Vulnerabilities > Microsoft > SQL Server > 7.0
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2001-07-21 | CVE-2001-0344 | Unspecified vulnerability in Microsoft SQL Server 2000/7.0 An SQL query method in Microsoft SQL Server 2000 Gold and 7.0 using Mixed Mode allows local database users to gain privileges by reusing a cached connection of the sa administrator account. | 7.2 |
2001-01-09 | CVE-2000-1088 | Buffer Overflow vulnerability in Microsoft Data Engine and SQL Server The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. | 4.6 |
2001-01-09 | CVE-2000-1087 | Buffer Overflow vulnerability in Microsoft Data Engine and SQL Server The xp_proxiedmetadata function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. | 4.6 |
2001-01-09 | CVE-2000-1086 | Buffer Overflow vulnerability in Microsoft Data Engine and SQL Server The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. | 4.6 |
2001-01-09 | CVE-2000-1085 | Buffer Overflow vulnerability in Microsoft Data Engine and SQL Server The xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. | 4.6 |
2001-01-09 | CVE-2000-1084 | Buffer Overflow vulnerability in Microsoft Data Engine and SQL Server The xp_updatecolvbm function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. | 4.6 |
2001-01-09 | CVE-2000-1083 | Buffer Overflow vulnerability in Microsoft Data Engine and SQL Server The xp_showcolv function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. | 2.1 |
2001-01-09 | CVE-2000-1082 | Buffer Overflow vulnerability in Microsoft Data Engine and SQL Server The xp_enumresultset function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. | 4.6 |
2001-01-09 | CVE-2000-1081 | Buffer Overflow vulnerability in Microsoft Data Engine and SQL Server The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. | 4.6 |
2000-07-11 | CVE-2000-0654 | Unspecified vulnerability in Microsoft SQL Server 7.0 Microsoft Enterprise Manager allows local users to obtain database passwords via the Data Transformation Service (DTS) package Registered Servers Dialog dialog, aka a variant of the "DTS Password" vulnerability. | 4.6 |