peter bassill · operator
$ cve CVE-2002-0624 JSON

CVE-2002-0624 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 22.8% (pctl 98)

Patch early

A public exploit exists.

Description

Buffer overflow in the password encryption function of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows remote attackers to gain control of the database and execute arbitrary code via SQL Server Authentication, aka "Unchecked Buffer in Password Encryption Procedure."

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS22.85% — more likely to be exploited than 98% of all CVEs
On CISA KEVno
Public exploityes
Published2002-07-23
Last modified2026-06-16

Affected (2)

VendorProduct
microsoftmsde
microsoftsql server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD