CVE-2010-1127
26.03.2010, 20:30
Microsoft Internet Explorer 6 and 7 does not initialize certain data structures during execution of the createElement method, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted JavaScript code, as demonstrated by setting the (1) outerHTML or (2) value property of an object returned by createElement.Enginsight
| Vendor | Product | Version |
|---|---|---|
| microsoft | internet_explorer | 6.0 |
| microsoft | internet_explorer | 6.00.2462.0000 |
| microsoft | internet_explorer | 6.00.2479.0006 |
| microsoft | internet_explorer | 6.0.2600 |
| microsoft | internet_explorer | 6.00.2600.0000 |
| microsoft | internet_explorer | 6.0.2800 |
| microsoft | internet_explorer | 6.0.2800.1106 |
| microsoft | internet_explorer | 6.00.2800.1106 |
| microsoft | internet_explorer | 6.0.2900 |
| microsoft | internet_explorer | 6.0.2900.2180 |
| microsoft | internet_explorer | 6.00.2900.2180 |
| microsoft | internet_explorer | 6.00.3663.0000 |
| microsoft | internet_explorer | 6.00.3718.0000 |
| microsoft | internet_explorer | 6.00.3790.0000 |
| microsoft | internet_explorer | 6.00.3790.1830 |
| microsoft | internet_explorer | 6.00.3790.3959 |
| microsoft | internet_explorer | 7.0 |
| microsoft | internet_explorer | 7.0:beta |
| microsoft | internet_explorer | 7.0:beta1 |
| microsoft | internet_explorer | 7.0:beta2 |
| microsoft | internet_explorer | 7.0:beta3 |
| microsoft | internet_explorer | 7.0.5730:unknown |
| microsoft | internet_explorer | 7.0.5730.11 |
| microsoft | internet_explorer | 7.00.5730.1100 |
| microsoft | internet_explorer | 7.00.6000.16386 |
| microsoft | internet_explorer | 7.00.6000.16441 |
𝑥
= Vulnerable software versions
References