5
CVE-2008-0085
- EPSS 30.43%
- Veröffentlicht 08.07.2008 23:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
- Quelle secure@microsoft.com
- Teams Watchlist Login
- Unerledigt Login
SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE); Microsoft Data Engine (MSDE) 1.0 SP4; and Internal Database (WYukon) SP2 does not initialize memory pages when reallocating memory, which allows database operators to obtain sensitive information (database contents) via unknown vectors related to memory page reuse.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Data Engine Version1.0 Updatesp4
Microsoft ≫ Sql Server Version7.0 Updatesp4
Microsoft ≫ Sql Server Version2000 Updatesp4
Microsoft ≫ Sql Server Version2000 Updatesp4 HwPlatformitanium
Microsoft ≫ Sql Server Version2005 Updatesp1
Microsoft ≫ Sql Server Version2005 Updatesp1 HwPlatformitanium
Microsoft ≫ Sql Server Version2005 Updatesp1 HwPlatformx64
Microsoft ≫ Sql Server Version2005 Updatesp1 Editionexpress
Microsoft ≫ Sql Server Version2005 Updatesp2
Microsoft ≫ Sql Server Version2005 Updatesp2 HwPlatformitanium
Microsoft ≫ Sql Server Version2005 Updatesp2 HwPlatformx64
Microsoft ≫ Sql Server Version2005 Updatesp2 Editionexpress
Microsoft ≫ Sql Server Desktop Engine Version2000 Updatesp4
Microsoft ≫ Wmsde Version2000
Microsoft ≫ Windows 2003 Server Version- Updatesp1
Microsoft ≫ Windows 2003 Server Version- Updatesp2
Microsoft ≫ Windows 2003 Server Version- Updatesp2
Microsoft ≫ Wyukon Updatesp2
Microsoft ≫ Windows 2003 Server Version- Updatesp1
Microsoft ≫ Windows 2003 Server Version- Updatesp2
Microsoft ≫ Windows 2003 Server Version- Updatesp2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 30.43% | 0.966 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.