Vulnerability record · CVE-2004-0842 · published 23 December 2004
CVE-2004-0842: Internet Explorer CSS heap memory corruption denial of service
Avaya · Ip600 Media Servers
Internet Explorer 6.0 SP1 and earlier mishandles malformed Cascading Style Sheet elements, triggering a heap-based buffer overflow that crashes the application. The flaw stems from a missing comment terminator that can cause an invalid length to drive a large memory copy operation. It matters because a remote attacker can crash the browser through crafted CSS content.
Description
Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "<STYLE>@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability."
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
medium priorityThe flaw is a remote, unauthenticated crash with public exploit material, but the record documents only denial of service and the affected software is long obsolete.
What it is
Internet Explorer 6.0 SP1 and earlier mishandles malformed Cascading Style Sheet elements, triggering a heap-based buffer overflow that crashes the application. The flaw stems from a missing comment terminator that can cause an invalid length to drive a large memory copy operation. It matters because a remote attacker can crash the browser through crafted CSS content.
Impact
An attacker gains a denial of service: the browser process crashes from memory corruption. The record describes only a crash, not code execution, so no further attacker gain is established.
Attack surface
Reached remotely over the network with no authentication required, per the AV:N/AC:L/Au:N vector. The description does not state whether user interaction such as visiting a page is needed, though the vector implies none.
Exploitation
Not listed in CISA KEV, but EPSS is 0.56607 (99th percentile) and references carry Exploit tags, indicating public exploit material exists.
What to do
- Apply the Microsoft security update referenced in MS04-038, which addresses this vulnerability.
- Upgrade or replace Internet Explorer 6.0 SP1 and earlier, which are long out of support.
- Restrict or block browsing with affected IE versions on managed endpoints.
- Filter or sanitize untrusted CSS content at web proxies and email gateways where feasible.
Detection
- Monitor for IE process crashes correlated with pages containing malformed CSS such as the '<STYLE>@;/*' pattern.
- Alert on crash reports or event logs showing memory corruption in IE rendering components.
- Hunt proxy or web logs for delivery of suspicious CSS payloads to IE clients.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-0842 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-0842), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.