Microsoft SQL Server vulnerabilities
108 known vulnerabilities affecting microsoft/sql_server.
Total CVEs
108
CISA KEV
2
actively exploited
Public exploits
23
Exploited in wild
7
Severity breakdown
CRITICAL18HIGH57MEDIUM30LOW3
Vulnerabilities
Page 6 of 6
CVE-2002-0729P4MEDIUMCVSS 5.0v20002002-08-12
CVE-2002-0729 [MEDIUM] CVE-2002-0729: Microsoft SQL Server 2000 allows remote attackers to cause a denial of service via a malformed 0x08
Microsoft SQL Server 2000 allows remote attackers to cause a denial of service via a malformed 0x08 packet that is missing a colon separator.
nvd
CVE-1999-1556P4HIGHCVSS 7.2v6.51998-06-29
CVE-1999-1556 [HIGH] CVE-1999-1556: Microsoft SQL Server 6.5 uses weak encryption for the password for the SQLExecutiveCmdExec account a
Microsoft SQL Server 6.5 uses weak encryption for the password for the SQLExecutiveCmdExec account and stores it in an accessible portion of the registry, which could allow local users to gain privileges by reading and decrypting the CmdExecAccount value.
nvd
CVE-2002-1981P4MEDIUMCVSS 5.0v20002002-12-31
CVE-2002-1981 [MEDIUM] CVE-2002-1981: Microsoft SQL Server 2000 through SQL Server 2000 SP2 allows the "public" role to execute the (1) sp
Microsoft SQL Server 2000 through SQL Server 2000 SP2 allows the "public" role to execute the (1) sp_MSSetServerProperties or (2) sp_MSsetalertinfo stored procedures, which allows attackers to modify configuration including SQL server startup and alert settings.
nvd
CVE-2001-0879P4MEDIUMCVSS 5.0v7.0v20002001-12-20
CVE-2001-0879 [MEDIUM] CVE-2001-0879: Format string vulnerability in the C runtime functions in SQL Server 7.0 and 2000 allows attackers t
Format string vulnerability in the C runtime functions in SQL Server 7.0 and 2000 allows attackers to cause a denial of service.
nvd
CVE-2002-0643P4MEDIUMCVSS 4.6v7.0v20002002-07-23
CVE-2002-0643 [MEDIUM] CVE-2002-0643: The installation of Microsoft Data Engine 1.0 (MSDE 1.0), and Microsoft SQL Server 2000 creates setu
The installation of Microsoft Data Engine 1.0 (MSDE 1.0), and Microsoft SQL Server 2000 creates setup.iss files with insecure permissions and does not delete them after installation, which allows local users to obtain sensitive data, including weakly encrypted passwords, to gain privileges, aka "SQL Server Installation Process May Leave Passwords on System."
nvd
CVE-2000-0485P4LOWCVSS 2.1v6.5v7.02000-05-30
CVE-2000-0485 [LOW] CVE-2000-0485: Microsoft SQL Server allows local users to obtain database passwords via the Data Transformation Ser
Microsoft SQL Server allows local users to obtain database passwords via the Data Transformation Service (DTS) package Properties dialog, aka the "DTS Password" vulnerability.
nvd
CVE-2000-0603P4MEDIUMCVSS 4.6v7.02000-07-07
CVE-2000-0603 [MEDIUM] CVE-2000-0603: Microsoft SQL Server 7.0 allows a local user to bypass permissions for stored procedures by referenc
Microsoft SQL Server 7.0 allows a local user to bypass permissions for stored procedures by referencing them via a temporary stored procedure, aka the "Stored Procedure Permissions" vulnerability.
nvd
CVE-2000-0654P4MEDIUMCVSS 4.6v7.02000-07-11
CVE-2000-0654 [MEDIUM] CVE-2000-0654: Microsoft Enterprise Manager allows local users to obtain database passwords via the Data Transforma
Microsoft Enterprise Manager allows local users to obtain database passwords via the Data Transformation Service (DTS) package Registered Servers Dialog dialog, aka a variant of the "DTS Password" vulnerability.
nvd
← Previous6 / 6