Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "<STYLE>@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability."
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2004-12-22 21:00
Updated : 2021-07-23 05:55
NVD link : CVE-2004-0842
Mitre link : CVE-2004-0842
JSON object : View
CWE
Products Affected
avaya
- s8100
- ip600_media_servers
- definity_one_media_server
- s3400
- modular_messaging_message_storage_server
microsoft
- internet_explorer
- ie