Show filters
37 Total Results
Displaying 21-30 of 37
Sort by:
Attacker Value
Unknown

CVE-2007-4666

Disclosure Date: September 04, 2007 (last updated October 04, 2023)
Unspecified vulnerability in the server in Firebird before 2.0.2, when a Superserver/TCP/IP environment is configured, allows remote attackers to cause a denial of service (CPU and memory consumption) via "large network packets with garbage", aka CORE-1397.
0
Attacker Value
Unknown

CVE-2007-3527

Disclosure Date: July 03, 2007 (last updated October 04, 2023)
Integer overflow in Firebird 2.0.0 allows remote authenticated users to cause a denial of service (CPU consumption) via certain database operations with multi-byte character sets that trigger an attempt to use the value 65536 for a 16-bit integer, which is treated as 0 and causes an infinite loop on zero-length data.
0
Attacker Value
Unknown

CVE-2006-7211

Disclosure Date: June 29, 2007 (last updated October 04, 2023)
fb_lock_mgr in Firebird 1.5 uses weak permissions (0666) for the semaphore array, which allows local users to cause a denial of service (blocked query processing) by locking semaphores.
0
Attacker Value
Unknown

CVE-2006-7214

Disclosure Date: June 29, 2007 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in Firebird 1.5 allow remote attackers to (1) cause a denial of service (application crash) by sending many remote protocol versions; and (2) cause a denial of service (connection drop) via certain network traffic, as demonstrated by Nessus vulnerability scanning.
0
Attacker Value
Unknown

CVE-2006-7213

Disclosure Date: June 29, 2007 (last updated October 04, 2023)
Firebird 1.5 allows remote authenticated users without SYSDBA and owner permissions to overwrite a database by creating a database.
0
Attacker Value
Unknown

CVE-2006-7212

Disclosure Date: June 29, 2007 (last updated October 04, 2023)
Multiple buffer overflows in Firebird 1.5, one of which affects WNET, have unknown impact and attack vectors. NOTE: this issue might overlap CVE-2006-1240.
0
Attacker Value
Unknown

CVE-2007-3181

Disclosure Date: June 12, 2007 (last updated October 04, 2023)
Buffer overflow in fbserver.exe in Firebird SQL 2 before 2.0.1 allows remote attackers to execute arbitrary code via a large p_cnct_count value in a p_cnct structure in a connect (0x01) request to port 3050/tcp, related to "an InterBase version of gds32.dll."
0
Attacker Value
Unknown

CVE-2007-2606

Disclosure Date: May 11, 2007 (last updated October 04, 2023)
Multiple buffer overflows in Firebird 2.1 allow attackers to trigger memory corruption and possibly have other unspecified impact via certain input processed by (1) config\ConfigFile.cpp or (2) msgs\check_msgs.epp. NOTE: if ConfigFile.cpp reads a configuration file with restrictive permissions, then the ConfigFile.cpp vector may not cross privilege boundaries and perhaps should not be included in CVE.
0
Attacker Value
Unknown

CVE-2006-1240

Disclosure Date: March 15, 2006 (last updated February 22, 2025)
Buffer overflow in inet_server.cpp in (1) fb_inet_server and (2) fbserver in Firebird 1.5.2.4731 allows local users to gain privileges via a long value of the -p argument.
0
Attacker Value
Unknown

CVE-2006-1241

Disclosure Date: March 15, 2006 (last updated February 22, 2025)
Firebird 1.5.2.4731 installs (1) fb_lock_mgr, (2) gds_drop, and (3) fb_inet_server with setuid firebird permissions, which might allow local users to gain privileges via a buffer overflow as identified by CVE-2006-1240, or possibly other vulnerabilities.
0