Microsoft / Data Engine
26 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2008-0107 | Integer underflow in SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop En… | HIGH | 9.0 | Jul 8, 2008 |
| CVE-2008-0106 | Buffer overflow in Microsoft SQL Server 2005 SP1 and SP2, and 2005 Express Edition SP1 and SP2, allows remote authenticated users to execute arbitrary code via… | HIGH | 9.0 | Jul 8, 2008 |
| CVE-2008-0086 | Buffer overflow in the convert function in Microsoft SQL Server 2000 SP4, 2000 Desktop Engine (MSDE 2000) SP4, and 2000 Desktop Engine (WMSDE) allows remote au… | HIGH | 9.0 | Jul 8, 2008 |
| CVE-2008-0085 | SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE); Microso… | MEDIUM | 5.0 | Jul 8, 2008 |
| CVE-2002-1138 | Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, writes output files for scheduled jobs… | HIGH | 7.5 | Sep 1, 2004 |
| CVE-2002-1137 | Buffer overflow in the Database Console Command (DBCC) that handles user inputs in Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.… | HIGH | 7.5 | Sep 1, 2004 |
| CVE-2002-1123 | Buffer overflow in the authentication function for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows remote attackers to execute arbitr… | HIGH | 7.5 | Sep 1, 2004 |
| CVE-2003-0232 | Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local Procedure Calls (LPC) port that leads to… | HIGH | 7.2 | Jul 25, 2003 |
| CVE-2003-0231 | Microsoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial of service (crash or hang) via a long request to a named pi… | MEDIUM | 5.0 | Jul 25, 2003 |
| CVE-2003-0230 | Microsoft SQL Server 7, 2000, and MSDE allows local users to gain privileges by hijacking a named pipe during the authentication of another user, aka the "Name… | HIGH | 7.2 | Jul 25, 2003 |
| CVE-2002-1145 | The xp_runwebtask stored procedure in the Web Tasks component of Microsoft SQL Server 7.0 and 2000, Microsoft Data Engine (MSDE) 1.0, and Microsoft Desktop Eng… | HIGH | 10.0 | Oct 21, 2002 |
| CVE-2002-0721 | Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could allow un… | HIGH | 10.0 | Aug 20, 2002 |
| CVE-2000-1209 | The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including thir… | HIGH | 10.0 | Aug 10, 2002 |
| CVE-2002-0649 | Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSDE) allow remote attackers to cause a de… | HIGH | 7.5 | Jul 26, 2002 |
| CVE-2002-0645 | SQL injection vulnerability in stored procedures for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 may allow authenticated users to execut… | HIGH | 7.5 | Jul 26, 2002 |
| CVE-2002-0644 | Buffer overflow in several Database Consistency Checkers (DBCCs) for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows members of the d… | HIGH | 7.5 | Jul 26, 2002 |
| CVE-2002-0643 | The installation of Microsoft Data Engine 1.0 (MSDE 1.0), and Microsoft SQL Server 2000 creates setup.iss files with insecure permissions and does not delete t… | MEDIUM | 4.6 | Jul 12, 2002 |
| CVE-2000-1088 | The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calli… | MEDIUM | 4.6 | Dec 19, 2000 |
| CVE-2000-1087 | The xp_proxiedmetadata function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before call… | MEDIUM | 4.6 | Dec 19, 2000 |
| CVE-2000-1086 | The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before call… | MEDIUM | 4.6 | Dec 19, 2000 |
| CVE-2000-1085 | The xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling th… | MEDIUM | 4.6 | Dec 19, 2000 |
| CVE-2000-1084 | The xp_updatecolvbm function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the… | MEDIUM | 4.6 | Dec 19, 2000 |
| CVE-2000-1083 | The xp_showcolv function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_… | LOW | 2.1 | Dec 19, 2000 |
| CVE-2000-1082 | The xp_enumresultset function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the… | MEDIUM | 4.6 | Dec 19, 2000 |
| CVE-2000-1081 | The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling… | MEDIUM | 4.6 | Dec 19, 2000 |
Showing 1 to 25 of 26 CVEs