CVE-2008-4110: Buffer Overflow
Buffer overflow in the SQLVDIRLib.SQLVDirControl ActiveX control in Tools\Binn\sqlvdir.dll in Microsoft SQL Server 2000 (aka SQL Server 8.0) allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a long URL in the second argument to the Connect method. NOTE: this issue is not a vulnerability in many environments, since the control is not marked as safe for scripting and would not execute with default Internet Explorer settings.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4110?
CVE-2008-4110 has a high severity due to its potential for remote code execution and denial of service.
How do I fix CVE-2008-4110?
To fix CVE-2008-4110, you should apply the latest security patches provided by Microsoft for SQL Server 2000.
What software is affected by CVE-2008-4110?
CVE-2008-4110 affects Microsoft SQL Server 2000, also known as SQL Server 8.0.
What type of attack is possible due to CVE-2008-4110?
CVE-2008-4110 allows remote attackers to exploit a buffer overflow, potentially crashing the browser or executing arbitrary code.
When was CVE-2008-4110 disclosed?
CVE-2008-4110 was disclosed in 2008.