5

CVE-2010-1127

Exploit
Microsoft Internet Explorer 6 and 7 does not initialize certain data structures during execution of the createElement method, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted JavaScript code, as demonstrated by setting the (1) outerHTML or (2) value property of an object returned by createElement.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Internet Explorer Version 6.0
Microsoft ≫ Internet Explorer Version 6.00.2462.0000
Microsoft ≫ Internet Explorer Version 6.00.2479.0006
Microsoft ≫ Internet Explorer Version 6.0.2600
Microsoft ≫ Internet Explorer Version 6.00.2600.0000
Microsoft ≫ Internet Explorer Version 6.0.2800
Microsoft ≫ Internet Explorer Version 6.0.2800.1106
Microsoft ≫ Internet Explorer Version 6.00.2800.1106
Microsoft ≫ Internet Explorer Version 6.0.2900
Microsoft ≫ Internet Explorer Version 6.0.2900.2180
Microsoft ≫ Internet Explorer Version 6.00.2900.2180
Microsoft ≫ Internet Explorer Version 6.00.3663.0000
Microsoft ≫ Internet Explorer Version 6.00.3718.0000
Microsoft ≫ Internet Explorer Version 6.00.3790.0000
Microsoft ≫ Internet Explorer Version 6.00.3790.1830
Microsoft ≫ Internet Explorer Version 6.00.3790.3959
Microsoft ≫ Internet Explorer Version 7.0
Microsoft ≫ Internet Explorer Version 7.0 Update beta
Microsoft ≫ Internet Explorer Version 7.0 Update beta1
Microsoft ≫ Internet Explorer Version 7.0 Update beta2
Microsoft ≫ Internet Explorer Version 7.0 Update beta3
Microsoft ≫ Internet Explorer Version 7.0.5730 Update unknown Edition gold
Microsoft ≫ Internet Explorer Version 7.0.5730.11
Microsoft ≫ Internet Explorer Version 7.00.5730.1100
Microsoft ≫ Internet Explorer Version 7.00.6000.16386
Microsoft ≫ Internet Explorer Version 7.00.6000.16441
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 18.27% 0.969
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://archives.neohapsis.com/archives/bugtraq/2010-01/0237.html
Exploit
http://archives.neohapsis.com/archives/bugtraq/2010-01/0278.html
http://securityreason.com/exploitalert/7731
Exploit