Firebirdsql Firebird vulnerabilities

37 known vulnerabilities affecting firebirdsql/firebird.

Total CVEs
37
CISA KEV
0
Public exploits
8
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH12MEDIUM17LOW2

Vulnerabilities

Page 1 of 2
CVE-2025-54989HIGHCVSS 7.5fixed in 3.0.13≥ 4.0.0, < 4.0.6+3 more2025-08-15
CVE-2025-54989 [HIGH] CWE-476 CVE-2025-54989: Firebird is a relational database. Prior to versions 3.0.13, 4.0.6, and 5.0.3, there is an XDR messa Firebird is a relational database. Prior to versions 3.0.13, 4.0.6, and 5.0.3, there is an XDR message parsing NULL pointer dereference denial-of-service vulnerability in Firebird. This specific flaw exists within the parsing of xdr message from client. It leads to NULL pointer dereference and DoS. This issue has been patched in versions 3.0.13, 4.0.6
cvelistv5nvd
CVE-2025-24975HIGHCVSS 8.8≥ 4.0.0, < 4.0.6≥ 5.0.0, < 5.0.2+3 more2025-08-15
CVE-2025-24975 [HIGH] CWE-754 CVE-2025-24975: Firebird is a relational database. Prior to snapshot versions 4.0.6.3183, 5.0.2.1610, and 6.0.0.609, Firebird is a relational database. Prior to snapshot versions 4.0.6.3183, 5.0.2.1610, and 6.0.0.609, Firebird is vulnerable if ExtConnPoolSize is not set equal to 0. If connections stored in ExtConnPool are not verified for presence and suitability of the CryptCallback interface is used when created versus what is available could result in a segfault
cvelistv5nvd
CVE-2023-41038HIGHCVSS 7.5≥ 4.0.0, ≤ 4.0.3v5.0+2 more2024-03-20
CVE-2023-41038 [HIGH] CWE-770 CVE-2023-41038: Firebird is a relational database. Versions 4.0.0 through 4.0.3 and version 5.0 beta1 are vulnerable Firebird is a relational database. Versions 4.0.0 through 4.0.3 and version 5.0 beta1 are vulnerable to a server crash when a user uses a specific form of SET BIND statement. Any non-privileged user with minimum access to a server may type a statement with a long `CHAR` length, which causes the server to crash due to stack corruption. Versions 4.0.4.2
cvelistv5nvd
CVE-2017-11509HIGHCVSS 8.8v2.5.7v3.0.22018-03-28
CVE-2017-11509 [HIGH] CWE-89 CVE-2017-11509: An authenticated remote attacker can execute arbitrary code in Firebird SQL Server versions 2.5.7 an An authenticated remote attacker can execute arbitrary code in Firebird SQL Server versions 2.5.7 and 3.0.2 by executing a malformed SQL statement.
nvd
CVE-2017-6369HIGHCVSS 8.8≥ 2.5.0, < 2.5.7≥ 3.0.0, < 3.0.22017-03-24
CVE-2017-6369 [HIGH] CWE-862 CVE-2017-6369: Insufficient checks in the UDF subsystem in Firebird 2.5.x before 2.5.7 and 3.0.x before 3.0.2 allow Insufficient checks in the UDF subsystem in Firebird 2.5.x before 2.5.7 and 3.0.x before 3.0.2 allow remote authenticated users to execute code by using a 'system' entrypoint from fbudf.so.
nvd
CVE-2016-1569MEDIUMCVSS 6.5v2.5.52016-01-13
CVE-2016-1569 [MEDIUM] CWE-20 CVE-2016-1569: FireBird 2.5.5 allows remote authenticated users to cause a denial of service (daemon crash) by usin FireBird 2.5.5 allows remote authenticated users to cause a denial of service (daemon crash) by using service manager to invoke the gbak utility with an invalid parameter.
nvd
CVE-2014-9323MEDIUMCVSS 5.0fixed in 2.1.7≥ 2.5, ≤ 2.5.32014-12-16
CVE-2014-9323 [MEDIUM] CWE-476 CVE-2014-9323: The xdr_status_vector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote att The xdr_status_vector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote attackers to cause a denial of service (NULL pointer dereference, segmentation fault, and crash) via an op_response action with a non-empty status.
nvd
CVE-2013-2492MEDIUMCVSS 6.8PoCv2.1.3v2.1.4+4 more2013-03-15
CVE-2013-2492 [MEDIUM] CWE-119 CVE-2013-2492: Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 be Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 before 26623, on Windows allows remote attackers to execute arbitrary code via a crafted packet to TCP port 3050, related to a missing size check during extraction of a group number from CNCT information.
nvd
CVE-2012-5529LOWCVSS 3.5v2.5.0v2.5.12012-11-20
CVE-2012-5529 [LOW] CWE-399 CVE-2012-5529: TraceManager in Firebird 2.5.0 and 2.5.1, when trace is enabled, allows remote authenticated users t TraceManager in Firebird 2.5.0 and 2.5.1, when trace is enabled, allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) by preparing an empty dynamic SQL query.
