CVE-2010-1127

medium
Published 2010-03-26 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
5.0

Description

Microsoft Internet Explorer 6 and 7 does not initialize certain data structures during execution of the createElement method, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted JavaScript code, as demonstrated by setting the (1) outerHTML or (2) value property of an object returned by createElement.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Application impact

VendorProductVersionsFixed
windows microsoftinternet_explorer6.0
windows microsoftinternet_explorer6.00.2462.0000
windows microsoftinternet_explorer6.00.2479.0006
windows microsoftinternet_explorer6.0.2600
windows microsoftinternet_explorer6.00.2600.0000
windows microsoftinternet_explorer6.0.2800
windows microsoftinternet_explorer6.0.2800.1106
windows microsoftinternet_explorer6.00.2800.1106
windows microsoftinternet_explorer6.0.2900
windows microsoftinternet_explorer6.0.2900.2180
windows microsoftinternet_explorer6.00.2900.2180
windows microsoftinternet_explorer6.00.3663.0000
windows microsoftinternet_explorer6.00.3718.0000
windows microsoftinternet_explorer6.00.3790.0000
windows microsoftinternet_explorer6.00.3790.1830
windows microsoftinternet_explorer6.00.3790.3959
windows microsoftinternet_explorer7.0
windows microsoftinternet_explorer7.0.5730
windows microsoftinternet_explorer7.0.5730.11
windows microsoftinternet_explorer7.00.5730.1100
windows microsoftinternet_explorer7.00.6000.16386
windows microsoftinternet_explorer7.00.6000.16441

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.