Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2014-4061 | First vendor Publication | 2014-08-12 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:S/C:N/I:N/A:C) | |||
---|---|---|---|
Cvss Base Score | 6.8 | Attack Range | Network |
Cvss Impact Score | 6.9 | Attack Complexity | Low |
Cvss Expoit Score | 8 | Authentication | Requires single instance |
Calculate full CVSS 2.0 Vectors scores |
Detail
Microsoft SQL Server 2008 SP3, 2008 R2 SP2, and 2012 SP1 does not properly control use of stack memory for processing of T-SQL batch commands, which allows remote authenticated users to cause a denial of service (daemon hang) via a crafted T-SQL statement, aka "Microsoft SQL Server Stack Overrun Vulnerability." |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4061 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-399 | Resource Management Errors |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:26287 | |||
Oval ID: | oval:org.mitre.oval:def:26287 | ||
Title: | Microsoft SQL Server stack overrun vulnerability - CVE-2014-4061 (MS14-044) | ||
Description: | Microsoft SQL Server 2008 SP3, 2008 R2 SP2, and 2012 SP1 does not properly control use of stack memory for processing of T-SQL batch commands, which allows remote authenticated users to cause a denial of service (daemon hang) via a crafted T-SQL statement, aka "Microsoft SQL Server Stack Overrun Vulnerability." | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2014-4061 | Version: | 5 |
Platform(s): | Microsoft Windows 7 Microsoft Windows 8 Microsoft Windows 8.1 Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Server 2008 R2 Microsoft Windows Server 2012 Microsoft Windows Server 2012 R2 Microsoft Windows Vista Microsoft Windows XP | Product(s): | Microsoft SQL Server 2008 Microsoft SQL Server 2008 R2 Microsoft SQL Server 2012 |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2014-08-14 | IAVM : 2014-A-0126 - Multiple Vulnerabilities in Microsoft SQL Server Severity : Category II - VMSKEY : V0053801 |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2014-08-12 | Name : A cross-site scripting vulnerability in SQL Server could allow an elevation o... File : smb_kb2984340.nasl - Type : ACT_GATHER_INFO |
2014-08-12 | Name : A cross-site scripting vulnerability in SQL Server could allow an elevation o... File : smb_nt_ms14-044.nasl - Type : ACT_GATHER_INFO |
2003-01-26 | Name : The remote host has a database server installed. File : mssql_version.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 12:41:18 |
|
2021-05-04 12:32:30 |
|
2021-04-22 01:39:46 |
|
2020-05-23 00:41:20 |
|
2018-10-13 05:18:47 |
|
2017-01-07 09:25:37 |
|
2015-10-18 17:22:40 |
|
2014-08-14 00:21:16 |
|
2014-08-13 13:24:54 |
|
2014-08-13 05:22:38 |
|