VendorsFirebirdsqlfirebirdany version
Vulnerabilities

Firebirdsql Firebird Firebird any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

25CVEs
CVE-2001-0008
Backdoor account in Interbase database server allows remote attackers to overwrite arbitrary files using stored procedures.
Published 2001-05-07 · Modified
10.01 PoCEPSS 0.133
CVE-2007-3181
Buffer overflow in fbserver.exe in Firebird SQL 2 before 2.0.1 allows remote attackers to execute arbitrary code via a large p_cnct_count value in a p_cnct structure in a connect (0x01) request to port 3050/tcp, related to "an InterBase version of gds32.dll."
Published 2007-06-12 · Modified
10.01 PoCEPSS 0.132
CVE-2008-0467
Stack-based buffer overflow in Firebird before 2.0.4, and 2.1.x before 2.1.0 RC1, might allow remote attackers to execute arbitrary code via a long username.
Published 2008-01-29 · Modified
10.0EPSS 0.064
CVE-2026-40342
Firebird: Path Traversal + Arbitrary File Write Leads to Remote Code Execution
Published 2026-04-17 · Analyzed
9.9EPSS 0.008
CVE-2017-6369
Insufficient checks in the UDF subsystem in Firebird 2.5.x before 2.5.7 and 3.0.x before 3.0.2 allow remote authenticated users to execute code by using a 'system' entrypoint from fbudf.so.
Published 2017-03-24 · Analyzed
8.8EPSS 0.033
CVE-2025-24975
Firebird Non-Authorized Access to Encrypted Database Using Execute Statement on External
Published 2025-08-15 · Analyzed
8.8EPSS 0.005
CVE-2026-28224
Firebird Null Pointer Dereference via CryptCallback causes DOS
Published 2026-04-17 · Analyzed
8.2EPSS 0.007
CVE-2026-27890
Firebird has Pre-Auth DOS when Processing Out of Order CNCT_specific_data Segments
Published 2026-04-17 · Analyzed
8.2EPSS 0.007
CVE-2025-65104
Firebird: Information leak vulnerability in firebird3 client when used with newer server
Published 2026-04-17 · Analyzed
7.9EPSS 0.002
CVE-2008-0387
Integer overflow in Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6, 2.0.x before 2.0.4, and 2.1.x before 2.1.0 RC1 might allow remote attackers to execute arbitrary code via crafted (1) op_receive, (2) op_start, (3) op_start_and_receive, (4) op_send, (5) op_start_and_send, and (6) op_start_send_and_receive XDR requests, which triggers memory corruption.
Published 2008-01-29 · Modified
7.81 PoCEPSS 0.459
CVE-2007-4664
Unspecified vulnerability in the (1) attach database and (2) create database functionality in Firebird before 2.0.2, when a filename exceeds MAX_PATH_LEN, has unknown impact and attack vectors, aka CORE-1405.
Published 2007-09-04 · Modified
7.5EPSS 0.019
CVE-2026-33337
Firebird has a buffer overflow when parsing corrupted slice packets
Published 2026-04-17 · Analyzed
7.5EPSS 0.008
CVE-2026-28212
Firebird has potential server crash via null pointer dereference when processing op_slice packet
Published 2026-04-17 · Analyzed
7.5EPSS 0.008
CVE-2026-34232
Firebird: DoS via `op_response` packet from client
Published 2026-04-17 · Analyzed
7.5EPSS 0.007
CVE-2026-35215
Firebird: DoS via malicious slice descriptor in slice packet
Published 2026-04-17 · Analyzed
7.5EPSS 0.007
CVE-2023-41038
Server crash when using specific form of SET BIND statement
Published 2024-03-20 · Analyzed
7.5EPSS 0.007
CVE-2025-54989
Firebird XDR Message Parsing NULL Pointer Dereference Denial-of-Service Vulnerability
Published 2025-08-15 · Modified
7.5EPSS 0.006
CVE-2026-28214
Firebird server hangs when using specific clumplet on batch creation
Published 2026-04-17 · Analyzed
6.5EPSS 0.006
CVE-2009-2620
src/remote/server.cpp in fbserver.exe in Firebird SQL 1.5 before 1.5.6, 2.0 before 2.0.6, 2.1 before 2.1.3, and 2.5 before 2.5 Beta 2 allows remote attackers to cause a denial of service (daemon crash) via a malformed op_connect_request message that triggers an infinite loop or NULL pointer dereference.
Published 2009-07-29 · Analyzed
5.01 PoCEPSS 0.086
CVE-2014-9323
The xdr_status_vector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote attackers to cause a denial of service (NULL pointer dereference, segmentation fault, and crash) via an op_response action with a non-empty status.
Published 2014-12-16 · Modified
5.0EPSS 0.029
CVE-2007-4665
Unspecified vulnerability in the server in Firebird before 2.0.2 allows remote attackers to cause a denial of service (daemon crash) via an XNET session that makes multiple simultaneous requests to register events, aka CORE-1403.
Published 2007-09-04 · Modified
5.0EPSS 0.021
CVE-2007-4667
Unspecified vulnerability in the Services API in Firebird before 2.0.2 allows remote attackers to cause a denial of service, aka CORE-1149.
Published 2007-09-04 · Modified
5.0EPSS 0.021
CVE-2007-4666
Unspecified vulnerability in the server in Firebird before 2.0.2, when a Superserver/TCP/IP environment is configured, allows remote attackers to cause a denial of service (CPU and memory consumption) via "large network packets with garbage", aka CORE-1397.
Published 2007-09-04 · Modified
5.0EPSS 0.021
CVE-2007-4668
Unspecified vulnerability in the server in Firebird before 2.0.2 allows remote attackers to determine the existence of arbitrary files, and possibly obtain other "file access," via unknown vectors, aka CORE-1312.
Published 2007-09-04 · Modified
5.0EPSS 0.015
CVE-2007-4669
The Services API in Firebird before 2.0.2 allows remote authenticated users without SYSDBA privileges to read the server log (firebird.log), aka CORE-1148.
Published 2007-09-04 · Modified
4.0EPSS 0.012