SQL Server
by Microsoft
CVEs (321)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-68778 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-68777 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-68776 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-67648 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-67645 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-67641 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | Integer overflow or wraparound in SQL Server allows an authorized attacker to deny service over a network. | ||
| CVE-2026-67633 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to deny service over a network. | ||
| CVE-2026-67630 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-67629 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-67624 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-67393 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-67390 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-67389 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-67386 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-67383 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-67369 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-66816 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network. | ||
| CVE-2025-47997 | Med | 0.42 | 6.5 | 0.01 | Sep 9, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to disclose information over a network. | ||
| CVE-2016-7251 | Med | 0.40 | 6.1 | 0.08 | Nov 10, 2016 | Cross-site scripting (XSS) vulnerability in the MDS API in Microsoft SQL Server 2016 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "MDS API XSS Vulnerability." | ||
| CVE-2026-77488 | Med | 0.36 | 5.5 | 0.00 | Sep 8, 2026 | Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally. |
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Integer overflow or wraparound in SQL Server allows an authorized attacker to deny service over a network.
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in SQL Server allows an authorized attacker to deny service over a network.
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network.
- risk 0.42cvss 6.5epss 0.01
Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to disclose information over a network.
- risk 0.40cvss 6.1epss 0.08
Cross-site scripting (XSS) vulnerability in the MDS API in Microsoft SQL Server 2016 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "MDS API XSS Vulnerability."
- risk 0.36cvss 5.5epss 0.00
Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally.
Page 12 of 17