Back
CVE-2001-0542
Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow attackers with access to SQL Server to execute arbitrary code through the functions (1) raiserror, (2) formatmessage, or (3) xp_sprintf. NOTE: the C runtime format string vulnerability reported in MS01-060 is identified by CVE-2001-0879.
Published: Dec 20, 2001
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (2)
| Vendor | Product | Version |
|---|---|---|
| microsoft | sql_server | 7.0 |
| microsoft | sql_server | 2000 |
GitHub Security Advisory GHSA-w7gq-qfwh-xj2g
Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow attackers with access to SQL Server...
References (14)
- http://marc.info/?l=bugtraq&m=100891252317406&w=2
- http://www.atstake.com/research/advisories/2001/a122001-1.txt Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/700575 US Government Resource
- http://www.securityfocus.com/bid/3733 Patch, Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-060
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7724
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A83
- http://marc.info/?l=bugtraq&m=100891252317406&w=2
- http://www.atstake.com/research/advisories/2001/a122001-1.txt Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/700575 US Government Resource
- http://www.securityfocus.com/bid/3733 Patch, Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-060
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7724
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A83
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
13.62%
Top 4% most likely to be exploited
Threat Score
34.1 / 100
Data Sources
NVD
EPSS
GitHub