Home/Product/microsoft sql server
Product

microsoft sql server

109 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-0056
all versions
Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
8.7HIGH
CVE-2023-36785
all versions
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
7.8HIGH
CVE-2023-36730
all versions
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
7.8HIGH
CVE-2023-36728
all versions
Microsoft SQL Server Denial of Service Vulnerability
5.5MEDIUM
CVE-2023-36420
all versions
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
7.8HIGH
CVE-2023-36417
all versions
Microsoft SQL OLE DB Remote Code Execution Vulnerability
7.8HIGH
CVE-2023-38169
all versions
Microsoft SQL OLE DB Remote Code Execution Vulnerability
8.8HIGH
CVE-2023-32028
all versions
Microsoft SQL OLE DB Remote Code Execution Vulnerability
7.8HIGH
CVE-2023-32027
all versions
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
7.8HIGH
CVE-2023-32026
all versions
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
7.8HIGH
CVE-2023-32025
all versions
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
7.8HIGH
CVE-2023-29356
all versions
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
7.8HIGH
CVE-2023-29349
all versions
Microsoft ODBC and OLE DB Remote Code Execution Vulnerability
7.8HIGH
CVE-2023-23384
all versions
Microsoft SQL Server Remote Code Execution Vulnerability
7.3HIGH
CVE-2023-21718
all versions
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
7.8HIGH
CVE-2023-21713
all versions
Microsoft SQL Server Remote Code Execution Vulnerability
8.8HIGH
CVE-2023-21705
all versions
Microsoft SQL Server Remote Code Execution Vulnerability
8.8HIGH
CVE-2023-21704
all versions
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
7.8HIGH
CVE-2023-21528
all versions
Microsoft SQL Server Remote Code Execution Vulnerability
7.8HIGH
CVE-2022-29143
all versions
Microsoft SQL Server Remote Code Execution Vulnerability
7.5HIGH
CVE-2022-23276
all versions
SQL Server for Linux Containers Elevation of Privilege Vulnerability
7.8HIGH
CVE-2021-1636
all versions
Microsoft SQL Elevation of Privilege Vulnerability
8.8HIGH
CVE-2020-0618
all versions
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests,
8.8HIGH
CVE-2019-1068
all versions
A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions,
8.8HIGH
CVE-2019-0819
all versions
An information disclosure vulnerability exists in Microsoft SQL Server Analysis Services when it improperly enforces metadata perm
6.5MEDIUM
CVE-2018-8273
all versions
A buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected system, a
9.8CRITICAL
CVE-2017-16055
all versions
sqlserver was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
7.5HIGH
CVE-2017-8516
all versions
Microsoft SQL Server Analysis Services in Microsoft SQL Server 2012, Microsoft SQL Server 2014, and Microsoft SQL Server 2016 allo
7.5HIGH
CVE-2016-7254
all versions
Microsoft SQL Server 2012 SP2 and 2012 SP3 does not properly perform a cast of an unspecified pointer, which allows remote authent
8.8HIGH
CVE-2016-7253
all versions
The agent in Microsoft SQL Server 2012 SP2, 2012 SP3, 2014 SP1, 2014 SP2, and 2016 does not properly check the atxcore.dll ACL, wh
8.8HIGH
CVE-2016-7252
all versions
Microsoft SQL Server 2016 mishandles the FILESTREAM path, which allows remote authenticated users to gain privileges via unspecifi
6.5MEDIUM
CVE-2016-7251
all versions
Cross-site scripting (XSS) vulnerability in the MDS API in Microsoft SQL Server 2016 allows remote attackers to inject arbitrary w
6.1MEDIUM
CVE-2016-7250
all versions
Microsoft SQL Server 2014 SP1, 2014 SP2, and 2016 does not properly perform a cast of an unspecified pointer, which allows remote
8.8HIGH
CVE-2016-7249
all versions
Microsoft SQL Server 2016 does not properly perform a cast of an unspecified pointer, which allows remote authenticated users to g
8.8HIGH
CVE-2015-1763
all versions
Microsoft SQL Server 2008 SP3 and SP4, 2008 R2 SP2 and SP3, 2012 SP1 and SP2, and 2014 does not prevent use of uninitialized memor
CVE-2015-1762
all versions
Microsoft SQL Server 2008 SP3 and SP4, 2008 R2 SP2 and SP3, 2012 SP1 and SP2, and 2014, when transactional replication is configur
CVE-2015-1761
all versions
Microsoft SQL Server 2008 SP3 and SP4, 2008 R2 SP2 and SP3, 2012 SP1 and SP2, and 2014 uses an incorrect class during casts of uns
CVE-2014-4061
all versions
Microsoft SQL Server 2008 SP3, 2008 R2 SP2, and 2012 SP1 does not properly control use of stack memory for processing of T-SQL bat
CVE-2014-1820
all versions
Cross-site scripting (XSS) vulnerability in Master Data Services (MDS) in Microsoft SQL Server 2012 SP1 and 2014 on 64-bit platfor
