Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2008-0107

EPSS 57.27% · P98
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2008-0107

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Integer underflow in SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE); Microsoft Data Engine (MSDE) 1.0 SP4; and Internal Database (WYukon) SP2 allows remote authenticated users to execute arbitrary code via a (1) SMB or (2) WebDAV pathname for an on-disk file (aka stored backup file) with a crafted record size value, which triggers a heap-based buffer overflow, aka "SQL Server Memory Corruption Vulnerability."
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Microsoft SQL Server磁盘数据结构整数溢出漏洞(MS08-040)
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Microsoft SQL Server是一款流行的SQL数据库系统。 如果要利用这个漏洞,攻击者必须能够诱骗服务器加载特制的备份文件,可通过提交到远程文件的路径或使用SMB/WebDAV来实现。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2008-0107

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2008-0107

登录查看更多情报信息。

Same Patch Batch · n/a · 2008-07-08 · 15 CVEs total

CVE-2008-1447ISC BIND 安全特征问题漏洞
CVE-2008-0085Microsoft SQL Server信息泄露及缓冲区溢出漏洞(MS08-040)
CVE-2008-0086Microsoft SQL Server信息泄露及缓冲区溢出漏洞(MS08-040)
CVE-2008-0106Microsoft SQL Server信息泄露及缓冲区溢出漏洞(MS08-040)
CVE-2008-1435Windows资源管理器保存搜索文件远程代码执行漏洞(MS08-038)
CVE-2008-1454Microsoft Windows DNS服务器缓存中毒漏洞(MS08-037)
CVE-2008-2247Outlook Web Access for Exchange Server邮件字段跨站脚本漏洞
CVE-2008-2248Outlook Web Access for Exchange Server邮件字段跨站脚本漏洞(MS08-039)
CVE-2008-2809Mozilla Firefox 证书处理欺骗漏洞
CVE-2008-3069MyBB 多文件跨站攻击漏洞
CVE-2008-3070mybb inc/datahandler/user.php SQL注入漏洞
CVE-2008-3071mybb 'class_language'路径遍历漏洞
CVE-2008-3072Simple Machine Forum Random Generator Seeding 安全漏洞
CVE-2008-3073Simple Machine Forum html-tag XSS跨站漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2008-0107

No comments yet


Leave a comment