cbcvebase.

Microsoft SQL Server vulnerabilities

108 known vulnerabilities affecting microsoft/sql_server.

Total CVEs
108
CISA KEV
2
actively exploited
Public exploits
23
Exploited in wild
7
Severity breakdown
CRITICAL18HIGH57MEDIUM30LOW3

Vulnerabilities

Page 3 of 6
CVE-2003-0232P3HIGHCVSS 7.2PoCv7.0v20002003-08-27
CVE-2003-0232 [HIGH] CVE-2003-0232: Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain re Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local Procedure Calls (LPC) port that leads to a buffer overflow.
nvd
CVE-2024-0056P3HIGHCVSS 8.7v20222024-01-09
CVE-2024-0056 [HIGH] CWE-319 CVE-2024-0056: Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnera Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
nvd
CVE-2023-38169P3HIGHCVSS 8.8v2019v20222023-08-08
CVE-2023-38169 [HIGH] CWE-416 CVE-2023-38169: Microsoft SQL OLE DB Remote Code Execution Vulnerability Microsoft SQL OLE DB Remote Code Execution Vulnerability
nvd
CVE-2022-29143P3HIGHCVSS 7.5v2014v2016+2 more2022-06-15
CVE-2022-29143 [HIGH] CVE-2022-29143: Microsoft SQL Server Remote Code Execution Vulnerability Microsoft SQL Server Remote Code Execution Vulnerability
nvd
CVE-2000-1085P4MEDIUMCVSS 4.6PoCv7.0v20002001-01-09
CVE-2000-1085 [MEDIUM] CVE-2000-1085: The xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not The xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedur
nvd
CVE-2000-1081P4MEDIUMCVSS 4.6PoCv7.0v20002001-01-09
CVE-2000-1081 [MEDIUM] CVE-2000-1081: The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does n The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Proced
nvd
CVE-2017-8516P3HIGHCVSS 7.5v2012v2014+1 more2017-08-08
CVE-2017-8516 [HIGH] CWE-200 CVE-2017-8516: Microsoft SQL Server Analysis Services in Microsoft SQL Server 2012, Microsoft SQL Server 2014, and Microsoft SQL Server Analysis Services in Microsoft SQL Server 2012, Microsoft SQL Server 2014, and Microsoft SQL Server 2016 allows an information disclosure vulnerability when it improperly enforces permissions, aka "Microsoft SQL Server Analysis Services Information Disclosure Vulnerability".
nvd
CVE-2000-1083P4LOWCVSS 2.1PoCv7.0v20002001-01-09
CVE-2000-1083 [LOW] CVE-2000-1083: The xp_showcolv function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not prope The xp_showcolv function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Paramet
nvd
CVE-2003-0231P4MEDIUMCVSS 5.0PoCv7.0v20002003-08-27
CVE-2003-0231 [MEDIUM] CVE-2003-0231: Microsoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial Microsoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial of service (crash or hang) via a long request to a named pipe.
nvd
CVE-2015-1761P3MEDIUMCVSS 6.5v2008v2012+1 more2015-07-14
CVE-2015-1761 [MEDIUM] CWE-284 CVE-2015-1761: Microsoft SQL Server 2008 SP3 and SP4, 2008 R2 SP2 and SP3, 2012 SP1 and SP2, and 2014 uses an incor Microsoft SQL Server 2008 SP3 and SP4, 2008 R2 SP2 and SP3, 2012 SP1 and SP2, and 2014 uses an incorrect class during casts of unspecified pointers, which allows remote authenticated users to gain privileges by leveraging certain write access, aka "SQL Server Elevation of Privilege Vulnerability."
nvd
CVE-2023-23384P3HIGHCVSS 7.3v2008v2012+5 more2023-04-11
CVE-2023-23384 [HIGH] CWE-122 CVE-2023-23384: Microsoft SQL Server Remote Code Execution Vulnerability Microsoft SQL Server Remote Code Execution Vulnerability
nvd
CVE-2015-1762P3HIGHCVSS 7.1v2008v2012+1 more2015-07-14
CVE-2015-1762 [HIGH] CWE-74 CVE-2015-1762: Microsoft SQL Server 2008 SP3 and SP4, 2008 R2 SP2 and SP3, 2012 SP1 and SP2, and 2014, when transac Microsoft SQL Server 2008 SP3 and SP4, 2008 R2 SP2 and SP3, 2012 SP1 and SP2, and 2014, when transactional replication is configured, does not prevent use of uninitialized memory in unspecified function calls, which allows remote authenticated users to execute arbitrary code by leveraging certain permissions and making a crafted query, as demonstrated by
nvd
CVE-2016-7252P3MEDIUMCVSS 6.5v20162016-11-10
CVE-2016-7252 [MEDIUM] CWE-200 CVE-2016-7252: Microsoft SQL Server 2016 mishandles the FILESTREAM path, which allows remote authenticated users to Microsoft SQL Server 2016 mishandles the FILESTREAM path, which allows remote authenticated users to gain privileges via unspecified vectors, aka "SQL Analysis Services Information Disclosure Vulnerability."
nvd
CVE-2014-4061P3MEDIUMCVSS 6.8v2008v20122014-08-12
CVE-2014-4061 [MEDIUM] CWE-399 CVE-2014-4061: Microsoft SQL Server 2008 SP3, 2008 R2 SP2, and 2012 SP1 does not properly control use of stack memo Microsoft SQL Server 2008 SP3, 2008 R2 SP2, and 2012 SP1 does not properly control use of stack memory for processing of T-SQL batch commands, which allows remote authenticated users to cause a denial of service (daemon hang) via a crafted T-SQL statement, aka "Microsoft SQL Server Stack Overrun Vulnerability."
nvd
CVE-1999-0999P4MEDIUMCVSS 4.3PoCv7.01999-11-19
CVE-1999-0999 [MEDIUM] CWE-20 CVE-1999-0999: Microsoft SQL 7.0 server allows a remote attacker to cause a denial of service via a malformed TDS p Microsoft SQL 7.0 server allows a remote attacker to cause a denial of service via a malformed TDS packet.
nvd
CVE-2008-4110P3HIGHCVSS 7.6v20002008-09-16
CVE-2008-4110 [HIGH] CWE-119 CVE-2008-4110: Buffer overflow in the SQLVDIRLib.SQLVDirControl ActiveX control in Tools\Binn\sqlvdir.dll in Micros Buffer overflow in the SQLVDIRLib.SQLVDirControl ActiveX control in Tools\Binn\sqlvdir.dll in Microsoft SQL Server 2000 (aka SQL Server 8.0) allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a long URL in the second argument to the Connect method. NOTE: this issue is not a vulnerability in many e
nvd
CVE-2002-0642P3HIGHCVSS 7.2v20002002-07-23
CVE-2002-0642 [HIGH] CVE-2002-0642: The registry key containing the SQL Server service account information in Microsoft SQL Server 2000, The registry key containing the SQL Server service account information in Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, has insecure permissions, which allows local users to gain privileges, aka "Incorrect Permission on SQL Server Service Account Registry Key."
nvd
CVE-2022-23276P3HIGHCVSS 7.8v20192022-02-09
CVE-2022-23276 [HIGH] CVE-2022-23276: SQL Server for Linux Containers Elevation of Privilege Vulnerability SQL Server for Linux Containers Elevation of Privilege Vulnerability
nvd
CVE-2023-21528P3HIGHCVSS 7.8v2008v2012+5 more2023-02-14
CVE-2023-21528 [HIGH] CWE-122 CVE-2023-21528: Microsoft SQL Server Remote Code Execution Vulnerability Microsoft SQL Server Remote Code Execution Vulnerability
nvd
CVE-2002-0056P3HIGHCVSS 7.5v7.0v20002002-03-08
CVE-2002-0056 [HIGH] CVE-2002-0056: Buffer overflow in SQL Server 7.0 and 2000 allows remote attackers to execute arbitrary code via a l Buffer overflow in SQL Server 7.0 and 2000 allows remote attackers to execute arbitrary code via a long OLE DB provider name to (1) OpenDataSource or (2) OpenRowset in an ad hoc connection.
nvd
Microsoft SQL Server vulnerabilities | cvebase