CVE-2012-2552
all versions
Cross-site scripting (XSS) vulnerability in the SQL Server Report Manager in Microsoft SQL Server 2000 Reporting Services SP2 and
CVE-2012-1856
all versions
The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3,
8.8HIGH
CVE-2011-1280
all versions
The XML Editor in Microsoft InfoPath 2007 SP2 and 2010; SQL Server 2005 SP3 and SP4 and 2008 SP1, SP2, and R2; SQL Server Manageme
CVE-2009-3126
all versions
Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Micros
CVE-2009-2528
all versions
GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows remote atta
CVE-2009-2504
all versions
Multiple integer overflows in unspecified APIs in GDI+ in Microsoft .NET Framework 1.1 SP1, .NET Framework 2.0 SP1 and SP2, Window
CVE-2009-2503
all versions
GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 M
CVE-2009-2502
all versions
Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microso
8.1HIGH
CVE-2009-2501
all versions
Heap-based buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2
CVE-2009-2500
all versions
Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Micros
CVE-2008-5416
all versions
Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier; SQL Server 2000 Desktop Engine (MS
CVE-2008-4110
all versions
Buffer overflow in the SQLVDIRLib.SQLVDirControl ActiveX control in Tools\Binn\sqlvdir.dll in Microsoft SQL Server 2000 (aka SQL S
CVE-2008-3015
all versions
Integer overflow in gdiplus.dll in GDI+ in Microsoft Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and
CVE-2008-3014
all versions
Buffer overflow in gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vist
CVE-2008-3013
all versions
gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Ser
CVE-2008-3012
all versions
gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Ser
CVE-2007-5348
all versions
Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1
CVE-2008-0107
all versions
Integer underflow in SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1
CVE-2008-0106
all versions
Buffer overflow in Microsoft SQL Server 2005 SP1 and SP2, and 2005 Express Edition SP1 and SP2, allows remote authenticated users
CVE-2008-0086
all versions
Buffer overflow in the convert function in Microsoft SQL Server 2000 SP4, 2000 Desktop Engine (MSDE 2000) SP4, and 2000 Desktop En
CVE-2008-0085
all versions
SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 De
CVE-2007-4814
all versions
Buffer overflow in the SQLServer ActiveX control in the Distributed Management Objects OLE DLL (sqldmo.dll) 2000.085.2004.00 in Mi
CVE-2004-1560
all versions
Microsoft SQL Server 7.0 allows remote attackers to cause a denial of service (mssqlserver service halt) via a long request to TCP
CVE-2003-0232
all versions
Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local Procedure C
CVE-2003-0231
all versions
Microsoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial of service (crash or hang) via
CVE-2003-0230
all versions
Microsoft SQL Server 7, 2000, and MSDE allows local users to gain privileges by hijacking a named pipe during the authentication o
CVE-2002-1981
all versions
Microsoft SQL Server 2000 through SQL Server 2000 SP2 allows the "public" role to execute the (1) sp_MSSetServerProperties or (2)
CVE-2002-1872
all versions
Microsoft SQL Server 6.0 through 2000, with SQL Authentication enabled, uses weak password encryption (XOR), which allows remote a
7.5HIGH
CVE-2002-1145
all versions
The xp_runwebtask stored procedure in the Web Tasks component of Microsoft SQL Server 7.0 and 2000, Microsoft Data Engine (MSDE) 1
CVE-2002-1138
all versions
Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, writes out
CVE-2002-1137
all versions
Buffer overflow in the Database Console Command (DBCC) that handles user inputs in Microsoft SQL Server 7.0 and 2000, including Mi
CVE-2002-1123
all versions
Buffer overflow in the authentication function for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows remot
CVE-2002-0982
all versions
Microsoft SQL Server 2000 SP2, when configured as a distributor, allows attackers to execute arbitrary code via the @scriptfile pa
CVE-2002-0859
all versions
Buffer overflow in the OpenDataSource function of the Jet engine on Microsoft SQL Server 2000 allows remote attackers to execute a
CVE-2002-0721
all versions
Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper fu
CVE-2002-0729
all versions
Microsoft SQL Server 2000 allows remote attackers to cause a denial of service via a malformed 0x08 packet that is missing a colon
CVE-2002-0650
all versions
