9
CVSSv2

CVE-2008-0107

Published: 08/07/2008 Updated: 26/02/2019
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

Integer underflow in SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE); Microsoft Data Engine (MSDE) 1.0 SP4; and Internal Database (WYukon) SP2 allows remote authenticated users to execute arbitrary code via a (1) SMB or (2) WebDAV pathname for an on-disk file (aka stored backup file) with a crafted record size value, which triggers a heap-based buffer overflow, aka "SQL Server Memory Corruption Vulnerability."

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft sql server 7.0

microsoft sql server 2000

microsoft sql server 2005

microsoft sql server desktop engine 2000

microsoft data engine 1.0

microsoft wmsde 2000

microsoft wyukon

microsoft windows_server_2008