Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2000-1087
Description:The xp_proxiedmetadata function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2000-1087
@stake Security Advisory: 20001201 SQL Server 2000 Extended Stored Procedure Vulnerability
http://marc.info/?l=bugtraq&m=97570884410184&w=2
BugTraq ID: 2042
http://www.securityfocus.com/bid/2042
Microsoft Security Bulletin: MS00-092
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-092




© 1998-2025 E-Soft Inc. All rights reserved.