5

CVE-2008-0085

SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE); Microsoft Data Engine (MSDE) 1.0 SP4; and Internal Database (WYukon) SP2 does not initialize memory pages when reallocating memory, which allows database operators to obtain sensitive information (database contents) via unknown vectors related to memory page reuse.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MicrosoftData Engine Version1.0 Updatesp4
MicrosoftSql Server Version7.0 Updatesp4
MicrosoftSql Server Version2000 Updatesp4
MicrosoftSql Server Version2000 Updatesp4 HwPlatformitanium
MicrosoftSql Server Version2005 Updatesp1
MicrosoftSql Server Version2005 Updatesp1 HwPlatformitanium
MicrosoftSql Server Version2005 Updatesp1 HwPlatformx64
MicrosoftSql Server Version2005 Updatesp1 Editionexpress
MicrosoftSql Server Version2005 Updatesp2
MicrosoftSql Server Version2005 Updatesp2 HwPlatformitanium
MicrosoftSql Server Version2005 Updatesp2 HwPlatformx64
MicrosoftSql Server Version2005 Updatesp2 Editionexpress
MicrosoftSql Server Desktop Engine Version2000 Updatesp4
MicrosoftWmsde Version2000
   MicrosoftWindows 2003 Server Version- Updatesp1
   MicrosoftWindows 2003 Server Version- Updatesp2
MicrosoftWyukon Updatesp2
   MicrosoftWindows 2003 Server Version- Updatesp1
   MicrosoftWindows 2003 Server Version- Updatesp2
MicrosoftWmsde Version2000
   MicrosoftWindows Server 2003
   MicrosoftWindows Server 2003 Version- Updatesp2
MicrosoftWyukon Updatesp2 HwPlatformx64
   MicrosoftWindows Server 2003
   MicrosoftWindows Server 2003 Version- Updatesp2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 30.43% 0.966
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.