cve,link,title,description,vendor,products,score,severity,epss,cisa,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2023-33990,https://securityvulnerability.io/vulnerability/CVE-2023-33990,Denial of Service (DoS) vulnerability in SAP SQL Anywhere,"This vulnerability in SAP SQL Anywhere version 17.0 for Windows allows a low privileged attacker with local access to disrupt legitimate users by causing the service to crash. By writing to shared memory objects, the attacker can initiate a Denial of Service attack, preventing user access and potentially compromising sensitive data stored in those objects. This issue does not impact other operating systems.",SAP,SAP Sql Anywhere,7.8,HIGH,0.0004299999854993075,false,false,false,false,,false,false,2023-07-11T03:15:00.000Z,0 CVE-2022-41259,https://securityvulnerability.io/vulnerability/CVE-2022-41259,,"SAP SQL Anywhere - version 17.0, allows an authenticated attacker to prevent legitimate users from accessing a SQL Anywhere database server by crashing the server with some queries that use an ARRAY constructor.",SAP,SAP Sql Anywhere,6.5,MEDIUM,0.0008099999977275729,false,false,false,false,,false,false,2022-11-08T00:00:00.000Z,0 CVE-2022-35299,https://securityvulnerability.io/vulnerability/CVE-2022-35299,,"SAP SQL Anywhere - version 17.0, and SAP IQ - version 16.1, allows an attacker to leverage logical errors in memory management to cause a memory corruption, such as Stack-based buffer overflow.",SAP,"SAP Sql Anywhere,SAP Iq",9.8,CRITICAL,0.0016499999910593033,false,false,false,false,,false,false,2022-10-11T00:00:00.000Z,0 CVE-2022-27670,https://securityvulnerability.io/vulnerability/CVE-2022-27670,,"SAP SQL Anywhere - version 17.0, allows an authenticated attacker to prevent legitimate users from accessing a SQL Anywhere database server by crashing the server with some queries that use indirect identifiers.",SAP,SAP Sql Anywhere Server,6.5,MEDIUM,0.0008099999977275729,false,false,false,false,,false,false,2022-04-12T16:11:25.000Z,0 CVE-2019-0381,https://securityvulnerability.io/vulnerability/CVE-2019-0381,,"A binary planting in SAP SQL Anywhere, before version 17.0, SAP IQ, before version 16.1, and SAP Dynamic Tier, before versions 1.0 and 2.0, can result in the inadvertent access of files located in directories outside of the paths specified by the user.",SAP,"SAP Iq,SAP Sql Anywhere,SAP Dynamic Tiering",5.5,MEDIUM,0.0004400000034365803,false,false,false,false,,false,false,2019-10-08T19:29:26.000Z,0 CVE-2016-10310,https://securityvulnerability.io/vulnerability/CVE-2016-10310,,"Buffer overflow in the MobiLink Synchronization Server component in SAP SQL Anywhere 17 and possibly earlier allows remote authenticated users to cause a denial of service (resource consumption and process crash) by sending a crafted packet several times, aka SAP Security Note 2308778.",SAP,Sql Anywhere,4.9,MEDIUM,0.001290000043809414,false,false,false,false,,false,false,2017-04-10T15:00:00.000Z,0 CVE-2015-2819,https://securityvulnerability.io/vulnerability/CVE-2015-2819,,"SAP Sybase SQL Anywhere 11 and 16 allows remote attackers to cause a denial of service (crash) via a crafted request, aka SAP Security Note 2108161.",SAP,Sql Anywhere,,,0.0050200000405311584,false,false,false,false,,false,false,2015-04-01T14:00:00.000Z,0 CVE-2014-9264,https://securityvulnerability.io/vulnerability/CVE-2014-9264,,Stack-based buffer overflow in the .NET Data Provider in SAP SQL Anywhere allows remote attackers to execute arbitrary code via a crafted column alias.,SAP,Sql Anywhere,,,0.9289399981498718,false,false,false,false,,false,false,2014-12-11T15:00:00.000Z,0