threat
engine
.sh
Back
·
··:··
Home
/
Product
/
firebirdsql firebird
Product
firebirdsql firebird
47 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2026-40342
< 3.0.14
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engin
9.9
CRITICAL
CVE-2026-35215
>= 3.0.0 and < 3.0.14
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the sdl_desc() fun
7.5
HIGH
CVE-2026-34232
>= 3.0.0 and < 3.0.14
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the xdr_status_vec
7.5
HIGH
CVE-2026-33337
>= 3.0.0 and < 3.0.14
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when deserializing
7.5
HIGH
CVE-2026-28224
< 3.0.14
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when the server re
8.2
HIGH
CVE-2026-28214
< 3.0.14
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the ClumpletReader
6.5
MEDIUM
CVE-2026-28212
< 3.0.14
Firebird is an open-source relational database management system. In versions prior to 6.0.0, 5.0.4, 4.0.7 and 3.0.14, when proces
7.5
HIGH
CVE-2026-27890
< 3.0.14
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when processing CN
8.2
HIGH
CVE-2025-65104
< 3.0.14
Firebird is an open-source relational database management system. In versions FB3 of the client library placed incorrect data leng
7.9
HIGH
CVE-2025-54989
< 3.0.13
Firebird is a relational database. Prior to versions 3.0.13, 4.0.6, and 5.0.3, there is an XDR message parsing NULL pointer derefe
5.3
MEDIUM
CVE-2025-24975
>= 4.0.0 and < 4.0.6
Firebird is a relational database. Prior to snapshot versions 4.0.6.3183, 5.0.2.1610, and 6.0.0.609, Firebird is vulnerable if Ext
7.1
HIGH
CVE-2023-41038
>= 4.0.0 and <= 4.0.3
Firebird is a relational database. Versions 4.0.0 through 4.0.3 and version 5.0 beta1 are vulnerable to a server crash when a user
7.5
HIGH
CVE-2017-11509
all versions
An authenticated remote attacker can execute arbitrary code in Firebird SQL Server versions 2.5.7 and 3.0.2 by executing a malform
8.8
HIGH
CVE-2017-6369
>= 2.5.0 and < 2.5.7
Insufficient checks in the UDF subsystem in Firebird 2.5.x before 2.5.7 and 3.0.x before 3.0.2 allow remote authenticated users to
8.8
HIGH
CVE-2016-1569
all versions
FireBird 2.5.5 allows remote authenticated users to cause a denial of service (daemon crash) by using service manager to invoke th
6.5
MEDIUM
CVE-2014-9323
< 2.1.7
The xdr_status_vector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote attackers to cause a denial of se
CVE-2013-2492
all versions
Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 before 26623, on Windows allows
CVE-2012-5529
all versions
TraceManager in Firebird 2.5.0 and 2.5.1, when trace is enabled, allows remote authenticated users to cause a denial of service (N
CVE-2009-2620
>= 1.5 and < 1.5.6
src/remote/server.cpp in fbserver.exe in Firebird SQL 1.5 before 1.5.6, 2.0 before 2.0.6, 2.1 before 2.1.3, and 2.5 before 2.5 Bet
CVE-2008-1880
<= 2.0.3.12981.0
The default configuration of Firebird before 2.0.3.12981.0-r6 on Gentoo Linux sets the ISC_PASSWORD environment variable before st
CVE-2008-0467
<= 2.0.3
Stack-based buffer overflow in Firebird before 2.0.4, and 2.1.x before 2.1.0 RC1, might allow remote attackers to execute arbitrar
CVE-2008-0387
<= 1.0.3
Integer overflow in Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6, 2.0.x before 2.0.4, and 2.1.x before 2.1.0 RC1 might allow
CVE-2007-4992
all versions
Stack-based buffer overflow in the process_packet function in fbserver.exe in Firebird SQL 2.0.2 allows remote attackers to execut
CVE-2007-5246
all versions
Multiple stack-based buffer overflows in Firebird LI 2.0.0.12748 and 2.0.1.12855, and WI 2.0.0.12748 and 2.0.1.12855, allow remote
