Vulnerabilities > Microsoft > SQL Server > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-10-10 CVE-2023-36728 Unspecified vulnerability in Microsoft products
Microsoft SQL Server Denial of Service Vulnerability
local
low complexity
microsoft
5.5
2019-05-16 CVE-2019-0819 Unspecified vulnerability in Microsoft SQL Server 2017
An information disclosure vulnerability exists in Microsoft SQL Server Analysis Services when it improperly enforces metadata permissions, aka 'Microsoft SQL Server Analysis Services Information Disclosure Vulnerability'.
network
low complexity
microsoft
6.5
2016-11-10 CVE-2016-7252 Information Exposure vulnerability in Microsoft SQL Server 2016
Microsoft SQL Server 2016 mishandles the FILESTREAM path, which allows remote authenticated users to gain privileges via unspecified vectors, aka "SQL Analysis Services Information Disclosure Vulnerability."
network
low complexity
microsoft CWE-200
6.5
2016-11-10 CVE-2016-7251 Cross-site Scripting vulnerability in Microsoft SQL Server 2016
Cross-site scripting (XSS) vulnerability in the MDS API in Microsoft SQL Server 2016 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "MDS API XSS Vulnerability."
network
low complexity
microsoft CWE-79
6.1