CVE Vulnerabilities

CVE-2001-0542

Published: Dec 20, 2001 | Modified: Oct 12, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow attackers with access to SQL Server to execute arbitrary code through the functions (1) raiserror, (2) formatmessage, or (3) xp_sprintf. NOTE: the C runtime format string vulnerability reported in MS01-060 is identified by CVE-2001-0879.

Affected Software

Name Vendor Start Version End Version
Sql_server Microsoft 7.0 (including) 7.0 (including)
Sql_server Microsoft 2000 (including) 2000 (including)

References