Show filters
35 Total Results
Displaying 1-10 of 35
Sort by:
Attacker Value
Unknown

CVE-2017-6369

Disclosure Date: March 24, 2017 (last updated November 26, 2024)
Insufficient checks in the UDF subsystem in Firebird 2.5.x before 2.5.7 and 3.0.x before 3.0.2 allow remote authenticated users to execute code by using a 'system' entrypoint from fbudf.so.
1
Attacker Value
Moderate

CVE-2013-2492

Disclosure Date: March 15, 2013 (last updated October 05, 2023)
Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 before 26623, on Windows allows remote attackers to execute arbitrary code via a crafted packet to TCP port 3050, related to a missing size check during extraction of a group number from CNCT information.
0
Attacker Value
Unknown

CVE-2023-41038

Disclosure Date: March 20, 2024 (last updated April 02, 2024)
Firebird is a relational database. Versions 4.0.0 through 4.0.3 and version 5.0 beta1 are vulnerable to a server crash when a user uses a specific form of SET BIND statement. Any non-privileged user with minimum access to a server may type a statement with a long `CHAR` length, which causes the server to crash due to stack corruption. Versions 4.0.4.2981 and 5.0.0.117 contain fixes for this issue. No known workarounds are available.
0
Attacker Value
Unknown

CVE-2017-11509

Disclosure Date: March 28, 2018 (last updated November 26, 2024)
An authenticated remote attacker can execute arbitrary code in Firebird SQL Server versions 2.5.7 and 3.0.2 by executing a malformed SQL statement.
Attacker Value
Unknown

CVE-2016-1569

Disclosure Date: January 13, 2016 (last updated November 25, 2024)
FireBird 2.5.5 allows remote authenticated users to cause a denial of service (daemon crash) by using service manager to invoke the gbak utility with an invalid parameter.
0
Attacker Value
Unknown

CVE-2014-9323

Disclosure Date: December 16, 2014 (last updated October 05, 2023)
The xdr_status_vector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote attackers to cause a denial of service (NULL pointer dereference, segmentation fault, and crash) via an op_response action with a non-empty status.
0
Attacker Value
Unknown

CVE-2012-5529

Disclosure Date: November 20, 2012 (last updated October 05, 2023)
TraceManager in Firebird 2.5.0 and 2.5.1, when trace is enabled, allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) by preparing an empty dynamic SQL query.
0
Attacker Value
Unknown

CVE-2009-2620

Disclosure Date: July 29, 2009 (last updated October 04, 2023)
src/remote/server.cpp in fbserver.exe in Firebird SQL 1.5 before 1.5.6, 2.0 before 2.0.6, 2.1 before 2.1.3, and 2.5 before 2.5 Beta 2 allows remote attackers to cause a denial of service (daemon crash) via a malformed op_connect_request message that triggers an infinite loop or NULL pointer dereference.
0
Attacker Value
Unknown

CVE-2008-0467

Disclosure Date: January 29, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in Firebird before 2.0.4, and 2.1.x before 2.1.0 RC1, might allow remote attackers to execute arbitrary code via a long username.
0
Attacker Value
Unknown

CVE-2008-0387

Disclosure Date: January 29, 2008 (last updated October 04, 2023)
Integer overflow in Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6, 2.0.x before 2.0.4, and 2.1.x before 2.1.0 RC1 might allow remote attackers to execute arbitrary code via crafted (1) op_receive, (2) op_start, (3) op_start_and_receive, (4) op_send, (5) op_start_and_send, and (6) op_start_send_and_receive XDR requests, which triggers memory corruption.
0