Vulnerabilities
Vulnerable Software
Firebirdsql:  >> Firebird  >> 1.5.5  Security Vulnerabilities
Stack-based buffer overflow in Firebird before 2.0.4, and 2.1.x before 2.1.0 RC1, might allow remote attackers to execute arbitrary code via a long username.
CVSS Score
10.0
EPSS Score
0.235
Published
2008-01-29
Unspecified vulnerability in the (1) attach database and (2) create database functionality in Firebird before 2.0.2, when a filename exceeds MAX_PATH_LEN, has unknown impact and attack vectors, aka CORE-1405.
CVSS Score
7.5
EPSS Score
0.012
Published
2007-09-04
Unspecified vulnerability in the server in Firebird before 2.0.2 allows remote attackers to cause a denial of service (daemon crash) via an XNET session that makes multiple simultaneous requests to register events, aka CORE-1403.
CVSS Score
5.0
EPSS Score
0.019
Published
2007-09-04
Unspecified vulnerability in the server in Firebird before 2.0.2, when a Superserver/TCP/IP environment is configured, allows remote attackers to cause a denial of service (CPU and memory consumption) via "large network packets with garbage", aka CORE-1397.
CVSS Score
5.0
EPSS Score
0.019
Published
2007-09-04
Unspecified vulnerability in the Services API in Firebird before 2.0.2 allows remote attackers to cause a denial of service, aka CORE-1149.
CVSS Score
5.0
EPSS Score
0.019
Published
2007-09-04
Unspecified vulnerability in the server in Firebird before 2.0.2 allows remote attackers to determine the existence of arbitrary files, and possibly obtain other "file access," via unknown vectors, aka CORE-1312.
CVSS Score
5.0
EPSS Score
0.003
Published
2007-09-04
The Services API in Firebird before 2.0.2 allows remote authenticated users without SYSDBA privileges to read the server log (firebird.log), aka CORE-1148.
CVSS Score
4.0
EPSS Score
0.004
Published
2007-09-04
Buffer overflow in fbserver.exe in Firebird SQL 2 before 2.0.1 allows remote attackers to execute arbitrary code via a large p_cnct_count value in a p_cnct structure in a connect (0x01) request to port 3050/tcp, related to "an InterBase version of gds32.dll."
CVSS Score
10.0
EPSS Score
0.292
Published
2007-06-12


Contact Us

Shodan ® - All rights reserved