VulnSea

sql_server_2017 vulnerabilities

CVEs whose affected-version data names the sql_server_2017 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

42 CVEsRSS

CVE-2026-77488Medium· 5.5
1w ago

Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally.

Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally.

Sunlitmicrosoft · sql_server_2017EPSS 0.30%via NVD
CVE-2026-77487High· 8.8
1w ago

Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Twilightmicrosoft · sql_server_2017EPSS 0.53%via NVD
CVE-2026-77486High· 8.8
1w ago

Integer overflow or wraparound in SQL Server allows an unauthorized attacker to execute code over a network.

Integer overflow or wraparound in SQL Server allows an unauthorized attacker to execute code over a network.

Twilightmicrosoft · sql_server_2017EPSS 0.55%via NVD
CVE-2026-77485High· 7.0
1w ago

Use after free in SQL Server allows an authorized attacker to elevate privileges locally.

Use after free in SQL Server allows an authorized attacker to elevate privileges locally.

Twilightmicrosoft · sql_server_2017EPSS 0.20%via NVD
CVE-2026-77483High· 8.8
1w ago

Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network.

Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network.

Twilightmicrosoft · sql_server_2017EPSS 0.53%via NVD
CVE-2026-77482High· 8.8
1w ago

Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.

Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.

Twilightmicrosoft · sql_server_2017EPSS 0.75%via NVD
CVE-2026-77481High· 8.8
1w ago

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Twilightmicrosoft · sql_server_2017EPSS 0.62%via NVD
CVE-2026-77480High· 8.8
1w ago

Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Twilightmicrosoft · sql_server_2017EPSS 0.53%via NVD
CVE-2026-73028High· 8.8
1w ago

Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Twilightmicrosoft · sql_server_2017EPSS 0.53%via NVD
CVE-2026-68787High· 7.8
1w ago

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code locally.

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code locally.

Twilightmicrosoft · sql_server_2017EPSS 0.24%via NVD
CVE-2026-68786High· 8.8
1w ago

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Twilightmicrosoft · sql_server_2017EPSS 0.49%via NVD
CVE-2026-68785Medium· 4.9
1w ago

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Sunlitmicrosoft · sql_server_2017EPSS 0.78%via NVD
CVE-2026-68784Medium· 6.5
1w ago

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Sunlitmicrosoft · sql_server_2017EPSS 0.71%via NVD
CVE-2026-68781Medium· 6.5
1w ago

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Sunlitmicrosoft · sql_server_2017EPSS 0.71%via NVD
CVE-2026-68780Medium· 6.5
1w ago

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Sunlitmicrosoft · sql_server_2017EPSS 0.74%via NVD
CVE-2026-68779Medium· 6.5
1w ago

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Sunlitmicrosoft · sql_server_2017EPSS 0.55%via NVD
CVE-2026-68778Medium· 6.5
1w ago

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Sunlitmicrosoft · sql_server_2017EPSS 0.74%via NVD
CVE-2026-68777Medium· 6.5
1w ago

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Sunlitmicrosoft · sql_server_2017EPSS 0.74%via NVD
CVE-2026-68776Medium· 6.5
1w ago

Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.

Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.

Sunlitmicrosoft · sql_server_2017EPSS 0.55%via NVD
CVE-2026-68775High· 8.8
1w ago

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Twilightmicrosoft · sql_server_2017EPSS 0.49%via NVD
CVE-2026-67648Medium· 6.5
1w ago

Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.

Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.

Sunlitmicrosoft · sql_server_2017EPSS 0.55%via NVD
CVE-2026-67645Medium· 6.5
1w ago

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Sunlitmicrosoft · sql_server_2017EPSS 0.55%via NVD
CVE-2026-67639High· 8.8
1w ago

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Twilightmicrosoft · sql_server_2017EPSS 0.68%via NVD
CVE-2026-67633Medium· 6.5
1w ago

Out-of-bounds read in SQL Server allows an authorized attacker to deny service over a network.

Out-of-bounds read in SQL Server allows an authorized attacker to deny service over a network.

Sunlitmicrosoft · sql_server_2017EPSS 0.79%via NVD
CVE-2026-67631Critical· 9.8
1w ago

Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.

Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.

Midnightmicrosoft · sql_server_2017EPSS 0.67%via NVD
CVE-2026-67393Medium· 6.5
1w ago

Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.

Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.

Sunlitmicrosoft · sql_server_2017EPSS 0.74%via NVD
CVE-2026-67390Medium· 6.5
1w ago

Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.

Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.

Sunlitmicrosoft · sql_server_2017EPSS 0.95%via NVD
CVE-2026-67388High· 8.8
1w ago

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Twilightmicrosoft · sql_server_2017EPSS 0.49%via NVD
CVE-2026-67386Medium· 6.5
1w ago

Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.

Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.

Sunlitmicrosoft · sql_server_2017EPSS 0.71%via NVD
CVE-2026-67385High· 8.8
1w ago

Use after free in SQL Server allows an authorized attacker to execute code over a network.

Use after free in SQL Server allows an authorized attacker to execute code over a network.

Twilightmicrosoft · sql_server_2017EPSS 0.49%via NVD
sql_server_2017 vulnerabilities (CVEs) · VulnSea