9

CVE-2008-0107

Integer underflow in SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE); Microsoft Data Engine (MSDE) 1.0 SP4; and Internal Database (WYukon) SP2 allows remote authenticated users to execute arbitrary code via a (1) SMB or (2) WebDAV pathname for an on-disk file (aka stored backup file) with a crafted record size value, which triggers a heap-based buffer overflow, aka "SQL Server Memory Corruption Vulnerability."

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MicrosoftData Engine Version1.0 Updatesp4
MicrosoftSql Server Version7.0 Updatesp4
MicrosoftSql Server Version2000 Updatesp4
MicrosoftSql Server Version2000 Updatesp4 Editionitanium
MicrosoftSql Server Version2005 Updatesp1
MicrosoftSql Server Version2005 Updatesp1 Editionexpress
MicrosoftSql Server Version2005 Updatesp1 Editionitanium
MicrosoftSql Server Version2005 Updatesp1 Editionx64
MicrosoftSql Server Version2005 Updatesp2
MicrosoftSql Server Version2005 Updatesp2 Editionexpress
MicrosoftSql Server Version2005 Updatesp2 Editionitanium
MicrosoftSql Server Version2005 Updatesp2 Editionx64
MicrosoftSql Server Desktop Engine Version2000 Updatesp4
MicrosoftWmsde Version2000
   MicrosoftWindows 2003 Server Updatesp1
   MicrosoftWindows 2003 Server Updatesp2
MicrosoftWyukon Updatesp2
   MicrosoftWindows 2003 Server Updatesp1
   MicrosoftWindows 2003 Server Updatesp2
MicrosoftWmsde Version2000
MicrosoftWyukon Updatesp2 Editionx64
MicrosoftWyukon Updatesp2
MicrosoftWyukon Updatesp2 Editionx64
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 57.27% 0.979
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C