VDB

CVE-2002-0649

CVE-2002-0649 PUBLISHED CVSS 7.5 HIGH

Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSDE) allow remote attackers to cause a denial of service or execute arbitrary code via UDP packets to port 1434 in which (1) a 0x04 byte that causes the SQL Monitor thread to generate a long registry key name, or (2) a 0x08 byte with a long string causes heap corruption, as exploited by the Slammer/Sapphire worm.

EPSS 86.09% · 99.4th percentile

Risk Scores

CVSS 2.0
7.5
EPSS Score
86.09%
99.4th percentile

Affected Products

VendorProductVersions
microsoftdata_engine2000, 2000, 2000
microsoftsql_server2000, 2000, 2000
n/an/an/a, n/a

Timeline

  • CVE Published
  • Aug 1, 2003 VulnCheck KEV Exploitation
  • Apr 30, 2010 PoC Published
  • Sep 23, 2010 PoC Published
  • May 29, 2018 PoC Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Oct 27, 2022 EPSS Score
  • Feb 9, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›