« Back to list

CVE-2010-1127

Status: ModifiedMedium (5)—

Microsoft Internet Explorer 6 and 7 does not initialize certain data structures during execution of the createElement method, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted JavaScript code, as demonstrated by setting the (1) outerHTML or (2) value property of an object returned by createElement.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2010-1127",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2010-03-26T20:30:00.843",
  "references": [
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2010-01/0237.html",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2010-01/0278.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securityreason.com/exploitalert/7731",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2010-01/0237.html",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2010-01/0278.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securityreason.com/exploitalert/7731",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Microsoft Internet Explorer 6 and 7 does not initialize certain data structures during execution of the createElement method, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted JavaScript code, as demonstrated by setting the (1) outerHTML or (2) value property of an object returned by createElement."
    },
    {
      "lang": "es",
      "value": "Microsoft Internet Explorer 6 y 7 no inicializan ciertas estructuras durante la ejecución del método createElement, lo que permite a atacantes remotos provocar una denegación de servicio (desreferenciación de puntero nulo y caída de aplicación) a través de código JavaScript, como se demostró fijando el valor de (1) outerHTML o (2) propiedad valor de un objeto devuelto por createElement."
    }
  ],
  "lastModified": "2026-06-16T23:17:33.960",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A19F6133-25D1-44A5-B6B9-354703436783"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:internet_explorer:6.00.2462.0000:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "314538E8-48EC-4869-9074-2A1F5B7CBB3C"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:internet_explorer:6.00.2479.0006:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F56B3A72-7C5E-4F0C-BBC7-AA13DDFBEE70"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:internet_explorer:6.0.2600:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "68656E52-AD8A-474E-9160-CD5F8857254B"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:internet_explorer:6.00.2600.0000:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6876CE89-AA70-44C5-8A69-E2ED7A63F570"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:internet_explorer:6.0.2800:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "93F47C82-E767-47A8-88DE-417B004ED7FC"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:internet_explorer:6.0.2800.1106:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F86E7189-CE21-4007-A3FA-39A6B51A5AB9"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:internet_explorer:6.00.2800.1106:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BCE2555F-C4BE-482F-8DD9-976D2026058C"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:internet_explorer:6.0.2900:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7B90EA4B-DA10-44B7-BD3D-6AE1197212D5"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:internet_explorer:6.0.2900.2180:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7CBF9B51-5AF4-4317-9768-21D866AC7990"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:internet_explorer:6.00.2900.2180:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "61F352FE-C22E-4B33-A46F-77A164B5DABB"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:internet_explorer:6.00.3663.0000:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5ACD5A44-0926-4A1B-9900-1E7CC0A561C8"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:internet_explorer:6.00.3718.0000:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "196CEE37-2E3A-41A7-9AC1-0D5CC3F35D8F"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:internet_explorer:6.00.3790.0000:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3E16BEF4-71AA-4E23-B438-D25FFABDB646"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:internet_explorer:6.00.3790.1830:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1F32702E-F955-4DDB-B235-7C47E882453C"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:internet_explorer:6.00.3790.3959:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6FA2B4AD-C04D-4A6B-8570-5A2F5489F750"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:internet_explorer:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6BC71FD8-D385-4507-BD14-B75FDD4C79E6"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:internet_explorer:7.0:beta:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "506711D9-6E57-4EED-8628-36C7F2324040"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:internet_explorer:7.0:beta1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ED471260-0272-431F-A91E-AC2883D92497"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:internet_explorer:7.0:beta2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "63D18070-EC48-4904-9AE0-558F7F3B869D"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:internet_explorer:7.0:beta3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "86584E3F-3B0D-4018-A186-E59F3B01CA5C"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:internet_explorer:7.0.5730:unknown:gold:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "817636ED-5E42-460E-89F1-24D5C64AB8BE"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:internet_explorer:7.0.5730.11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0E6E1020-1017-4670-9316-27C79F1E2698"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:internet_explorer:7.00.5730.1100:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "37F63AE1-8FC9-4C0F-8D19-F17DFA214E94"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:internet_explorer:7.00.6000.16386:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "35B1186A-FA5B-4E49-8C2F-BCD2D45F22A2"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:internet_explorer:7.00.6000.16441:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "53D75496-8594-44DB-B5C4-EA3CABD6551A"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "evaluatorComment": "Per:  http://cwe.mitre.org/data/definitions/476.html\r\n\r\nCWE-476: NULL Pointer Dereference",
  "sourceIdentifier": "cve@mitre.org"
}