Firebirdsql

Firebird

47 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht Exploit
  • EPSS 0.1%
  • Veröffentlicht 17.04.2026 19:22:46
  • Zuletzt bearbeitet 27.04.2026 14:28:24

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader concatenates a user-supplied engine name into a filesystem path without filtering path separators or .. ...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 17.04.2026 18:59:23
  • Zuletzt bearbeitet 27.04.2026 14:29:26

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the sdl_desc() function does not validate the length of a decoded SDL descriptor from a slice packet. A zero-length descriptor is later us...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 17.04.2026 18:52:11
  • Zuletzt bearbeitet 27.04.2026 14:27:50

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the xdr_status_vector() function does not handle the isc_arg_cstring type when decoding an op_response packet, causing a server crash when...

Medienbericht Exploit
  • EPSS 0.12%
  • Veröffentlicht 17.04.2026 18:48:47
  • Zuletzt bearbeitet 27.04.2026 14:26:16

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when deserializing a slice packet, the xdr_datum() function does not validate that a cstring length conforms to the slice descriptor bound...

Medienbericht Exploit
  • EPSS 0.4%
  • Veröffentlicht 17.04.2026 18:38:58
  • Zuletzt bearbeitet 24.04.2026 19:45:57

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when the server receives an op_crypt_key_callback packet without prior authentication, the port_server_crypt_callback handler is not initi...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 17.04.2026 18:35:46
  • Zuletzt bearbeitet 24.04.2026 19:47:36

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the ClumpletReader::getClumpletSize() function can overflow the totalLength value when parsing a Wide type clumplet, causing an infinite l...

  • EPSS 0.03%
  • Veröffentlicht 17.04.2026 18:16:30
  • Zuletzt bearbeitet 24.04.2026 20:27:22

Firebird is an open-source relational database management system. In versions FB3 of the client library placed incorrect data length values into XSQLDA fields when communicating with FB4 or higher servers, resulting in an information leak. This issue...

Exploit
  • EPSS 0.4%
  • Veröffentlicht 17.04.2026 18:14:29
  • Zuletzt bearbeitet 24.04.2026 20:05:41

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when processing CNCT_specific_data segments during authentication, the server assumes segments arrive in strictly ascending order. If segm...

Exploit
  • EPSS 0.07%
  • Veröffentlicht 17.04.2026 18:05:25
  • Zuletzt bearbeitet 24.04.2026 19:54:47

Firebird is an open-source relational database management system. In versions prior to 6.0.0, 5.0.4, 4.0.7 and 3.0.14, when processing an op_slice network packet, the server passes an unprepared structure containing a null pointer to the SDL_info() f...

Medienbericht
  • EPSS 0.29%
  • Veröffentlicht 15.08.2025 15:15:32
  • Zuletzt bearbeitet 03.11.2025 19:16:11

Firebird is a relational database. Prior to versions 3.0.13, 4.0.6, and 5.0.3, there is an XDR message parsing NULL pointer dereference denial-of-service vulnerability in Firebird. This specific flaw exists within the parsing of xdr message from clie...