VDB
CVE-2002-0624
CVE-2002-0624
PUBLISHED
CVSS 7.5 HIGH
Buffer overflow in the password encryption function of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows remote attackers to gain control of the database and execute arbitrary code via SQL Server Authentication, aka "Unchecked Buffer in Password Encryption Procedure."
EPSS 5.43% · 90.3th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
5.43%
90.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| microsoft | sql_server | 2000 |
| microsoft | msde | 2000 |
| n/a | n/a | n/a |
Timeline
- Jul 12, 2002 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 10, 2023 EPSS Score
- May 26, 2023 EPSS Score
References
- oval:org.mitre.oval:def:291 vdb
- CA-2002-22 third-party-advisory
- MS02-034 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2002-0624 advisory