Denial of Service Vulnerability in Internet Explorer by Microsoft
CVE-2004-0842
Currently unrated
Key Information:
- Vendor
Avaya
- Vendor
- CVE Published:
- 23 December 2004
Badges
๐พ Exploit Exists๐ก Public PoC๐ฃ EPSS 56%
What is CVE-2004-0842?
This vulnerability in Internet Explorer 6.0 SP1 and earlier versions allows remote attackers to exploit malformed CSS elements, leading to a denial of service through application crashes. The issue manifests from a heap-based buffer overflow, potentially triggered by an invalid length resulting from a missing comment terminator. Consequently, certain CSS strings can prompt extensive memory operations, severely impacting system stability.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.