Denial of Service Vulnerability in Internet Explorer by Microsoft
CVE-2004-0842

Currently unrated

Key Information:

Vendor
Avaya
Vendor
CVE Published:
23 December 2004

Summary

This vulnerability in Internet Explorer 6.0 SP1 and earlier versions allows remote attackers to exploit malformed CSS elements, leading to a denial of service through application crashes. The issue manifests from a heap-based buffer overflow, potentially triggered by an invalid length resulting from a missing comment terminator. Consequently, certain CSS strings can prompt extensive memory operations, severely impacting system stability.

References

EPSS Score

74% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.