Data Engine

Vendor:

First CVE: Mar 8, 2000 · Active for 26 years

26
Total CVEs
More Total CVEs than 95% of tracked products
5.2
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 33% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Data Engine over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 8, 2000
26 years ago
Most Recent CVE
Jul 8, 2008
6,590 days ago

CVE Severity & Scoring

Data Engine26 CVEs
All CVEs352,294 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown26 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown26 (100.0%)
User Interaction
None0 (0.0%)
Unknown26 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown26 (100.0%)

Top CVEs

Signals from CVEs in this product scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that
Aug 12, 200210.089NOYES
Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSDE) allow remote attackers to cause a denial of service or ex
Aug 12, 20027.584NOYES
Buffer overflow in the authentication function for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows remote attackers to execute arbitrary code via a long r
Sep 24, 20027.578NOYES
Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could allow unprivileged users, and
Sep 5, 200210.061NOYES
Buffer overflow in the convert function in Microsoft SQL Server 2000 SP4, 2000 Desktop Engine (MSDE 2000) SP4, and 2000 Desktop Engine (WMSDE) allows remote authenticated users to
Jul 8, 20089.058NONO
Microsoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial of service (crash or hang) via a long request to a named pipe.
Aug 27, 20035.040NOYES
Buffer overflow in Microsoft SQL Server 2005 SP1 and SP2, and 2005 Express Edition SP1 and SP2, allows remote authenticated users to execute arbitrary code via a crafted insert sta
Jul 8, 20089.039NONO
Integer underflow in SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE); Microso
Jul 8, 20089.039NONO
Buffer overflow in several Database Consistency Checkers (DBCCs) for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows members of the db_owner and db_ddladm
Aug 12, 20027.539NOYES
Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local Procedure Calls (LPC) port that leads to a buffer overflow.
Aug 27, 20037.235NOYES

Exploit Exposure

Signals from CVEs in this product scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
11.5% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
10 CVEs
38.5% of CVEs· 91st percentile

Social Chatter

Signals from CVEs in this product scope (26 CVEs).

Media Mentions

Signals from CVEs in this product scope (26 CVEs).

Top CNAs Publishing CVEs For Data Engine

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2000166.217.3%07
1.0226.517.4%07