4.6
CVSSv2

CVE-2000-1084

Published: 09/01/2001 Updated: 12/10/2018
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The xp_updatecolvbm function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an malicious user to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft data engine 1.0

microsoft data engine 2000

microsoft sql server 2000

microsoft sql server 7.0