Lucene search

K
nvd[email protected]NVD:CVE-2008-0085
HistoryJul 08, 2008 - 11:41 p.m.

CVE-2008-0085

2008-07-0823:41:00
CWE-200
web.nvd.nist.gov
5

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

7.3

Confidence

High

EPSS

0.028

Percentile

90.9%

SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE); Microsoft Data Engine (MSDE) 1.0 SP4; and Internal Database (WYukon) SP2 does not initialize memory pages when reallocating memory, which allows database operators to obtain sensitive information (database contents) via unknown vectors related to memory page reuse.

Affected configurations

Nvd
Node
microsoftdata_engineMatch1.0sp4
OR
microsoftsql_serverMatch7.0sp4
OR
microsoftsql_serverMatch2000sp4
OR
microsoftsql_serverMatch2000sp4itanium
OR
microsoftsql_serverMatch2005sp1
OR
microsoftsql_serverMatch2005sp1itanium
OR
microsoftsql_serverMatch2005sp1x64
OR
microsoftsql_serverMatch2005sp1express
OR
microsoftsql_serverMatch2005sp2
OR
microsoftsql_serverMatch2005sp2itanium
OR
microsoftsql_serverMatch2005sp2x64
OR
microsoftsql_serverMatch2005sp2express
OR
microsoftsql_server_desktop_engineMatch2000sp4
Node
microsoftwmsdeMatch2000
OR
microsoftwyukonsp2
AND
microsoftwindows_2003_serverMatch-sp1
OR
microsoftwindows_2003_serverMatch-sp2
Node
microsoftwmsdeMatch2000
OR
microsoftwyukonsp2x64
AND
microsoftwindows_server_2003
OR
microsoftwindows_server_2003Match-sp2
VendorProductVersionCPE
microsoftdata_engine1.0cpe:2.3:a:microsoft:data_engine:1.0:sp4:*:*:*:*:*:*
microsoftsql_server7.0cpe:2.3:a:microsoft:sql_server:7.0:sp4:*:*:*:*:*:*
microsoftsql_server2000cpe:2.3:a:microsoft:sql_server:2000:sp4:*:*:*:*:*:*
microsoftsql_server2000cpe:2.3:a:microsoft:sql_server:2000:sp4:*:*:*:*:itanium:*
microsoftsql_server2005cpe:2.3:a:microsoft:sql_server:2005:sp1:*:*:*:*:*:*
microsoftsql_server2005cpe:2.3:a:microsoft:sql_server:2005:sp1:*:*:*:*:itanium:*
microsoftsql_server2005cpe:2.3:a:microsoft:sql_server:2005:sp1:*:*:*:*:x64:*
microsoftsql_server2005cpe:2.3:a:microsoft:sql_server:2005:sp1:express:*:*:*:*:*
microsoftsql_server2005cpe:2.3:a:microsoft:sql_server:2005:sp2:*:*:*:*:*:*
microsoftsql_server2005cpe:2.3:a:microsoft:sql_server:2005:sp2:*:*:*:*:itanium:*
Rows per page:
1-10 of 201

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

7.3

Confidence

High

EPSS

0.028

Percentile

90.9%