Vulnerabilities > CVE-2004-0842

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
microsoft
avaya
exploit available

Summary

Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "<STYLE>@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability."

Exploit-Db

descriptionMicrosoft Internet Explorer 5.0.1 Style Tag Comment Memory Corruption Vulnerability. CVE-2004-0842. Remote exploit for windows platform
idEDB-ID:24328
last seen2016-02-02
modified2004-07-08
published2004-07-08
reporterPhuong Nguyen
sourcehttps://www.exploit-db.com/download/24328/
titleMicrosoft Internet Explorer 5.0.1 Style Tag Comment Memory Corruption Vulnerability

Oval

  • accepted2014-02-24T04:03:13.890-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameMaria Mikhno
      organizationALTX-SOFT
    description@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability."
    familywindows
    idoval:org.mitre.oval:def:2906
    statusaccepted
    submitted2004-10-19T04:45:00.000-04:00
    titleWindows 2000, IE v5.01 CSS Heap Memory Corruption Vulnerability
    version67
  • accepted2014-02-24T04:03:15.326-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameMaria Mikhno
      organizationALTX-SOFT
    description@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability."
    familywindows
    idoval:org.mitre.oval:def:3372
    statusaccepted
    submitted2004-10-19T12:00:00.000-04:00
    titleWindows Server 2003, IE v6,SP1 CSS Heap Memory Corruption Vulnerability
    version68
  • accepted2014-02-24T04:03:18.156-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameJohn Hoyland
      organizationCentennial Software
    • nameMaria Mikhno
      organizationALTX-SOFT
    description@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability."
    familywindows
    idoval:org.mitre.oval:def:4169
    statusaccepted
    submitted2004-10-19T04:00:00.000-04:00
    titleWindows XP, IE v6.0 CSS Heap Memory Corruption Vulnerability
    version68
  • accepted2014-02-24T04:03:23.456-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameMaria Mikhno
      organizationALTX-SOFT
    description@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability."
    familywindows
    idoval:org.mitre.oval:def:5592
    statusaccepted
    submitted2004-10-19T04:49:00.000-04:00
    titleWindows (ME, NT, 2K), IE v5.5,SP2 CSS Heap Memory Corruption Vulnerability
    version67
  • accepted2014-02-24T04:03:25.262-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameMaria Mikhno
      organizationALTX-SOFT
    description@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability."
    familywindows
    idoval:org.mitre.oval:def:6579
    statusaccepted
    submitted2004-10-19T04:56:00.000-04:00
    titleWindows (ME, NT, 2K, XP), IE v6,SP1 CSS Heap Memory Corruption Vulnerability
    version68