Skip to main content

Vendor/product archive

firebirdsql / firebird CVEs

Beta · best-effort

46 CVEs tagged to firebirdsql / firebird7 Critical, 18 High, 19 Medium, 2 Low, 0 Unrated.

CVE-2026-40342

Published Apr 17, 2026

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader concatenates a user-supplied engi…

CVSS 9.9 · Critical
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-35215

Published Apr 17, 2026

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the sdl_desc() function does not validate the length of a decoded S…

CVSS 7.5 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-34232

Published Apr 17, 2026

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the xdr_status_vector() function does not handle the isc_arg_cstrin…

CVSS 7.5 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-33337

Published Apr 17, 2026

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when deserializing a slice packet, the xdr_datum() function does no…

CVSS 7.5 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-28224

Published Apr 17, 2026

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when the server receives an op_crypt_key_callback packet without pr…

CVSS 8.2 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-28214

Published Apr 17, 2026

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the ClumpletReader::getClumpletSize() function can overflow the tot…

CVSS 6.0 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-28212

Published Apr 17, 2026

Firebird is an open-source relational database management system. In versions prior to 6.0.0, 5.0.4, 4.0.7 and 3.0.14, when processing an op_slice network packet, the server passe…

CVSS 7.5 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-27890

Published Apr 17, 2026

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when processing CNCT_specific_data segments during authentication,…

CVSS 8.2 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2025-65104

Published Apr 17, 2026

Firebird is an open-source relational database management system. In versions FB3 of the client library placed incorrect data length values into XSQLDA fields when communicating w…

CVSS 7.9 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-54989

Published Aug 15, 2025

Firebird is a relational database. Prior to versions 3.0.13, 4.0.6, and 5.0.3, there is an XDR message parsing NULL pointer dereference denial-of-service vulnerability in Firebird…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2025-24975

Published Aug 15, 2025

Firebird is a relational database. Prior to snapshot versions 4.0.6.3183, 5.0.2.1610, and 6.0.0.609, Firebird is vulnerable if ExtConnPoolSize is not set equal to 0. If connection…

CVSS 7.1 · High
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2023-41038

Published Mar 20, 2024

Firebird is a relational database. Versions 4.0.0 through 4.0.3 and version 5.0 beta1 are vulnerable to a server crash when a user uses a specific form of SET BIND statement. Any…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-6369

Published Mar 24, 2017

Insufficient checks in the UDF subsystem in Firebird 2.5.x before 2.5.7 and 3.0.x before 3.0.2 allow remote authenticated users to execute code by using a 'system' entrypoint from…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-1569

Published Jan 13, 2016

FireBird 2.5.5 allows remote authenticated users to cause a denial of service (daemon crash) by using service manager to invoke the gbak utility with an invalid parameter.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2492

Published Mar 15, 2013

Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 before 26623, on Windows allows remote attackers to execute arbitrary code via a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5529

Published Nov 20, 2012

TraceManager in Firebird 2.5.0 and 2.5.1, when trace is enabled, allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) by preparing a…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-2620

Published Jul 29, 2009

src/remote/server.cpp in fbserver.exe in Firebird SQL 1.5 before 1.5.6, 2.0 before 2.0.6, 2.1 before 2.1.3, and 2.5 before 2.5 Beta 2 allows remote attackers to cause a denial of…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0387

Published Jan 29, 2008

Integer overflow in Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6, 2.0.x before 2.0.4, and 2.1.x before 2.1.0 RC1 might allow remote attackers to execute arbitrary code via c…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0467

Published Jan 29, 2008

Stack-based buffer overflow in Firebird before 2.0.4, and 2.1.x before 2.1.0 RC1, might allow remote attackers to execute arbitrary code via a long username.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-4992

Published Oct 11, 2007

Stack-based buffer overflow in the process_packet function in fbserver.exe in Firebird SQL 2.0.2 allows remote attackers to execute arbitrary code via a long request to TCP port 3…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-5245

Published Oct 6, 2007

Multiple stack-based buffer overflows in Firebird LI 1.5.3.4870 and 1.5.4.4910, and WI 1.5.3.4870 and 1.5.4.4910, allow remote attackers to execute arbitrary code via (1) a long s…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-5246

Published Oct 6, 2007

Multiple stack-based buffer overflows in Firebird LI 2.0.0.12748 and 2.0.1.12855, and WI 2.0.0.12748 and 2.0.1.12855, allow remote attackers to execute arbitrary code via (1) a lo…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-4664

Published Sep 4, 2007

Unspecified vulnerability in the (1) attach database and (2) create database functionality in Firebird before 2.0.2, when a filename exceeds MAX_PATH_LEN, has unknown impact and a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 46 CVEsPage 1 of 2