5

CVE-2008-0085

SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE); Microsoft Data Engine (MSDE) 1.0 SP4; and Internal Database (WYukon) SP2 does not initialize memory pages when reallocating memory, which allows database operators to obtain sensitive information (database contents) via unknown vectors related to memory page reuse.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Data Engine Version 1.0 Update sp4
Microsoft ≫ Sql Server Version 7.0 Update sp4
Microsoft ≫ Sql Server Version 2000 Update sp4
Microsoft ≫ Sql Server Version 2000 Update sp4 HwPlatform itanium
Microsoft ≫ Sql Server Version 2005 Update sp1
Microsoft ≫ Sql Server Version 2005 Update sp1 HwPlatform itanium
Microsoft ≫ Sql Server Version 2005 Update sp1 HwPlatform x64
Microsoft ≫ Sql Server Version 2005 Update sp1 Edition express
Microsoft ≫ Sql Server Version 2005 Update sp2
Microsoft ≫ Sql Server Version 2005 Update sp2 HwPlatform itanium
Microsoft ≫ Sql Server Version 2005 Update sp2 HwPlatform x64
Microsoft ≫ Sql Server Version 2005 Update sp2 Edition express
Microsoft ≫ Sql Server Desktop Engine Version 2000 Update sp4
Microsoft ≫ Wmsde Version 2000
   Microsoft ≫ Windows 2003 Server Version - Update sp1
   Microsoft ≫ Windows 2003 Server Version - Update sp2
Microsoft ≫ Wyukon Update sp2
   Microsoft ≫ Windows 2003 Server Version - Update sp1
   Microsoft ≫ Windows 2003 Server Version - Update sp2
Microsoft ≫ Wmsde Version 2000
   Microsoft ≫ Windows Server 2003
   Microsoft ≫ Windows Server 2003 Version - Update sp2
Microsoft ≫ Wyukon Update sp2 HwPlatform x64
   Microsoft ≫ Windows Server 2003
   Microsoft ≫ Windows Server 2003 Version - Update sp2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 10.68% 0.952
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://secunia.com/advisories/30970
Vendor Advisory
http://www.securityfocus.com/archive/1/516397/100/0/threaded
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id?1020441
Third Party Advisory
VDB Entry
http://www.us-cert.gov/cas/techalerts/TA08-190A.html
Third Party Advisory
US Government Resource
http://www.vmware.com/security/advisories/VMSA-2011-0003.html
Patch
Third Party Advisory
http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html
Third Party Advisory
http://www.vupen.com/english/advisories/2008/2022/references
Broken Link
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-040
Patch
Vendor Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14213
Third Party Advisory