The keep-alive mechanism for Microsoft SQL Server 2000 allows remote attackers to cause a denial of service (bandwidth consumption
CVE-2002-0649
all versions
Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSDE) allow r
CVE-2002-0645
all versions
SQL injection vulnerability in stored procedures for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 may allow
CVE-2002-0644
all versions
Buffer overflow in several Database Consistency Checkers (DBCCs) for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE)
CVE-2002-0643
all versions
The installation of Microsoft Data Engine 1.0 (MSDE 1.0), and Microsoft SQL Server 2000 creates setup.iss files with insecure perm
CVE-2002-0642
all versions
The registry key containing the SQL Server service account information in Microsoft SQL Server 2000, including Microsoft SQL Serve
CVE-2002-0641
all versions
Buffer overflow in bulk insert procedure of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000,
CVE-2002-0624
all versions
Buffer overflow in the password encryption function of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (M
CVE-2002-0187
all versions
Cross-site scripting vulnerability in the SQLXML component of Microsoft SQL Server 2000 allows an attacker to execute arbitrary sc
CVE-2002-0186
all versions
Buffer overflow in the SQLXML ISAPI extension of Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code via d
CVE-2002-0224
all versions
The MSDTC (Microsoft Distributed Transaction Service Coordinator) for Microsoft Windows 2000, Microsoft IIS 5.0 and SQL Server 6.5
CVE-2002-0154
all versions
Buffer overflows in extended stored procedures for Microsoft SQL Server 7.0 and 2000 allow remote attackers to cause a denial of s
CVE-2002-0057
all versions
XMLHTTP control in Microsoft XML Core Services 2.6 and later does not properly handle IE Security Zone settings, which allows remo
CVE-2002-0056
all versions
Buffer overflow in SQL Server 7.0 and 2000 allows remote attackers to execute arbitrary code via a long OLE DB provider name to (1
CVE-2001-0879
all versions
Format string vulnerability in the C runtime functions in SQL Server 7.0 and 2000 allows attackers to cause a denial of service.
CVE-2001-0542
all versions
Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow attackers with access to SQL Server to execute arbitrary code through
CVE-2001-0509
all versions
Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) W
CVE-2001-0344
all versions
An SQL query method in Microsoft SQL Server 2000 Gold and 7.0 using Mixed Mode allows local database users to gain privileges by r
CVE-2000-1088
all versions
The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the le
CVE-2000-1087
all versions
The xp_proxiedmetadata function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the l
CVE-2000-1086
all versions
The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the l
CVE-2000-1085
all versions
The xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length
CVE-2000-1084
all versions
The xp_updatecolvbm function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of
CVE-2000-1083
all versions
The xp_showcolv function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a b
CVE-2000-1082
all versions
The xp_enumresultset function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length o
CVE-2000-1081
all versions
The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the lengt
CVE-2000-0654
all versions
Microsoft Enterprise Manager allows local users to obtain database passwords via the Data Transformation Service (DTS) package Reg
CVE-2000-0603
all versions
Microsoft SQL Server 7.0 allows a local user to bypass permissions for stored procedures by referencing them via a temporary store
CVE-2000-0485
all versions
Microsoft SQL Server allows local users to obtain database passwords via the Data Transformation Service (DTS) package Properties
CVE-2000-0402
all versions
The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in plaintext in
CVE-2000-0199
all versions
When a new SQL Server is registered in Enterprise Manager for Microsoft SQL Server 7.0 and the "Always prompt for login name and p
CVE-2000-0202
all versions
Microsoft SQL Server 7.0 and Microsoft Data Engine (MSDE) 1.0 allow remote attackers to gain privileges via a malformed Select sta
CVE-1999-0999
all versions
Microsoft SQL 7.0 server allows a remote attacker to cause a denial of service via a malformed TDS packet.
CVE-1999-1556
all versions
Microsoft SQL Server 6.5 uses weak encryption for the password for the SQLExecutiveCmdExec account and stores it in an accessible
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin