Back

CVE-2001-0542

Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow attackers with access to SQL Server to execute arbitrary code through the functions (1) raiserror, (2) formatmessage, or (3) xp_sprintf. NOTE: the C runtime format string vulnerability reported in MS01-060 is identified by CVE-2001-0879.

Published: Dec 20, 2001 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
microsoft sql_server 7.0
microsoft sql_server 2000

GitHub Security Advisory GHSA-w7gq-qfwh-xj2g

Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow attackers with access to SQL Server...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 13.62%

Top 4% most likely to be exploited

Threat Score 34.1 / 100

Data Sources

NVD EPSS GitHub