CVE-2004-0842: Buffer Overflow
Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "<STYLE>@;/" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0842?
CVE-2004-0842 is classified as a high severity vulnerability due to its potential to cause application crashes and denial of service.
How do I fix CVE-2004-0842?
To fix CVE-2004-0842, users should upgrade their Internet Explorer to the latest version available and apply any relevant security updates.
Which software versions are affected by CVE-2004-0842?
CVE-2004-0842 affects Internet Explorer 5.0.1 and 6.0 SP1 as well as several Avaya products, including IP600 Media Servers.
What type of attack does CVE-2004-0842 exploit?
CVE-2004-0842 exploits a vulnerability in how Internet Explorer processes certain malformed CSS elements, triggering memory corruption.
Can I still use Internet Explorer if CVE-2004-0842 is present?
Using an affected version of Internet Explorer poses significant risk, and it is highly recommended to update or switch to a more secure browser.