Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2000-1084
Description:The xp_updatecolvbm function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2000-1084
@stake Security Advisory: 20001201 Microsoft SQL Server extended stored procedure vulnerability
http://marc.info/?l=bugtraq&m=97570878710037&w=2
BugTraq ID: 2039
http://www.securityfocus.com/bid/2039
Microsoft Security Bulletin: MS00-092
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-092




© 1998-2025 E-Soft Inc. All rights reserved.