Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "<STYLE>@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability."
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2004-12-23 05:00
Updated : 2025-04-03 01:03
NVD link : CVE-2004-0842
Mitre link : CVE-2004-0842
CVE.ORG link : CVE-2004-0842
JSON object : View
Products Affected
avaya
- s3400
- ip600_media_servers
- modular_messaging_message_storage_server
- definity_one_media_server
- s8100
microsoft
- ie
- internet_explorer
CWE