Buffer Overflow in Microsoft SQL Server 2000 and MSDE
CVE-2000-1086

Currently unrated

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
9 January 2001

Summary

The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) is susceptible to a flaw that fails to appropriately restrict buffer length prior to invoking the srv_paraminfo function. This oversight can result in denial of service conditions or allow an attacker to execute arbitrary commands on the database server, thereby compromising the system's integrity and availability.

References

EPSS Score

43% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.