CVE-2007-5245
all versions
Multiple stack-based buffer overflows in Firebird LI 1.5.3.4870 and 1.5.4.4910, and WI 1.5.3.4870 and 1.5.4.4910, allow remote att
CVE-2007-4669
<= 2.0.1
The Services API in Firebird before 2.0.2 allows remote authenticated users without SYSDBA privileges to read the server log (fire
CVE-2007-4668
<= 2.0.1
Unspecified vulnerability in the server in Firebird before 2.0.2 allows remote attackers to determine the existence of arbitrary f
CVE-2007-4667
<= 2.0.1
Unspecified vulnerability in the Services API in Firebird before 2.0.2 allows remote attackers to cause a denial of service, aka C
CVE-2007-4666
<= 2.0.1
Unspecified vulnerability in the server in Firebird before 2.0.2, when a Superserver/TCP/IP environment is configured, allows remo
CVE-2007-4665
<= 2.0.1
Unspecified vulnerability in the server in Firebird before 2.0.2 allows remote attackers to cause a denial of service (daemon cras
CVE-2007-4664
<= 2.0.1
Unspecified vulnerability in the (1) attach database and (2) create database functionality in Firebird before 2.0.2, when a filena
CVE-2007-3527
all versions
Integer overflow in Firebird 2.0.0 allows remote authenticated users to cause a denial of service (CPU consumption) via certain da
CVE-2006-7214
all versions
Multiple unspecified vulnerabilities in Firebird 1.5 allow remote attackers to (1) cause a denial of service (application crash) b
CVE-2006-7213
all versions
Firebird 1.5 allows remote authenticated users without SYSDBA and owner permissions to overwrite a database by creating a database
CVE-2006-7212
all versions
Multiple buffer overflows in Firebird 1.5, one of which affects WNET, have unknown impact and attack vectors. NOTE: this issue mi
CVE-2006-7211
all versions
fb_lock_mgr in Firebird 1.5 uses weak permissions (0666) for the semaphore array, which allows local users to cause a denial of se
CVE-2007-3181
<= 2.0.0
Buffer overflow in fbserver.exe in Firebird SQL 2 before 2.0.1 allows remote attackers to execute arbitrary code via a large p_cnc
CVE-2007-2606
all versions
Multiple buffer overflows in Firebird 2.1 allow attackers to trigger memory corruption and possibly have other unspecified impact
CVE-2006-1241
all versions
Firebird 1.5.2.4731 installs (1) fb_lock_mgr, (2) gds_drop, and (3) fb_inet_server with setuid firebird permissions, which might a
CVE-2006-1240
all versions
Buffer overflow in inet_server.cpp in (1) fb_inet_server and (2) fbserver in Firebird 1.5.2.4731 allows local users to gain privil
CVE-2004-1449
all versions
Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7 allows remote attackers to determine the location of files on a
CVE-2004-0779
all versions
The (1) Mozilla 1.6, (2) Firebird 0.7 and (3) Firefox 0.8 web browsers do not properly verify that cached passwords for SSL encryp
CVE-2004-0718
all versions
The (1) Mozilla 1.6, (2) Firebird 0.7, (3) Firefox 0.8, and (4) Netscape 7.1 web browsers do not properly prevent a frame in one d
CVE-2004-2043
all versions
Buffer overflow in ibserver for Firebird Database 1.0 and other versions before 1.5, and possibly other products that use the Inte
CVE-2003-0281
all versions
Buffer overflow in Firebird 1.0.2 and other versions before 1.5, and possibly other products that use the InterBase codebase, allo
CVE-2003-0197
all versions
Buffer overflow gds_lock_mgr of Interbase Database 6.x allows local users to gain privileges via a long ISC_LOCK_ENV environment v
CVE-2001-0008
<= 0.9.3
Backdoor account in Interbase database server allows remote attackers to overwrite arbitrary files using stored procedures.
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin