← Vulnerability feed

Vulnerability record · CVE-2004-0842 · published 23 December 2004

CVE-2004-0842: Internet Explorer CSS heap memory corruption denial of service

Avaya · Ip600 Media Servers

Internet Explorer 6.0 SP1 and earlier mishandles malformed Cascading Style Sheet elements, triggering a heap-based buffer overflow that crashes the application. The flaw stems from a missing comment terminator that can cause an invalid length to drive a large memory copy operation. It matters because a remote attacker can crash the browser through crafted CSS content.

7.5 CVSS 2.0 High EPSS 57% · top 1.0%
7.5CVSS 2.0 base score
57%EPSS exploitation probability, 30 days
NoNot in CISA KEV
7Affected product versions listed by NVD
34References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "<STYLE>@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability."

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

medium priorityThe flaw is a remote, unauthenticated crash with public exploit material, but the record documents only denial of service and the affected software is long obsolete.

What it is

Internet Explorer 6.0 SP1 and earlier mishandles malformed Cascading Style Sheet elements, triggering a heap-based buffer overflow that crashes the application. The flaw stems from a missing comment terminator that can cause an invalid length to drive a large memory copy operation. It matters because a remote attacker can crash the browser through crafted CSS content.

Impact

An attacker gains a denial of service: the browser process crashes from memory corruption. The record describes only a crash, not code execution, so no further attacker gain is established.

Attack surface

Reached remotely over the network with no authentication required, per the AV:N/AC:L/Au:N vector. The description does not state whether user interaction such as visiting a page is needed, though the vector implies none.

Exploitation

Not listed in CISA KEV, but EPSS is 0.56607 (99th percentile) and references carry Exploit tags, indicating public exploit material exists.

What to do

  • Apply the Microsoft security update referenced in MS04-038, which addresses this vulnerability.
  • Upgrade or replace Internet Explorer 6.0 SP1 and earlier, which are long out of support.
  • Restrict or block browsing with affected IE versions on managed endpoints.
  • Filter or sanitize untrusted CSS content at web proxies and email gateways where feasible.

Detection

  • Monitor for IE process crashes correlated with pages containing malformed CSS such as the '<STYLE>@;/*' pattern.
  • Alert on crash reports or event logs showing memory corruption in IE rendering components.
  • Hunt proxy or web logs for delivery of suspicious CSS payloads to IE clients.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://marc.info/?l=bugtraq&m=109107496214572&w=2
http://marc.info/?l=full-disclosure&m=109060455614702&w=2
http://marc.info/?l=full-disclosure&m=109102919426844&w=2
http://secunia.com/advisories/12806
http://www.ciac.org/ciac/bulletins/p-006.shtml
http://www.ecqurity.com/adv/IEstyle.html ExploitVendor Advisory
http://www.kb.cert.org/vuls/id/291304 US Government Resource
http://www.securiteam.com/exploits/5NP042KF5A.html
http://www.securityfocus.com/bid/10816 ExploitPatchVendor Advisory
http://www.us-cert.gov/cas/techalerts/TA04-293A.html US Government Resource
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-038
https://exchange.xforce.ibmcloud.com/vulnerabilities/16675
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2906
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3372
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4169
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5592
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6579
http://marc.info/?l=bugtraq&m=109107496214572&w=2
http://marc.info/?l=full-disclosure&m=109060455614702&w=2
http://marc.info/?l=full-disclosure&m=109102919426844&w=2
http://secunia.com/advisories/12806
http://www.ciac.org/ciac/bulletins/p-006.shtml
http://www.ecqurity.com/adv/IEstyle.html ExploitVendor Advisory
http://www.kb.cert.org/vuls/id/291304 US Government Resource
http://www.securiteam.com/exploits/5NP042KF5A.html
http://www.securityfocus.com/bid/10816 ExploitPatchVendor Advisory
http://www.us-cert.gov/cas/techalerts/TA04-293A.html US Government Resource
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-038
https://exchange.xforce.ibmcloud.com/vulnerabilities/16675
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2906
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3372
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4169
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5592
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6579

Track CVE-2004-0842 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2004-1050Internet Explorer 6 heap overflow via IFRAME, FRAME and EMBED attributesInternet Explorer 6 contains a heap-based buffer overflow triggered by long SRC or NAME attributes in IFRAME, FRAME and EMBED elements. A remote atta…EPSS 67%analysed10.0CVE-2004-0201Microsoft HTML Help hh.exe heap buffer overflow via crafted CHM fileThe HTML Help program (hh.exe) in multiple Microsoft Windows versions contains a heap-based buffer overflow triggered by a .CHM file with a large len…EPSS 45%analysed10.0CVE-2004-0212Windows Task Scheduler .job file stack buffer overflowThe Windows Task Scheduler in Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, contains a stack-based buffer overflow triggered by a .…EPSS 64%analysed9.3CVE-2007-2374Microsoft windows 2000 vulnerabilityUnspecified vulnerability in Microsoft Windows 2000, XP, and Server 2003 allows user-assisted remote attackers to execute arbitrary code via unspecif…EPSS 17%9.3CVE-2007-1765Microsoft Windows ANI cursor parsing memory corruptionMicrosoft Windows 2000 SP4 through Vista mishandles malformed ANI files when processing cursors, animated cursors and icons, causing memory corruptio…EPSS 55%analysed7.5CVE-2004-1307Avaya call management system server vulnerabilityInteger overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF …EPSS 6.3%7.5CVE-2004-1082Apache http server vulnerabilitymod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attacke…EPSS 7.6%7.2CVE-2004-0205Avaya ip600 media servers vulnerabilityBuffer overflow in Microsoft Internet Information Server (IIS) 4.0 allows local users to execute arbitrary code via the redirect function.EPSS 24%

Source: NIST National Vulnerability Database (record CVE-2004-0842), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.