Vulnerability index

Browse CVEs

32 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firebird CRITICAL 9.9
CVE-2026-40342

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader con…

Fix: 3.0.14 / 4.0.7+
Fix from $2,300 2026-04-17
Firebird HIGH 7.5
CVE-2026-35215

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the sdl_desc() function does not vali…

Fix: 3.0.14 / 4.0.7+
Fix from $1,950 2026-04-17
Firebird HIGH 7.5
CVE-2026-34232

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the xdr_status_vector() function does…

Fix: 3.0.14 / 4.0.7+
Fix from $1,950 2026-04-17
Firebird HIGH 7.5
CVE-2026-33337

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when deserializing a slice packet, th…

Fix: 3.0.14 / 4.0.7+
Fix from $1,950 2026-04-17
Firebird HIGH 8.2
CVE-2026-28224

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when the server receives an op_crypt_…

Fix: 3.0.14 / 4.0.7+
Fix from $1,950 2026-04-17
Firebird HIGH 7.5
CVE-2026-28212

Firebird is an open-source relational database management system. In versions prior to 6.0.0, 5.0.4, 4.0.7 and 3.0.14, when processing an op_slice ne…

Fix: 3.0.14 / 4.0.7+
Fix from $1,950 2026-04-17
Firebird MEDIUM 6.5
CVE-2026-28214

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the ClumpletReader::getClumpletSize()…

Fix: 3.0.14 / 4.0.7+
Fix from $1,600 2026-04-17
Firebird HIGH 8.2
CVE-2026-27890

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when processing CNCT_specific_data se…

Fix: 3.0.14 / 4.0.7+
Fix from $1,950 2026-04-17
Firebird HIGH 7.5
CVE-2025-65104

Firebird is an open-source relational database management system. In versions FB3 of the client library placed incorrect data length values into XSQL…

Fix: 3.0.14+
Fix from $1,950 2026-04-17
Firebird HIGH 8.8
CVE-2025-24975

Firebird is a relational database. Prior to snapshot versions 4.0.6.3183, 5.0.2.1610, and 6.0.0.609, Firebird is vulnerable if ExtConnPoolSize is not…

Fix: 4.0.6 / 5.0.2+
Fix from $1,950 2025-08-15
Firebird HIGH 7.5
CVE-2025-54989

Firebird is a relational database. Prior to versions 3.0.13, 4.0.6, and 5.0.3, there is an XDR message parsing NULL pointer dereference denial-of-ser…

Fix: 3.0.13 / 4.0.6+
Fix from $1,950 2025-08-15
Firebird HIGH 7.5
CVE-2023-41038

Firebird is a relational database. Versions 4.0.0 through 4.0.3 and version 5.0 beta1 are vulnerable to a server crash when a user uses a specific fo…

Fix: after 4.0.3
Fix from $1,950 2024-03-20
Firebird HIGH 8.8
CVE-2017-6369

Insufficient checks in the UDF subsystem in Firebird 2.5.x before 2.5.7 and 3.0.x before 3.0.2 allow remote authenticated users to execute code by us…

Fix: 2.5.7 / 3.0.2+
Fix from $1,950 2017-03-24
Firebird MEDIUM 6.5
CVE-2016-1569

FireBird 2.5.5 allows remote authenticated users to cause a denial of service (daemon crash) by using service manager to invoke the gbak utility with…

No fix yet
Fix from $1,600 2016-01-13
Firebird MEDIUM 6.8
CVE-2013-2492EPSS 42%

Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 before 26623, on Windows allows remote attackers to…

No fix yet
Fix from $1,600 2013-03-15
Firebird MEDIUM 5.0
CVE-2009-2620EPSS 9%

src/remote/server.cpp in fbserver.exe in Firebird SQL 1.5 before 1.5.6, 2.0 before 2.0.6, 2.1 before 2.1.3, and 2.5 before 2.5 Beta 2 allows remote a…

