CVE-2001-0344
- EPSS 1.04%
- Veröffentlicht 21.07.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
An SQL query method in Microsoft SQL Server 2000 Gold and 7.0 using Mixed Mode allows local database users to gain privileges by reusing a cached connection of the sa administrator account.
CVE-2000-1081
- EPSS 6.84%
- Veröffentlicht 09.01.2001 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which...
CVE-2000-1082
- EPSS 43.15%
- Veröffentlicht 09.01.2001 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The xp_enumresultset function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which al...
CVE-2000-1083
- EPSS 4.71%
- Veröffentlicht 09.01.2001 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The xp_showcolv function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows ...
CVE-2000-1084
- EPSS 43.15%
- Veröffentlicht 09.01.2001 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The xp_updatecolvbm function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which all...
CVE-2000-1085
- EPSS 10.69%
- Veröffentlicht 09.01.2001 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which a...
CVE-2000-1086
- EPSS 43.15%
- Veröffentlicht 09.01.2001 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), w...
CVE-2000-1087
- EPSS 43.15%
- Veröffentlicht 09.01.2001 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The xp_proxiedmetadata function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), w...
CVE-2000-1088
- EPSS 27.85%
- Veröffentlicht 09.01.2001 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), wh...
CVE-2000-0654
- EPSS 1.02%
- Veröffentlicht 11.07.2000 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Microsoft Enterprise Manager allows local users to obtain database passwords via the Data Transformation Service (DTS) package Registered Servers Dialog dialog, aka a variant of the "DTS Password" vulnerability.