Microsoft SQL Server vulnerabilities
108 known vulnerabilities affecting microsoft/sql_server.
Total CVEs
108
CISA KEV
2
actively exploited
Public exploits
23
Exploited in wild
7
Severity breakdown
CRITICAL18HIGH57MEDIUM30LOW3
Vulnerabilities
Page 5 of 6
CVE-2002-1872P4HIGHCVSS 7.5v6.0v6.5+2 more2002-12-31
CVE-2002-1872 [HIGH] CWE-326 CVE-2002-1872: Microsoft SQL Server 6.0 through 2000, with SQL Authentication enabled, uses weak password encryptio
Microsoft SQL Server 6.0 through 2000, with SQL Authentication enabled, uses weak password encryption (XOR), which allows remote attackers to sniff and decrypt the password.
nvd
CVE-2002-0057P4MEDIUMCVSS 5.0v20002002-03-08
CVE-2002-0057 [MEDIUM] CVE-2002-0057: XMLHTTP control in Microsoft XML Core Services 2.6 and later does not properly handle IE Security Zo
XMLHTTP control in Microsoft XML Core Services 2.6 and later does not properly handle IE Security Zone settings, which allows remote attackers to read arbitrary files by specifying a local file as an XML Data Source.
nvd
CVE-2016-7251P4MEDIUMCVSS 6.1v20162016-11-10
CVE-2016-7251 [MEDIUM] CWE-79 CVE-2016-7251: Cross-site scripting (XSS) vulnerability in the MDS API in Microsoft SQL Server 2016 allows remote a
Cross-site scripting (XSS) vulnerability in the MDS API in Microsoft SQL Server 2016 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "MDS API XSS Vulnerability."
nvd
CVE-2008-0085P4MEDIUMCVSS 5.0v7.0v2000+1 more2008-07-08
CVE-2008-0085 [MEDIUM] CWE-200 CVE-2008-0085: SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Ed
SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE); Microsoft Data Engine (MSDE) 1.0 SP4; and Internal Database (WYukon) SP2 does not initialize memory pages when reallocating memory, which allows database operators to obtain sensitive information (data
nvd
CVE-2002-0645P4HIGHCVSS 7.5v20002002-08-12
CVE-2002-0645 [HIGH] CVE-2002-0645: SQL injection vulnerability in stored procedures for Microsoft SQL Server 2000 and Microsoft Desktop
SQL injection vulnerability in stored procedures for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 may allow authenticated users to execute arbitrary commands.
nvd
CVE-2002-1138P4HIGHCVSS 7.5v7.0v20002002-10-11
CVE-2002-1138 [HIGH] CVE-2002-1138: Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop
Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, writes output files for scheduled jobs under its own privileges instead of the entity that launched it, which allows attackers to overwrite system files, aka "Flaw in Output File Handling for Scheduled Jobs."
nvd
CVE-2012-2552P4MEDIUMCVSS 4.3v2005v2008+1 more2012-10-09
CVE-2012-2552 [MEDIUM] CWE-79 CVE-2012-2552: Cross-site scripting (XSS) vulnerability in the SQL Server Report Manager in Microsoft SQL Server 20
Cross-site scripting (XSS) vulnerability in the SQL Server Report Manager in Microsoft SQL Server 2000 Reporting Services SP2 and SQL Server 2005 SP4, 2008 SP2 and SP3, 2008 R2 SP1, and 2012 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "Reflected XSS Vulnerability."
nvd
CVE-2001-0344P4HIGHCVSS 7.2v7.0v20002001-07-21
CVE-2001-0344 [HIGH] CVE-2001-0344: An SQL query method in Microsoft SQL Server 2000 Gold and 7.0 using Mixed Mode allows local database
An SQL query method in Microsoft SQL Server 2000 Gold and 7.0 using Mixed Mode allows local database users to gain privileges by reusing a cached connection of the sa administrator account.
