CVE Database
/

CVE-2004-0842

Back to search

CVE-2004-0842

Published: Sep 14, 2004

Modified: Aug 8, 2024

PUBLISHED

Description

Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "<STYLE>@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability."

VendorProductVersions

n/a

n/a

affected
n/a

References

20040728 Re: Crash IE with 11 bytes ;)
mailing-list
x_refsource_FULLDISC
oval:org.mitre.oval:def:4169
vdb-entry
signature
x_refsource_OVAL
MS04-038
vendor-advisory
x_refsource_MS
VU#291304
third-party-advisory
x_refsource_CERT-VN
oval:org.mitre.oval:def:2906
vdb-entry
signature
x_refsource_OVAL
20040723 Crash IE with 11 bytes ;)
mailing-list
x_refsource_FULLDISC
oval:org.mitre.oval:def:5592
vdb-entry
signature
x_refsource_OVAL
TA04-293A
third-party-advisory
x_refsource_CERT
20040728 Re: Crash IE with 11 bytes ;)
mailing-list
x_refsource_BUGTRAQ
12806
third-party-advisory
x_refsource_SECUNIA
P-006
third-party-advisory
government-resource
x_refsource_CIAC
10816
vdb-entry
x_refsource_BID
oval:org.mitre.oval:def:6579
vdb-entry
signature
x_refsource_OVAL
oval:org.mitre.oval:def:3372
vdb-entry
signature
x_refsource_OVAL

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now