AE1197212D5"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:6.0.2900.2180:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7CBF9B51-5AF4-4317-9768-21D866AC7990"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:6.00.2900.2180:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "61F352FE-C22E-4B33-A46F-77A164B5DABB"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:6.00.3663.0000:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5ACD5A44-0926-4A1B-9900-1E7CC0A561C8"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:6.00.3718.0000:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "196CEE37-2E3A-41A7-9AC1-0D5CC3F35D8F"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:6.00.3790.0000:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3E16BEF4-71AA-4E23-B438-D25FFABDB646"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:6.00.3790.1830:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1F32702E-F955-4DDB-B235-7C47E882453C"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:6.00.3790.3959:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6FA2B4AD-C04D-4A6B-8570-5A2F5489F750"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:7.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6BC71FD8-D385-4507-BD14-B75FDD4C79E6"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:7.0:beta:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "506711D9-6E57-4EED-8628-36C7F2324040"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:7.0:beta1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ED471260-0272-431F-A91E-AC2883D92497"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:7.0:beta2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "63D18070-EC48-4904-9AE0-558F7F3B869D"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:7.0:beta3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "86584E3F-3B0D-4018-A186-E59F3B01CA5C"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:7.0.5730:unknown:gold:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "817636ED-5E42-460E-89F1-24D5C64AB8BE"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:7.0.5730.11:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0E6E1020-1017-4670-9316-27C79F1E2698"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:7.00.5730.1100:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "37F63AE1-8FC9-4C0F-8D19-F17DFA214E94"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:7.00.6000.16386:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "35B1186A-FA5B-4E49-8C2F-BCD2D45F22A2"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:7.00.6000.16441:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "53D75496-8594-44DB-B5C4-EA3CABD6551A"
}
],
"operator": "OR"
}
]
}
],
"evaluatorComment": "Per: http://cwe.mitre.org/data/definitions/476.html\r\n\r\nCWE-476: NULL Pointer Dereference",
"sourceIdentifier": "cve@mitre.org"
}