sql_server_2019_gdr vulnerabilities
CVEs whose affected-version data names the sql_server_2019_gdr package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
10 CVEsRSS
CVE-2026-78442High· 8.8Heap-based buffer overflow in Windows OLE DB allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Windows OLE DB allows an unauthorized attacker to execute code over a network.
CVE-2026-78441Medium· 6.5Out-of-bounds read in Windows OLE DB allows an unauthorized attacker to disclose information over a network.
Out-of-bounds read in Windows OLE DB allows an unauthorized attacker to disclose information over a network.
CVE-2026-69562Medium· 6.5Out-of-bounds read in SQL Server allows an unauthorized attacker to disclose information over a network.
Out-of-bounds read in SQL Server allows an unauthorized attacker to disclose information over a network.
CVE-2026-67630Medium· 6.5Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-67629Medium· 6.5Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-67624Medium· 6.5Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-47297High· 8.1Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
CVE-2026-55002High· 8.8Microsoft SQL Server Elevation of Privilege Vulnerability
External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-54118Critical· 9.8Microsoft SQL Server Remote Code Execution Vulnerability
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
CVE-2026-47295High· 8.8Microsoft SQL Server Elevation of Privilege Vulnerability
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.