VendorsFirebirdsqlfirebirdall versions
Vulnerabilities

Firebirdsql Firebird Firebird

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

46CVEs
CVE-2003-0281
Buffer overflow in Firebird 1.0.2 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows local users to execute arbitrary code via a long INTERBASE environment variable when calling (1) gds_inet_server, (2) gds_lock_mgr, or (3) gds_drop.
Published 2003-05-14 · Modified
4.63 PoCEPSS 0.010
CVE-2006-1240
Buffer overflow in inet_server.cpp in (1) fb_inet_server and (2) fbserver in Firebird 1.5.2.4731 allows local users to gain privileges via a long value of the -p argument.
Published 2006-03-15 · Modified
4.61 PoCEPSS 0.009
CVE-2006-1241
Firebird 1.5.2.4731 installs (1) fb_lock_mgr, (2) gds_drop, and (3) fb_inet_server with setuid firebird permissions, which might allow local users to gain privileges via a buffer overflow as identified by CVE-2006-1240, or possibly other vulnerabilities.
Published 2006-03-15 · Modified
4.6EPSS 0.005
CVE-2007-4669
The Services API in Firebird before 2.0.2 allows remote authenticated users without SYSDBA privileges to read the server log (firebird.log), aka CORE-1148.
Published 2007-09-04 · Modified
4.0EPSS 0.012
CVE-2012-5529
TraceManager in Firebird 2.5.0 and 2.5.1, when trace is enabled, allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) by preparing an empty dynamic SQL query.
Published 2012-11-20 · Modified
3.5EPSS 0.018
CVE-2004-1449
Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7 allows remote attackers to determine the location of files on a user's hard drive by obscuring a file upload control and tricking the user into dragging text into that control.
Published 2005-02-13 · Modified
2.6EPSS 0.009
← Prev2 / 2