Computer Security
[EN] securityvulns.ru no-pyccku


Microsoft SQL Server multiple security vulnerabilities
Published:15.09.2014
Source:
SecurityVulns ID:13957
Type:remote
Threat Level:
6/10
Description:XSS, stack overrun.
Affected:MICROSOFT : SQL Server 2008
 MICROSOFT : SQL Server 2012
 MICROSOFT : SQL Server 2014
CVE:CVE-2014-4061 (Microsoft SQL Server 2008 SP3, 2008 R2 SP2, and 2012 SP1 does not properly control use of stack memory for processing of T-SQL batch commands, which allows remote authenticated users to cause a denial of service (daemon hang) via a crafted T-SQL statement, aka "Microsoft SQL Server Stack Overrun Vulnerability.")
 CVE-2014-1820 (Cross-site scripting (XSS) vulnerability in Master Data Services (MDS) in Microsoft SQL Server 2012 SP1 and 2014 on 64-bit platforms allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "SQL Master Data Services XSS Vulnerability.")
Files: Microsoft Security Bulletin MS14-044 - Important Vulnerabilities in SQL Server Could Allow Elevation of Privilege (2984340)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod