René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

166 lines
6.0 KiB
JSON

{
"id": "CVE-2002-0695",
"sourceIdentifier": "cve@mitre.org",
"published": "2002-08-12T04:00:00.000",
"lastModified": "2018-10-12T21:31:42.427",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Buffer overflow in the Transact-SQL (T-SQL) OpenRowSet component of Microsoft Data Access Components (MDAC) 2.5 through 2.7 for SQL Server 7.0 or 2000 allows remote attackers to execute arbitrary code via a query that calls the OpenRowSet command."
},
{
"lang": "es",
"value": "Desbordamiento de b\u00fafer en el componente Transact-SQL (T-SQL) OpenRowSet de Microsoft Data Access Components (MDAC), versiones 2.5 hasta 2.7 para SQL Server 7.0 \u00f3 2000 permite que atacantes remotos ejecuten c\u00f3digo arbitrario por medio de una sentencia que llama al comando OpenRowSet."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": true,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:data_access_components:1.5:*:*:*:*:*:*:*",
"matchCriteriaId": "1B1985AB-FCAB-4ABC-BF03-9E11CD015596"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:data_access_components:2.0:*:*:*:*:*:*:*",
"matchCriteriaId": "0D331DB4-AA55-4E1B-8B73-14EE2F13E09E"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:data_access_components:2.1:*:*:*:*:*:*:*",
"matchCriteriaId": "A3BFD086-7F94-4482-AC27-E4FAD418B767"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:data_access_components:2.1.1.3711.11:ga:*:*:*:*:*:*",
"matchCriteriaId": "ADD39E09-B345-4796-9C67-B2087F806988"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:data_access_components:2.5:*:*:*:*:*:*:*",
"matchCriteriaId": "49A5B686-0B8A-4904-8166-24D899D24ED5"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:data_access_components:2.5:gold:*:*:*:*:*:*",
"matchCriteriaId": "092A2E97-C8C4-4F4F-9EC1-70E64DF0052D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:data_access_components:2.5:sp1:*:*:*:*:*:*",
"matchCriteriaId": "950834D8-A6CE-4636-9ABC-47528001983D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:data_access_components:2.5:sp2:*:*:*:*:*:*",
"matchCriteriaId": "0D819A49-C10C-47C8-8A82-6CAE4FD5396D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:data_access_components:2.6:*:*:*:*:*:*:*",
"matchCriteriaId": "01EAE3CC-D507-40A4-9198-873EE0E3DCE2"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:data_access_components:2.6:gold:*:*:*:*:*:*",
"matchCriteriaId": "CE28EB73-C986-4184-9C82-AC55432B3BA9"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:data_access_components:2.6:sp1:*:*:*:*:*:*",
"matchCriteriaId": "9BA9FEED-B40F-4673-B9D0-265B4BDC6411"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:data_access_components:2.6:sp2:*:*:*:*:*:*",
"matchCriteriaId": "7B11B6C6-D76E-4B6D-9792-89DE5569EA8D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:data_access_components:2.7:*:*:*:*:*:*:*",
"matchCriteriaId": "307B13E2-EB93-420B-B47E-0681864DC429"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:data_access_components:2.7:gold:*:*:*:*:*:*",
"matchCriteriaId": "6FC21845-6911-4FA4-9B9A-19F533ED3E1A"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:data_access_components:2.12.4202.3:*:*:*:*:*:*:*",
"matchCriteriaId": "D627CFF6-F877-48CB-8C86-F8EF961C08C0"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:microsoft_data_access_components:2.12.4292.3_ga_clean:*:*:*:*:*:*:*",
"matchCriteriaId": "2ADFE032-610E-4009-A29D-9E4E64A2427E"
}
]
}
]
}
],
"references": [
{
"url": "http://www.iss.net/security_center/static/9734.php",
"source": "cve@mitre.org"
},
{
"url": "http://www.nextgenss.com/advisories/mssql-ors.txt",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/5372",
"source": "cve@mitre.org"
},
{
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-040",
"source": "cve@mitre.org"
}
]
}