| CVE ID | CVE-2014-9264 | 
| CVSS SCORE | 9.5, AV:U/AC:L/Au:U/C:P/I:P/A:P | 
| AFFECTED VENDORS | 
                            
                            
                            SAP | 
                    
| AFFECTED PRODUCTS | 
                            
                            
                            SQL Anywhere | 
                    
| VULNERABILITY DETAILS | 
                             
 The specific flaw exists within the handling of column aliases. If an application allows untrusted input to be used as the column alias in a query, even if the input is correctly filtered against SQL injection, an attacker could overflow a fixed size stack buffer and execute arbitrary code in the context of the application.  | 
                    
| ADDITIONAL DETAILS | 
                            
                            
                            
                             
  | 
                    
| DISCLOSURE TIMELINE | 
                            
  | 
                    
| CREDIT | John Leitch |