HIGH · 7.5

CVE-2004-0842

Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading St...

Vulnerability Description

Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "<STYLE>@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability."

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
AvayaIp600 Media ServersAll versions
MicrosoftIe6.0
MicrosoftInternet Explorer5.0.1
AvayaDefinity One Media ServerAll versions
AvayaS3400All versions
AvayaS8100All versions
AvayaModular Messaging Message Storage Server1.1

References

FAQ

What is CVE-2004-0842?

CVE-2004-0842 is a vulnerability with a CVSS score of 7.5 (HIGH). Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading St...

How severe is CVE-2004-0842?

CVE-2004-0842 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-0842?

Check the references section above for vendor advisories and patch information. Affected products include: Avaya Ip600 Media Servers, Microsoft Ie, Microsoft Internet Explorer, Avaya Definity One Media Server, Avaya S3400.