CVE
- Id
- 3355
- CVE No.
- CVE-2001-0542
- Status
- Candidate
- Description
- Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow attackers with access to SQL Server to execute arbitrary code through the functions (1) raiserror, (2) formatmessage, or (3) xp_sprintf. NOTE: the C runtime format string vulnerability reported in MS01-060 is identified by CVE-2001-0879.
- Phase
- Modified (20061101)
- Votes
- ACCEPT(5) Baker, Cole, Frech, Green, Wall | NOOP(1) Foat
- Comments