19 results (0.006 seconds)

CVSS: 8.7EPSS: 0%CPEs: 77EXPL: 0

Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability Vulnerabilidad de omisión de característica de seguridad del proveedor de datos SQL de Microsoft.Data.SqlClient y System.Data.SqlClient A vulnerability was found in the .NET Framework. This vulnerability exists in the Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data provider where an attackercan perform an AiTM (adversary-in-the-middle) attack between the SQL client and the SQL server. This may allow the attacker to steal authentication credentials intended for the database server, even if the connection is established over an encrypted channel like TLS. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-0056 https://access.redhat.com/security/cve/CVE-2024-0056 https://bugzilla.redhat.com/show_bug.cgi?id=2255384 • CWE-319: Cleartext Transmission of Sensitive Information CWE-420: Unprotected Alternate Channel •

CVSS: 7.8EPSS: 0%CPEs: 8EXPL: 0

Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability Vulnerabilidad de ejecución remota de código en Microsoft ODBC Driver para SQL Server • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36785 • CWE-191: Integer Underflow (Wrap or Wraparound) •

CVSS: 7.8EPSS: 0%CPEs: 4EXPL: 0

Microsoft SQL OLE DB Remote Code Execution Vulnerability Vulnerabilidad de ejecución remota de código de Microsoft SQL OLE DB • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36417 • CWE-122: Heap-based Buffer Overflow •

CVSS: 7.8EPSS: 0%CPEs: 8EXPL: 0

Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability Vulnerabilidad de ejecución remota de código en Microsoft ODBC Driver para SQL Server • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36420 • CWE-415: Double Free •

CVSS: 5.5EPSS: 0%CPEs: 13EXPL: 0

Microsoft SQL Server Denial of Service Vulnerability Vulnerabilidad de denegación de servicio en Microsoft SQL Server • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36728 • CWE-125: Out-of-bounds Read •