← Vulnerability feed

Vulnerability record · CVE-2008-0085 · published 8 July 2008

CVE-2008-0085: Microsoft data engine information exposure vulnerability

Microsoft · Data Engine

SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE); Microsoft Data Engine (MSDE) 1.0 SP4; and Internal Database (WYukon) SP2 does not initialize memory pages when reallocating memory, which allows database operators to obtain sensitive information (database contents) via unknown vectors related to memory page reuse.

5.0 CVSS 2.0 Medium EPSS 11% · top 4.3% CWE-200 · Information exposure
5.0CVSS 2.0 base score
11%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
18References
16 Jun 2026Last modified by NVD

Description

SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE); Microsoft Data Engine (MSDE) 1.0 SP4; and Internal Database (WYukon) SP2 does not initialize memory pages when reallocating memory, which allows database operators to obtain sensitive information (database contents) via unknown vectors related to memory page reuse.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://secunia.com/advisories/30970 Vendor Advisory
http://www.securityfocus.com/archive/1/516397/100/0/threaded Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1020441 Third Party AdvisoryVDB Entry
http://www.us-cert.gov/cas/techalerts/TA08-190A.html Third Party AdvisoryUS Government Resource
http://www.vmware.com/security/advisories/VMSA-2011-0003.html PatchThird Party Advisory
http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html Third Party Advisory
http://www.vupen.com/english/advisories/2008/2022/references Broken Link
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-040 PatchVendor Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14213 Third Party Advisory
http://secunia.com/advisories/30970 Vendor Advisory
http://www.securityfocus.com/archive/1/516397/100/0/threaded Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1020441 Third Party AdvisoryVDB Entry
http://www.us-cert.gov/cas/techalerts/TA08-190A.html Third Party AdvisoryUS Government Resource
http://www.vmware.com/security/advisories/VMSA-2011-0003.html PatchThird Party Advisory
http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html Third Party Advisory
http://www.vupen.com/english/advisories/2008/2022/references Broken Link
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-040 PatchVendor Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14213 Third Party Advisory

Track CVE-2008-0085 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-0618Microsoft SQL Server Reporting Services ViewState deserialization RCESQL Server Reporting Services mishandles page requests, allowing untrusted ViewState data to be deserialized (CWE-502). An authenticated attacker can…KEVEPSS 99%analysed8.8CVE-2019-1068Microsoft SQL Server improper input validation remote code executionMicrosoft SQL Server mishandles processing of internal functions, allowing an authenticated remote attacker to execute code on the database server. T…KEVEPSS 58%analysed8.8CVE-2012-1856Microsoft Office MSCOMCTL.OCX TabStrip ActiveX Control Remote Code ExecutionThe TabStrip ActiveX control in MSCOMCTL.OCX fails to properly handle system state, allowing a crafted document or web page to corrupt memory and exe…KEVEPSS 72%analysed10.0CVE-2002-1145Microsoft data engine vulnerabilityThe xp_runwebtask stored procedure in the Web Tasks component of Microsoft SQL Server 7.0 and 2000, Microsoft Data Engine (MSDE) 1.0, and Microsoft D…EPSS 8.3%10.0CVE-2002-0721Microsoft SQL Server weak permissions on extended stored proceduresMicrosoft SQL Server 7.0 and 2000 installs extended stored procedures tied to helper functions with weak permissions. Unprivileged users, and possibl…EPSS 46%analysed10.0CVE-2000-1209Microsoft SQL Server and MSDE default null sa passwordMicrosoft SQL Server 2000, SQL Server 7.0 and MSDE 1.0 install the "sa" account with a default null password, and third-party packages such as Tumble…EPSS 87%analysed9.8CVE-2018-8273Microsoft sql server out-of-bounds write vulnerabilityA buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected system, aka "Microsoft SQL S…EPSS 29%9.3CVE-2009-2500Microsoft windows 2003 server vulnerabilityInteger overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System S…EPSS 24%

Source: NIST National Vulnerability Database (record CVE-2008-0085), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.