Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Microsoft SQL Server Number Of NVD 107 CRITICAL 0 HIGH 74 MEDIUM 30 LOW 3
URL https://www.microsoft.com/ja-jp/sql-server/
Explanation It is a relational database management system (RDBMS) provided by Microsoft, and like other Windows products, it can be operated in various ways from the GUI (screen).
The support end date depends on the service pack provided.
If a new service pack is provided, the old service pack will be supported for 12 months.
Tag
  • 商用ライセンス有り

Add Information URL
No Type Name URL
1 https://support.microsoft.com/ja-jp/lifecycle/search?alpha=SQL%20Server
2 https://sqlserverbuilds.blogspot.com/
3 https://learn.microsoft.com/ja-jp/lifecycle/policies/fixed

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
101 SQL Server 2022 2022 Nov. 16, 2022 Jan. 11, 2028 Jan. 11, 2033 0 18 1 0
102 SQL Server 2019 2019 Nov. 4, 2019 Jan. 7, 2025 Jan. 8, 2030 0 20 1 0
103 SQL Server 2014 Service Pack 3 2014 Oct. 30, 2018 July 9, 2019 July 9, 2024 0 15 3 0
104 SQL Server 2016 Service Pack 2 2016 April 24, 2018 July 13, 2021 July 14, 2026 0 13 3 0
105 SQL Server 2017 2017 Sept. 29, 2017 Oct. 11, 2022 Oct. 12, 2027 0 9 2 0
106 SQL Server 2012 Service Pack 4 2012 July 11, 2017 July 12, 2022 0 12 4 0
107 SQL Server 7.0 7.0 Jan. 1, 2000 0 16 17 3
108 SQL Server 6.5 6.5 Jan. 1, 2000 0 2 1 1
109 SQL Server 6.0 6.0 Jan. 1, 2000 0 1 0 0
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
101 -
4.6
MEDIUM Microsoft SQL Server 7.0 allows a local user to bypass permissions for stored procedures by referencing them via a temporary stored procedure, aka the "Stored Procedure Permissions" vulnerability. NVD-CWE-Other
CVE-2000-0603 cpe:2.3:a:microsoft:sql_server:7.0:* 2018-10-13 06:29
2000-07-7
Show GitHub Exploit DB Packet Storm
102 -
2.1
LOW The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in plaintext in a log file which is readable by any user, aka the "SQL Server 7.0 Ser… NVD-CWE-Other
CVE-2000-0402 cpe:2.3:a:microsoft:sql_server:7.0:sp2
cpe:2.3:a:microsoft:sql_server:7.0:sp1
cpe:2.3:a:microsoft:sql_server:7.0:*
2018-10-13 06:29
2000-05-30
Show GitHub Exploit DB Packet Storm
103 -
2.1
LOW Microsoft SQL Server allows local users to obtain database passwords via the Data Transformation Service (DTS) package Properties dialog, aka the "DTS Password" vulnerability. NVD-CWE-Other
CVE-2000-0485 cpe:2.3:a:microsoft:sql_server:7.0:*
cpe:2.3:a:microsoft:sql_server:6.5:*
2018-10-13 06:29
2000-05-30
Show GitHub Exploit DB Packet Storm
104 -
7.2
HIGH When a new SQL Server is registered in Enterprise Manager for Microsoft SQL Server 7.0 and the "Always prompt for login name and password" option is not set, then the Enterprise Manager uses weak enc… NVD-CWE-Other
CVE-2000-0199 cpe:2.3:a:microsoft:sql_server:7.0:* 2008-09-11 04:03
2000-03-14
Show GitHub Exploit DB Packet Storm
105 -
7.5
HIGH Microsoft SQL Server 7.0 and Microsoft Data Engine (MSDE) 1.0 allow remote attackers to gain privileges via a malformed Select statement in an SQL query. NVD-CWE-Other
CVE-2000-0202 cpe:2.3:a:microsoft:sql_server:7.0:* 2018-10-13 06:29
2000-03-8
Show GitHub Exploit DB Packet Storm
106 -
4.3
MEDIUM Microsoft SQL 7.0 server allows a remote attacker to cause a denial of service via a malformed TDS packet. CWE-20
 Improper Input Validation 
CVE-1999-0999 cpe:2.3:a:microsoft:sql_server:7.0:* 2023-11-7 10:55
1999-11-19
Show GitHub Exploit DB Packet Storm
107 -
7.2
HIGH Microsoft SQL Server 6.5 uses weak encryption for the password for the SQLExecutiveCmdExec account and stores it in an accessible portion of the registry, which could allow local users to gain privil… NVD-CWE-Other
CVE-1999-1556 cpe:2.3:a:microsoft:sql_server:6.5:* 2017-10-10 10:29
1998-06-29
Show GitHub Exploit DB Packet Storm