VYPR

SQL Server Management Studio

by Microsoft

CVEs (7)

  • CVE-2025-29803HigApr 12, 2025
    risk 0.47cvss 7.3epss 0.01

    Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate privileges locally.

  • CVE-2019-1376MedOct 10, 2019
    risk 0.43cvss 6.5epss 0.05

    An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when it improperly enforces permissions, aka 'SQL Server Management Studio Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1313.

  • CVE-2019-1313MedOct 10, 2019
    risk 0.43cvss 6.5epss 0.05

    An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when it improperly enforces permissions, aka 'SQL Server Management Studio Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1376.

  • CVE-2018-8533MedOct 10, 2018
    risk 0.41cvss 5.5epss 0.23

    An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing malicious XML content containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This affects SQL Server…

  • CVE-2018-8532MedOct 10, 2018
    risk 0.41cvss 5.5epss 0.23

    An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XMLA file containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This affects SQL Server…

  • CVE-2018-8527MedOct 10, 2018
    risk 0.41cvss 5.5epss 0.23

    An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XEL file containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This affects SQL Server…

  • CVE-2020-1455MedAug 17, 2020
    risk 0.35cvss 5.3epss 0.01

    A denial of service vulnerability exists when Microsoft SQL Server Management Studio (SSMS) improperly handles files. An attacker could exploit the vulnerability to trigger a denial of service. To exploit the vulnerability, an attacker would first require execution on the victim…