Fix: 1.5.6 / 2.0.6+
Fix from $1,600 2009-07-29
Firebird HIGH 10.0
CVE-2008-0467EPSS 6%

Stack-based buffer overflow in Firebird before 2.0.4, and 2.1.x before 2.1.0 RC1, might allow remote attackers to execute arbitrary code via a long u…

Fix: after 2.1
Fix from $1,950 2008-01-29
Firebird HIGH 7.8
CVE-2008-0387EPSS 46%

Integer overflow in Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6, 2.0.x before 2.0.4, and 2.1.x before 2.1.0 RC1 might allow remote attackers t…

Fix: 1.5.6 / 2.0.4+
Fix from $1,950 2008-01-29
Firebird HIGH 10.0
CVE-2007-4992EPSS 8%

Stack-based buffer overflow in the process_packet function in fbserver.exe in Firebird SQL 2.0.2 allows remote attackers to execute arbitrary code vi…

Mitigation only
Fix from $1,950 2007-10-11
Firebird HIGH 10.0
CVE-2007-5245EPSS 9%

Multiple stack-based buffer overflows in Firebird LI 1.5.3.4870 and 1.5.4.4910, and WI 1.5.3.4870 and 1.5.4.4910, allow remote attackers to execute a…

No fix yet
Fix from $1,950 2007-10-06
Firebird HIGH 10.0
CVE-2007-5246EPSS 7%

Multiple stack-based buffer overflows in Firebird LI 2.0.0.12748 and 2.0.1.12855, and WI 2.0.0.12748 and 2.0.1.12855, allow remote attackers to execu…

No fix yet
Fix from $1,950 2007-10-06
Firebird HIGH 7.5
CVE-2007-4664

Unspecified vulnerability in the (1) attach database and (2) create database functionality in Firebird before 2.0.2, when a filename exceeds MAX_PATH…

Fix: after 2.0.1
Fix from $1,950 2007-09-04
Firebird MEDIUM 5.0
CVE-2007-4665

Unspecified vulnerability in the server in Firebird before 2.0.2 allows remote attackers to cause a denial of service (daemon crash) via an XNET sess…

Fix: after 2.0.1
Fix from $1,600 2007-09-04
Firebird MEDIUM 5.0
CVE-2007-4666

Unspecified vulnerability in the server in Firebird before 2.0.2, when a Superserver/TCP/IP environment is configured, allows remote attackers to cau…

Fix: after 2.0.1
Fix from $1,600 2007-09-04
Firebird MEDIUM 5.0
CVE-2007-4667

Unspecified vulnerability in the Services API in Firebird before 2.0.2 allows remote attackers to cause a denial of service, aka CORE-1149.

Fix: after 2.0.1
Fix from $1,600 2007-09-04
Firebird MEDIUM 5.0
CVE-2007-4668

Unspecified vulnerability in the server in Firebird before 2.0.2 allows remote attackers to determine the existence of arbitrary files, and possibly …

Fix: after 2.0.1
Fix from $1,600 2007-09-04
Firebird MEDIUM 6.8
CVE-2007-3527

Integer overflow in Firebird 2.0.0 allows remote authenticated users to cause a denial of service (CPU consumption) via certain database operations w…

Patch available
Fix from $1,600 2007-07-03
Firebird HIGH 7.8
CVE-2006-7214

Multiple unspecified vulnerabilities in Firebird 1.5 allow remote attackers to (1) cause a denial of service (application crash) by sending many remo…

Patch available
Fix from $1,950 2007-06-29
Firebird MEDIUM 6.8
CVE-2006-7212

Multiple buffer overflows in Firebird 1.5, one of which affects WNET, have unknown impact and attack vectors. NOTE: this issue might overlap CVE-200…

Patch available
Fix from $1,600 2007-06-29
Firebird MEDIUM 5.5
CVE-2006-7213

Firebird 1.5 allows remote authenticated users without SYSDBA and owner permissions to overwrite a database by creating a database.

Patch available
Fix from $1,600 2007-06-29