Page 5 of 60 results (0.010 seconds)

CVSS: 9.0EPSS: 95%CPEs: 6EXPL: 0

Buffer overflow in Microsoft SQL Server 2005 SP1 and SP2, and 2005 Express Edition SP1 and SP2, allows remote authenticated users to execute arbitrary code via a crafted insert statement. Un desbordamiento de búfer en SQL Server 2005 SP1 y SP2, y 2005 Express Edition SP1 y SP2, de Microsoft, permite a usuarios autenticados remotos ejecutar código arbitrario por medio de una sentencia insert diseñada. • http://secunia.com/advisories/30970 http://www.securityfocus.com/archive/1/494082/100/0/threaded http://www.securityfocus.com/archive/1/516397/100/0/threaded http://www.securitytracker.com/id?1020441 http://www.us-cert.gov/cas/techalerts/TA08-190A.html http://www.vmware.com/security/advisories/VMSA-2011-0003.html http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html http://www.vupen.com/english/advisories/2008/2022/references https://docs.microsoft.com • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 7.2EPSS: 1%CPEs: 12EXPL: 0

Microsoft SQL Server 7, 2000, and MSDE allows local users to gain privileges by hijacking a named pipe during the authentication of another user, aka the "Named Pipe Hijacking" vulnerability. Microsoft SQL Server 7, 2000, y MSDE permite a usuarios locales ganar privilegios secuestrando una tubería con nombre (named pipe) de otro usuario, llamada vulnerabilidad de "Secuestro de Tubería con Nombre". • http://www.kb.cert.org/vuls/id/556356 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-031 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A235 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 7.2EPSS: 0%CPEs: 12EXPL: 1

Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local Procedure Calls (LPC) port that leads to a buffer overflow. Microsoft SQL Server 7, 2000 y MSDE permite a usuarios locales ejecutar código arbitrario mediante una cierta petición al puerto de llamadas de procedimiento local (LPC - Local Procedure Calls) que conduce a un desbordamiento de búfer. • https://www.exploit-db.com/exploits/65 http://www.atstake.com/research/advisories/2003/a072303-3.txt http://www.kb.cert.org/vuls/id/584868 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-031 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A303 •

CVSS: 5.0EPSS: 17%CPEs: 12EXPL: 1

Microsoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial of service (crash or hang) via a long request to a named pipe. Microsoft SQL Server 7, 2000 y MSDE permite a usurios locales o a usuarios remotos autenticados causar una denegación de servicio (caída o cuelgue) mediante un petición larga a una tubería con nombre. • https://www.exploit-db.com/exploits/22957 http://www.atstake.com/research/advisories/2003/a072303-2.txt http://www.kb.cert.org/vuls/id/918652 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-031 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A299 •

CVSS: 7.5EPSS: 1%CPEs: 10EXPL: 0

Microsoft SQL Server 6.0 through 2000, with SQL Authentication enabled, uses weak password encryption (XOR), which allows remote attackers to sniff and decrypt the password. • http://online.securityfocus.com/archive/1/298361 http://www.iss.net/security_center/static/10542.php http://www.nextgenss.com/papers/tp-SQL2000.pdf http://www.securityfocus.com/bid/6097 • CWE-326: Inadequate Encryption Strength •