Show filters
37 Total Results
Displaying 1-10 of 37
Sort by:
Attacker Value
Unknown
CVE-2017-6369
Disclosure Date: March 24, 2017 (last updated November 26, 2024)
Insufficient checks in the UDF subsystem in Firebird 2.5.x before 2.5.7 and 3.0.x before 3.0.2 allow remote authenticated users to execute code by using a 'system' entrypoint from fbudf.so.
1
Attacker Value
Moderate
CVE-2013-2492
Disclosure Date: March 15, 2013 (last updated October 05, 2023)
Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 before 26623, on Windows allows remote attackers to execute arbitrary code via a crafted packet to TCP port 3050, related to a missing size check during extraction of a group number from CNCT information.
0
Attacker Value
Unknown
CVE-2023-41038
Disclosure Date: March 20, 2024 (last updated April 02, 2024)
Firebird is a relational database. Versions 4.0.0 through 4.0.3 and version 5.0 beta1 are vulnerable to a server crash when a user uses a specific form of SET BIND statement. Any non-privileged user with minimum access to a server may type a statement with a long `CHAR` length, which causes the server to crash due to stack corruption. Versions 4.0.4.2981 and 5.0.0.117 contain fixes for this issue. No known workarounds are available.
0
Attacker Value
Unknown
CVE-2017-11509
Disclosure Date: March 28, 2018 (last updated November 26, 2024)
An authenticated remote attacker can execute arbitrary code in Firebird SQL Server versions 2.5.7 and 3.0.2 by executing a malformed SQL statement.
0
Attacker Value
Unknown
CVE-2016-1569
Disclosure Date: January 13, 2016 (last updated November 25, 2024)
FireBird 2.5.5 allows remote authenticated users to cause a denial of service (daemon crash) by using service manager to invoke the gbak utility with an invalid parameter.
0
Attacker Value
Unknown
CVE-2015-2788
Disclosure Date: April 14, 2015 (last updated October 05, 2023)
Multiple stack-based buffer overflows in the ib_fill_isqlda function in dbdimp.c in DBD-Firebird before 1.19 allow remote attackers to have unspecified impact via unknown vectors that trigger an error condition, related to binding octets to columns.
0
Attacker Value
Unknown
CVE-2014-9323
Disclosure Date: December 16, 2014 (last updated October 05, 2023)
The xdr_status_vector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote attackers to cause a denial of service (NULL pointer dereference, segmentation fault, and crash) via an op_response action with a non-empty status.
0
Attacker Value
Unknown
CVE-2012-5529
Disclosure Date: November 20, 2012 (last updated October 05, 2023)
TraceManager in Firebird 2.5.0 and 2.5.1, when trace is enabled, allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) by preparing an empty dynamic SQL query.
0
Attacker Value
Unknown
CVE-2009-2620
Disclosure Date: July 29, 2009 (last updated October 04, 2023)
src/remote/server.cpp in fbserver.exe in Firebird SQL 1.5 before 1.5.6, 2.0 before 2.0.6, 2.1 before 2.1.3, and 2.5 before 2.5 Beta 2 allows remote attackers to cause a denial of service (daemon crash) via a malformed op_connect_request message that triggers an infinite loop or NULL pointer dereference.
0
Attacker Value
Unknown
CVE-2008-1880
Disclosure Date: May 12, 2008 (last updated October 04, 2023)
The default configuration of Firebird before 2.0.3.12981.0-r6 on Gentoo Linux sets the ISC_PASSWORD environment variable before starting Firebird, which allows remote attackers to bypass SYSDBA authentication and obtain sensitive database information via an empty password.
0