Back

CVE-2004-0842

Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "<STYLE>@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability."

Published: Dec 23, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (16)

Vendor Product Version
avaya ip600_media_servers *
microsoft ie 6.0
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.0.1
microsoft internet_explorer 5.5
microsoft internet_explorer 5.5
microsoft internet_explorer 5.5
microsoft internet_explorer 6.0
avaya definity_one_media_server *
avaya s3400 *
avaya s8100 *
avaya modular_messaging_message_storage_server 1.1
avaya modular_messaging_message_storage_server 2.0

GitHub Security Advisory GHSA-g4xq-83hp-jc9q

Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 56.61%

Top 1% most likely to be exploited

Threat Score 47 / 100

Data Sources

NVD EPSS GitHub