VulnSea

sql_server_2017 vulnerabilities

CVEs whose affected-version data names the sql_server_2017 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

42 CVEsRSS

CVE-2026-67384High· 8.8
2w ago

Integer overflow or wraparound in SQL Server allows an authorized attacker to execute code over a network.

Integer overflow or wraparound in SQL Server allows an authorized attacker to execute code over a network.

Twilightmicrosoft · sql_server_2017EPSS 0.62%via NVD
CVE-2026-67381High· 8.8
2w ago

Heap-based buffer overflow in SQL Server allows an authorized attacker to elevate privileges over a network.

Heap-based buffer overflow in SQL Server allows an authorized attacker to elevate privileges over a network.

Twilightmicrosoft · sql_server_2017EPSS 0.49%via NVD
CVE-2026-67380High· 8.8
2w ago

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Twilightmicrosoft · sql_server_2017EPSS 0.68%via NVD
CVE-2026-67376High· 7.5
2w ago

Integer overflow or wraparound in SQL Server allows an unauthorized attacker to deny service over a network.

Integer overflow or wraparound in SQL Server allows an unauthorized attacker to deny service over a network.

Twilightmicrosoft · sql_server_2017EPSS 0.82%via NVD
CVE-2026-67370High· 8.8
2w ago

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

Twilightmicrosoft · sql_server_2017EPSS 0.67%via NVD
CVE-2026-67368High· 8.8
2w ago

Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network.

Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network.

Twilightmicrosoft · sql_server_2017EPSS 0.70%via NVD
CVE-2026-66820High· 8.8
2w ago

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

Twilightmicrosoft · sql_server_2017EPSS 0.53%via NVD
CVE-2026-66819High· 8.8
2w ago

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

Twilightmicrosoft · sql_server_2017EPSS 0.73%via NVD
CVE-2026-66818High· 8.8
2w ago

Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network.

Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network.

Twilightmicrosoft · sql_server_2017EPSS 0.57%via NVD
CVE-2026-66814High· 8.8
2w ago

Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Twilightmicrosoft · sql_server_2017EPSS 0.42%via NVD
CVE-2026-47296High· 7.8
2mo ago

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.

Twilightmicrosoft · sql_server_2016EPSS 0.50%via NVD
CVE-2026-21262High· 8.8
6mo ago

Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Twilightmicrosoft · sql_server_2016EPSS 2.0%via NVD
sql_server_2017 vulnerabilities (CVEs) — page 2 · VulnSea