Lucene search

K
cveMicrosoftCVE-2008-0086
HistoryJul 08, 2008 - 11:41 p.m.

CVE-2008-0086

2008-07-0823:41:00
CWE-119
microsoft
web.nvd.nist.gov
73
cve-2008-0086
buffer overflow
microsoft sql server
remote code execution
nvd

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

AI Score

7.2

Confidence

High

EPSS

0.96

Percentile

99.5%

Buffer overflow in the convert function in Microsoft SQL Server 2000 SP4, 2000 Desktop Engine (MSDE 2000) SP4, and 2000 Desktop Engine (WMSDE) allows remote authenticated users to execute arbitrary code via a crafted SQL expression.

Affected configurations

Nvd
Node
microsoftdata_engineMatch1.0sp4
OR
microsoftsql_serverMatch7.0sp4
OR
microsoftsql_serverMatch2000sp4
OR
microsoftsql_serverMatch2005sp2
OR
microsoftsql_server_desktop_engineMatch2000sp4
OR
microsoftsql_server_express_editionMatch2005sp2
VendorProductVersionCPE
microsoftdata_engine1.0cpe:2.3:a:microsoft:data_engine:1.0:sp4:*:*:*:*:*:*
microsoftsql_server7.0cpe:2.3:a:microsoft:sql_server:7.0:sp4:*:*:*:*:*:*
microsoftsql_server2000cpe:2.3:a:microsoft:sql_server:2000:sp4:*:*:*:*:*:*
microsoftsql_server2005cpe:2.3:a:microsoft:sql_server:2005:sp2:*:*:*:*:*:*
microsoftsql_server_desktop_engine2000cpe:2.3:a:microsoft:sql_server_desktop_engine:2000:sp4:*:*:*:*:*:*
microsoftsql_server_express_edition2005cpe:2.3:a:microsoft:sql_server_express_edition:2005:sp2:*:*:*:*:*:*

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

AI Score

7.2

Confidence

High

EPSS

0.96

Percentile

99.5%