2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2004-0842" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2004-12-23T05:00:00.000" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-20T23:49:32.833" ,
2023-04-24 12:24:31 +02:00
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from \"memory corruption\") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the \"<STYLE>@;/*\" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the \"CSS Heap Memory Corruption Vulnerability.\""
} ,
{
"lang" : "es" ,
"value" : "Internet Explorer 6.1 SP1 y anteriores, y posiblemente otras versiones, permiten a atacantes remotos causar una denegaci\u00f3n de servicio (ca\u00edda de aplicaci\u00f3n por \"corrupci\u00f3n de memoria\") mediante ciertos elementos de Hoja de Estilos en Cascada (CSS), como se ha demostrado usanto la cadena \"<STYLE>@;/*\", posiblemente debido a un terminador de comentario ausente que puede causar una longitud inv\u00e1lida que dispare una operaci\u00f3n de copia de memoria grande."
}
] ,
"metrics" : {
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 7.5 ,
2023-04-24 12:24:31 +02:00
"accessVector" : "NETWORK" ,
"accessComplexity" : "LOW" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "PARTIAL" ,
"integrityImpact" : "PARTIAL" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "PARTIAL"
2023-04-24 12:24:31 +02:00
} ,
"baseSeverity" : "HIGH" ,
"exploitabilityScore" : 10.0 ,
"impactScore" : 6.4 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : true ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : false
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "NVD-CWE-Other"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:avaya:ip600_media_servers:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9692F8E9-E8E9-43A8-87D5-F2409333F8CC"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:*" ,
"matchCriteriaId" : "24DF2AB3-DEAB-4D70-986E-FFBB7E64B96A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:internet_explorer:5.0.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3A04FEA6-37B0-44B0-844F-55652ABA1F85"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp1:*:*:*:*:*:*" ,
"matchCriteriaId" : "4D56FB8E-2553-47C1-82A2-9E59023780CE"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp2:*:*:*:*:*:*" ,
"matchCriteriaId" : "8541EEED-94F4-42F8-9719-57F3EC85D52B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp3:*:*:*:*:*:*" ,
"matchCriteriaId" : "40372520-08CF-4F64-A7AC-7E0AE0964138"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp4:*:*:*:*:*:*" ,
"matchCriteriaId" : "2EB39B99-91A0-4B70-B12A-BA37F6AFBA83"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:internet_explorer:5.5:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "40F8042F-C621-45AE-9F8C-70469579643A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:internet_explorer:5.5:sp1:*:*:*:*:*:*" ,
"matchCriteriaId" : "2CD04E07-3664-4D4F-BF3E-6B33AF0F2D12"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:internet_explorer:5.5:sp2:*:*:*:*:*:*" ,
"matchCriteriaId" : "D05ED9D0-CF78-4FAD-9371-6FB3D5825148"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A19F6133-25D1-44A5-B6B9-354703436783"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:h:avaya:definity_one_media_server:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "88301496-BED2-45EB-BF19-5F5BF2957373"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:h:avaya:s3400:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "BCB0BA4C-BA48-4DDA-917E-9EA9E04A898F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:h:avaya:s8100:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1D190CA6-7807-4361-8FB8-C015B21E66B1"
}
]
}
]
} ,
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:avaya:modular_messaging_message_storage_server:1.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E25F5CF2-F891-41CA-A40C-13966F72FDF8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:avaya:modular_messaging_message_storage_server:2.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7417958C-5321-41D6-9D1A-D16BF5511E81"
}
]
}
]
}
] ,
"references" : [
{
"url" : "http://marc.info/?l=bugtraq&m=109107496214572&w=2" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "http://marc.info/?l=full-disclosure&m=109060455614702&w=2" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "http://marc.info/?l=full-disclosure&m=109102919426844&w=2" ,
"source" : "cve@mitre.org"
} ,
2024-04-04 08:46:00 +00:00
{
"url" : "http://secunia.com/advisories/12806" ,
"source" : "cve@mitre.org"
} ,
2023-04-24 12:24:31 +02:00
{
"url" : "http://www.ciac.org/ciac/bulletins/p-006.shtml" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "http://www.ecqurity.com/adv/IEstyle.html" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Exploit" ,
"Vendor Advisory"
]
} ,
{
"url" : "http://www.kb.cert.org/vuls/id/291304" ,
"source" : "cve@mitre.org" ,
"tags" : [
"US Government Resource"
]
} ,
{
"url" : "http://www.securiteam.com/exploits/5NP042KF5A.html" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "http://www.securityfocus.com/bid/10816" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Exploit" ,
"Patch" ,
"Vendor Advisory"
]
} ,
{
"url" : "http://www.us-cert.gov/cas/techalerts/TA04-293A.html" ,
"source" : "cve@mitre.org" ,
"tags" : [
"US Government Resource"
]
} ,
{
"url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-038" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/16675" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2906" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3372" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4169" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5592" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6579" ,
"source" : "cve@mitre.org"
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "http://marc.info/?l=bugtraq&m=109107496214572&w=2" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://marc.info/?l=full-disclosure&m=109060455614702&w=2" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://marc.info/?l=full-disclosure&m=109102919426844&w=2" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://secunia.com/advisories/12806" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://www.ciac.org/ciac/bulletins/p-006.shtml" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://www.ecqurity.com/adv/IEstyle.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Exploit" ,
"Vendor Advisory"
]
} ,
{
"url" : "http://www.kb.cert.org/vuls/id/291304" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"US Government Resource"
]
} ,
{
"url" : "http://www.securiteam.com/exploits/5NP042KF5A.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://www.securityfocus.com/bid/10816" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Exploit" ,
"Patch" ,
"Vendor Advisory"
]
} ,
{
"url" : "http://www.us-cert.gov/cas/techalerts/TA04-293A.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"US Government Resource"
]
} ,
{
"url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-038" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/16675" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2906" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3372" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4169" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5592" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6579" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
2023-04-24 12:24:31 +02:00
}
]
}