CVE-2020-1455 – Microsoft SQL Server Management Studio Denial of Service Vulnerability
https://notcve.org/view.php?id=CVE-2020-1455
A denial of service vulnerability exists when Microsoft SQL Server Management Studio (SSMS) improperly handles files. An attacker could exploit the vulnerability to trigger a denial of service. To exploit the vulnerability, an attacker would first require execution on the victim system. The security update addresses the vulnerability by ensuring Microsoft SQL Server Management Studio properly handles files. Se presenta una vulnerabilidad de denegación de servicio cuando Microsoft SQL Server Management Studio (SSMS), maneja archivos inapropiadamente, también se conoce como "Microsoft SQL Server Management Studio Denial of Service Vulnerability". • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1455 •
CVE-2019-1376
https://notcve.org/view.php?id=CVE-2019-1376
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when it improperly enforces permissions, aka 'SQL Server Management Studio Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1313. Hay una vulnerabilidad de divulgación de información en Microsoft SQL Server Management Studio (SSMS) cuando aplica inapropiadamente los permisos, también se conoce como "SQL Server Management Studio Information Disclosure Vulnerability". Este ID de CVE es diferente de CVE-2019-1313. • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1376 • CWE-755: Improper Handling of Exceptional Conditions •
CVE-2019-1313
https://notcve.org/view.php?id=CVE-2019-1313
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when it improperly enforces permissions, aka 'SQL Server Management Studio Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1376. Hay una vulnerabilidad de divulgación de información en Microsoft SQL Server Management Studio (SSMS) cuando aplica inapropiadamente los permisos, también se conoce como "SQL Server Management Studio Information Disclosure Vulnerability". Este ID de CVE es diferente de CVE-2019-1376. • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1313 • CWE-755: Improper Handling of Exceptional Conditions •
CVE-2018-8532 – Microsoft SQL Server Management Studio xmla File XML External Entity Processing Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2018-8532
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XMLA file containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This affects SQL Server Management Studio 17.9, SQL Server Management Studio 18.0. This CVE ID is unique from CVE-2018-8527, CVE-2018-8533. Existe una vulnerabilidad de divulgación de información en Microsoft SQL Server Management Studio (SSMS) al analizar un archivo XMLA malicioso que contiene una referencia a una entidad externa. Esto también se conoce como "SQL Server Management Studio Information Disclosure Vulnerability". • https://www.exploit-db.com/exploits/45587 http://www.securityfocus.com/bid/105475 http://www.securitytracker.com/id/1041826 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8532 • CWE-611: Improper Restriction of XML External Entity Reference •
CVE-2018-8533 – Microsoft SQL Server Management Studio regsrvr File XML External Entity Processing Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2018-8533
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing malicious XML content containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This affects SQL Server Management Studio 17.9, SQL Server Management Studio 18.0. This CVE ID is unique from CVE-2018-8527, CVE-2018-8532. Existe una vulnerabilidad de divulgación de información en Microsoft SQL Server Management Studio (SSMS) al analizar contenido XML malicioso que contiene una referencia a una entidad externa. Esto también se conoce como "SQL Server Management Studio Information Disclosure Vulnerability". • https://www.exploit-db.com/exploits/45583 http://www.securityfocus.com/bid/105476 http://www.securitytracker.com/id/1041826 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8533 • CWE-611: Improper Restriction of XML External Entity Reference •