Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "<STYLE>@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability."
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2004-12-23 05:00
Updated : 2021-07-23 12:55
NVD link : CVE-2004-0842
Mitre link : CVE-2004-0842
CVE.ORG link : CVE-2004-0842
JSON object : View
Products Affected
microsoft
- ie
- internet_explorer
avaya
- s8100
- modular_messaging_message_storage_server
- ip600_media_servers
- s3400
- definity_one_media_server
CWE