Vulnerability Details CVE-2013-2492
Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 before 26623, on Windows allows remote attackers to execute arbitrary code via a crafted packet to TCP port 3050, related to a missing size check during extraction of a group number from CNCT information.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.853
EPSS Ranking 99.3%
CVSS Severity
CVSS v2 Score 6.8
Products affected by CVE-2013-2492
-
cpe:2.3:a:firebirdsql:firebird:2.1.3
-
cpe:2.3:a:firebirdsql:firebird:2.1.4
-
cpe:2.3:a:firebirdsql:firebird:2.1.5
-
cpe:2.3:a:firebirdsql:firebird:2.5.1
-
cpe:2.3:a:firebirdsql:firebird:2.5.2
-
cpe:2.3:a:firebirdsql:firebird:2.5.3
-
cpe:2.3:o:microsoft:windows:-
-
cpe:2.3:o:microsoft:windows:1.0
-
cpe:2.3:o:microsoft:windows:2.0
-
cpe:2.3:o:microsoft:windows:2000
-
cpe:2.3:o:microsoft:windows:3.0
-
cpe:2.3:o:microsoft:windows:3.1
-
cpe:2.3:o:microsoft:windows:3.11
-
cpe:2.3:o:microsoft:windows:server_2008
-
cpe:2.3:o:microsoft:windows:vista