Vulnerabilities
Vulnerable Software
Firebirdsql:  >> Firebird  >> 1.5  Security Vulnerabilities
Stack-based buffer overflow in Firebird before 2.0.4, and 2.1.x before 2.1.0 RC1, might allow remote attackers to execute arbitrary code via a long username.
CVSS Score
10.0
EPSS Score
0.235
Published
2008-01-29
Unspecified vulnerability in the (1) attach database and (2) create database functionality in Firebird before 2.0.2, when a filename exceeds MAX_PATH_LEN, has unknown impact and attack vectors, aka CORE-1405.
CVSS Score
7.5
EPSS Score
0.012
Published
2007-09-04
Unspecified vulnerability in the server in Firebird before 2.0.2 allows remote attackers to cause a denial of service (daemon crash) via an XNET session that makes multiple simultaneous requests to register events, aka CORE-1403.
CVSS Score
5.0
EPSS Score
0.019
Published
2007-09-04
Unspecified vulnerability in the server in Firebird before 2.0.2, when a Superserver/TCP/IP environment is configured, allows remote attackers to cause a denial of service (CPU and memory consumption) via "large network packets with garbage", aka CORE-1397.
CVSS Score
5.0
EPSS Score
0.019
Published
2007-09-04
Unspecified vulnerability in the Services API in Firebird before 2.0.2 allows remote attackers to cause a denial of service, aka CORE-1149.
CVSS Score
5.0
EPSS Score
0.019
Published
2007-09-04
Unspecified vulnerability in the server in Firebird before 2.0.2 allows remote attackers to determine the existence of arbitrary files, and possibly obtain other "file access," via unknown vectors, aka CORE-1312.
CVSS Score
5.0
EPSS Score
0.003
Published
2007-09-04
The Services API in Firebird before 2.0.2 allows remote authenticated users without SYSDBA privileges to read the server log (firebird.log), aka CORE-1148.
CVSS Score
4.0
EPSS Score
0.004
Published
2007-09-04
fb_lock_mgr in Firebird 1.5 uses weak permissions (0666) for the semaphore array, which allows local users to cause a denial of service (blocked query processing) by locking semaphores.
CVSS Score
4.9
EPSS Score
0.0
Published
2007-06-29
Multiple buffer overflows in Firebird 1.5, one of which affects WNET, have unknown impact and attack vectors. NOTE: this issue might overlap CVE-2006-1240.
CVSS Score
6.8
EPSS Score
0.005
Published
2007-06-29
Firebird 1.5 allows remote authenticated users without SYSDBA and owner permissions to overwrite a database by creating a database.
CVSS Score
5.5
EPSS Score
0.002
Published
2007-06-29


Contact Us

Shodan ® - All rights reserved