CVE-2000-1088
published 2001-01-09CVE-2000-1088: The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before…
PriorityP422medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
2.84%
85.1th percentile
The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | data_engine | — | — |
| microsoft | data_engine | — | — |
| microsoft | sql_server | — | — |
| microsoft | sql_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Microsoft Outlook 97/98/2000/4/5 - Address Book Spoofing
exploitdb·2001-06-05
CVE-2001-1088 Microsoft Outlook 97/98/2000/4/5 - Address Book Spoofing
Microsoft Outlook 97/98/2000/4/5 - Address Book Spoofing
---
source: https://www.securityfocus.com/bid/2823/info
Outlook Express is the standard e-mail client that is shipped with Microsoft Windows 9x/ME/NT.
The address book in Outlook Express is normally configured to make entries for all addresses that are replied to by the user of the mail client. An attacker may construct a message header that tricks Address Book into making an entry for an untrusted user under the guise of a trusted one. This is done by sending a message with a misleading "From:" field. When the message is replied to then Address Book will make an entry which actually replies to the attacker.
Situation: 2 good users Target1 and Target2 with addresses [email protected] and
[email protected] and one bad user At
Exploit-DB
Real Networks RealPlayer 6/7 - Location Buffer Overflow
exploitdb·2000-04-03
CVE-2000-0280 Real Networks RealPlayer 6/7 - Location Buffer Overflow
Real Networks RealPlayer 6/7 - Location Buffer Overflow
---
source: https://www.securityfocus.com/bid/1088/info
Unchecked buffer code exists in the 'location' field of Real Networks RealPlayer versions 6.0 and 7.0. Requesting a URL containing a string consisting of 300 or more characters would cause the application to crash and would require a restart in order to regain normal functionality. Arbitrary code can potentially be executed through this vulnerability.
This vulnerability may be exploited remotely if such a URL were embedded in a HTML file with the command 'autostart' set as 'true'. Both RealPlayer and the accompanying browser would crash in this case and require to be restarted to regain functionality.
So far only the Windows versions of the Real Player have been proven to be
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=97570884410184&w=2http://www.securityfocus.com/bid/2043https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-092http://marc.info/?l=bugtraq&m=97570884410184&w=2http://www.securityfocus.com/bid/2043https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-092
2001-01-09
Published