MS-SQL
All Categories
The xp_showcolv function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
The xp_updatecolvbm function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
Multiple buffer overflows in SQL Server 2000 Resolution Service allow remote attackers to cause a denial of service or execute arbitrary code via UDP packets to port 1434 in which (1) a 0x04 byte causes the SQL Monitor thread to generate a long registry key name, or (2) a 0x08 byte with a long string causes heap corruption.
sp_start_job - program execution
xp_enumresultset possible buffer overflow
sp_password - password change
sp_delete_1 log file deletion
sp_adduser - database user creation
xp_reg* - registry access
xp_cmdshell - program execution
shellcode attempt
shellcode attempt
xp_sprintf possible buffer overflow
xp_cmdshell program execution (445)
sa login failed
ping attempt
version overflow attempt
IPS Alert Level
Low
Medium
High
Home
|
Products
|
Applications
|
Markets
|
Support
|
How to Buy
|
Channel Partners
|
Company
Comprehensive Internet Security ®
2003 SonicWALL, Inc. |
Privacy Statement