Unrated severityNVD Advisory· Published Aug 12, 2002· Updated Apr 16, 2026
CVE-2002-0649
CVE-2002-0649
Description
Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSDE) allow remote attackers to cause a denial of service or execute arbitrary code via UDP packets to port 1434 in which (1) a 0x04 byte that causes the SQL Monitor thread to generate a long registry key name, or (2) a 0x08 byte with a long string causes heap corruption, as exploited by the Slammer/Sapphire worm.
Affected products
4cpe:2.3:a:microsoft:sql_server:2000:sp2:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:microsoft:sql_server:2000:sp2:*:*:*:*:*:*
- cpe:2.3:a:microsoft:sql_server:2000:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:sql_server:2000:sp1:*:*:*:*:*:*
- cpe:2.3:a:microsoft:data_engine:2000:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
23- secunia.com/advisories/7945nvdVendor Advisory
- www.cert.org/advisories/CA-2002-22.htmlnvdUS Government Resource
- www.cert.org/advisories/CA-2003-04.htmlnvdUS Government Resource
- www.kb.cert.org/vuls/id/399260nvdUS Government Resource
- www.kb.cert.org/vuls/id/484891nvdUS Government Resource
- marc.infonvd
- marc.infonvd
- www.securityfocus.com/archive/1/308306/30/26180/threadednvd
- www.securityfocus.com/archive/1/308321/30/26180/threadednvd
- www.securityfocus.com/archive/1/308324/30/26180/threadednvd
- www.securityfocus.com/archive/1/308388/30/26180/threadednvd
- www.securityfocus.com/archive/1/308393/30/26180/threadednvd
- www.securityfocus.com/archive/1/308396/30/26150/threadednvd
- www.securityfocus.com/archive/1/308418/30/26150/threadednvd
- www.securityfocus.com/archive/1/308419/30/26150/threadednvd
- www.securityfocus.com/archive/1/308760/30/26120/threadednvd
- www.securityfocus.com/archive/1/308806/30/26120/threadednvd
- www.securityfocus.com/archive/1/309096/30/26120/threadednvd
- www.securityfocus.com/archive/1/309324/30/26120/threadednvd
- www.securityfocus.com/archive/1/309776/30/26090/threadednvd
- www.securityfocus.com/bid/5310nvd
- docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-039nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1077nvd
News mentions
0No linked articles in our index yet.