nvd
CVE-2002-0650P4MEDIUMCVSS 5.0v20002002-08-12
CVE-2002-0650 [MEDIUM] CVE-2002-0650: The keep-alive mechanism for Microsoft SQL Server 2000 allows remote attackers to cause a denial of
The keep-alive mechanism for Microsoft SQL Server 2000 allows remote attackers to cause a denial of service (bandwidth consumption) via a "ping" style packet to the Resolution Service (UDP port 1434) with a spoofed IP address of another SQL Server system, which causes the two servers to exchange packets in an infinite loop.
nvd
CVE-2014-1820P4MEDIUMCVSS 4.3v2012v20142014-08-12
CVE-2014-1820 [MEDIUM] CWE-79 CVE-2014-1820: Cross-site scripting (XSS) vulnerability in Master Data Services (MDS) in Microsoft SQL Server 2012
Cross-site scripting (XSS) vulnerability in Master Data Services (MDS) in Microsoft SQL Server 2012 SP1 and 2014 on 64-bit platforms allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "SQL Master Data Services XSS Vulnerability."
nvd
CVE-2003-0230P4HIGHCVSS 7.2v7.0v20002003-08-27
CVE-2003-0230 [HIGH] CWE-264 CVE-2003-0230: Microsoft SQL Server 7, 2000, and MSDE allows local users to gain privileges by hijacking a named pi
Microsoft SQL Server 7, 2000, and MSDE allows local users to gain privileges by hijacking a named pipe during the authentication of another user, aka the "Named Pipe Hijacking" vulnerability.
nvd
CVE-2001-0509P4MEDIUMCVSS 5.0v7.0v20002001-09-20
CVE-2001-0509 [MEDIUM] CWE-20 CVE-2001-0509: Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL
Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs.
nvd
CVE-2002-0224P4MEDIUMCVSS 5.0v6.5v7.0+1 more2002-05-16
CVE-2002-0224 [MEDIUM] CVE-2002-0224: The MSDTC (Microsoft Distributed Transaction Service Coordinator) for Microsoft Windows 2000, Micros
The MSDTC (Microsoft Distributed Transaction Service Coordinator) for Microsoft Windows 2000, Microsoft IIS 5.0 and SQL Server 6.5 through SQL 2000 0.0 allows remote attackers to cause a denial of service (crash or hang) via malformed (random) input.
nvd
CVE-2023-36728P4MEDIUMCVSS 5.5v2014v2016+3 more2023-10-10
CVE-2023-36728 [MEDIUM] CWE-125 CVE-2023-36728: Microsoft SQL Server Denial of Service Vulnerability
Microsoft SQL Server Denial of Service Vulnerability
nvd
CVE-2000-1088P4MEDIUMCVSS 4.6v7.0v20002001-01-09
CVE-2000-1088 [MEDIUM] CVE-2000-1088: The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) doe
The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Pro
nvd
CVE-2000-1086P4MEDIUMCVSS 4.6v7.0v20002001-01-09
CVE-2000-1086 [MEDIUM] CVE-2000-1086: The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) do
The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Pr
nvd
CVE-2000-1082P4MEDIUMCVSS 4.6v7.0v20002001-01-09
CVE-2000-1082 [MEDIUM] CVE-2000-1082: The xp_enumresultset function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not
The xp_enumresultset function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure
nvd
CVE-2000-1084P4MEDIUMCVSS 4.6v7.0v20002001-01-09
CVE-2000-1084 [MEDIUM] CVE-2000-1084: The xp_updatecolvbm function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not p
The xp_updatecolvbm function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure
nvd
CVE-2000-1087P4MEDIUMCVSS 4.6v7.0v20002001-01-09
CVE-2000-1087 [MEDIUM] CVE-2000-1087: The xp_proxiedmetadata function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) do
The xp_proxiedmetadata function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Pr
nvd
CVE-2000-0199P4HIGHCVSS 7.2v7.02000-03-14
CVE-2000-0199 [HIGH] CVE-2000-0199: When a new SQL Server is registered in Enterprise Manager for Microsoft SQL Server 7.0 and the "Alwa
When a new SQL Server is registered in Enterprise Manager for Microsoft SQL Server 7.0 and the "Always prompt for login name and password" option is not set, then the Enterprise Manager uses weak encryption to store the login ID and password.
nvd