nvd
CVE-2009-2620MEDIUMCVSS 5.0PoC≥ 1.5, < 1.5.6≥ 2.0.0, < 2.0.6+2 more2009-07-29
CVE-2009-2620 [MEDIUM] CWE-20 CVE-2009-2620: src/remote/server.cpp in fbserver.exe in Firebird SQL 1.5 before 1.5.6, 2.0 before 2.0.6, 2.1 before src/remote/server.cpp in fbserver.exe in Firebird SQL 1.5 before 1.5.6, 2.0 before 2.0.6, 2.1 before 2.1.3, and 2.5 before 2.5 Beta 2 allows remote attackers to cause a denial of service (daemon crash) via a malformed op_connect_request message that triggers an infinite loop or NULL pointer dereference.
nvd
CVE-2008-0467CRITICALCVSS 10.0≤ 2.0.3≤ 2.12008-01-29
CVE-2008-0467 [CRITICAL] CWE-119 CVE-2008-0467: Stack-based buffer overflow in Firebird before 2.0.4, and 2.1.x before 2.1.0 RC1, might allow remote Stack-based buffer overflow in Firebird before 2.0.4, and 2.1.x before 2.1.0 RC1, might allow remote attackers to execute arbitrary code via a long username.
nvd
CVE-2008-0387HIGHCVSS 7.8PoC≤ 1.0.3≥ 1.5, < 1.5.6+2 more2008-01-29
CVE-2008-0387 [HIGH] CWE-189 CVE-2008-0387: Integer overflow in Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6, 2.0.x before 2.0.4, and 2.1. Integer overflow in Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6, 2.0.x before 2.0.4, and 2.1.x before 2.1.0 RC1 might allow remote attackers to execute arbitrary code via crafted (1) op_receive, (2) op_start, (3) op_start_and_receive, (4) op_send, (5) op_start_and_send, and (6) op_start_send_and_receive XDR requests, which triggers memory corrupt
nvd
CVE-2007-4992CRITICALCVSS 10.0v2.0.22007-10-11
CVE-2007-4992 [CRITICAL] CWE-119 CVE-2007-4992: Stack-based buffer overflow in the process_packet function in fbserver.exe in Firebird SQL 2.0.2 all Stack-based buffer overflow in the process_packet function in fbserver.exe in Firebird SQL 2.0.2 allows remote attackers to execute arbitrary code via a long request to TCP port 3050.
nvd
CVE-2007-5246CRITICALCVSS 10.0v2.0.0.12748v2.0.1.128552007-10-06
CVE-2007-5246 [CRITICAL] CWE-119 CVE-2007-5246: Multiple stack-based buffer overflows in Firebird LI 2.0.0.12748 and 2.0.1.12855, and WI 2.0.0.12748 Multiple stack-based buffer overflows in Firebird LI 2.0.0.12748 and 2.0.1.12855, and WI 2.0.0.12748 and 2.0.1.12855, allow remote attackers to execute arbitrary code via (1) a long attach request on TCP port 3050 to the isc_attach_database function or (2) a long create request on TCP port 3050 to the isc_create_database function.
nvd
CVE-2007-5245CRITICALCVSS 10.0v1.5.3.4870v1.5.4.49102007-10-06
CVE-2007-5245 [CRITICAL] CWE-119 CVE-2007-5245: Multiple stack-based buffer overflows in Firebird LI 1.5.3.4870 and 1.5.4.4910, and WI 1.5.3.4870 an Multiple stack-based buffer overflows in Firebird LI 1.5.3.4870 and 1.5.4.4910, and WI 1.5.3.4870 and 1.5.4.4910, allow remote attackers to execute arbitrary code via (1) a long service attach request on TCP port 3050 to the SVC_attach function or (2) unspecified vectors involving the INET_connect function.
nvd
CVE-2007-4664HIGHCVSS 7.5≤ 2.0.12007-09-04
CVE-2007-4664 [HIGH] CWE-20 CVE-2007-4664: Unspecified vulnerability in the (1) attach database and (2) create database functionality in Firebi Unspecified vulnerability in the (1) attach database and (2) create database functionality in Firebird before 2.0.2, when a filename exceeds MAX_PATH_LEN, has unknown impact and attack vectors, aka CORE-1405.
nvd
CVE-2007-4667MEDIUMCVSS 5.0≤ 2.0.12007-09-04
CVE-2007-4667 [MEDIUM] CVE-2007-4667: Unspecified vulnerability in the Services API in Firebird before 2.0.2 allows remote attackers to ca Unspecified vulnerability in the Services API in Firebird before 2.0.2 allows remote attackers to cause a denial of service, aka CORE-1149.
nvd
CVE-2007-4665MEDIUMCVSS 5.0≤ 2.0.12007-09-04
CVE-2007-4665 [MEDIUM] CWE-119 CVE-2007-4665: Unspecified vulnerability in the server in Firebird before 2.0.2 allows remote attackers to cause a Unspecified vulnerability in the server in Firebird before 2.0.2 allows remote attackers to cause a denial of service (daemon crash) via an XNET session that makes multiple simultaneous requests to register events, aka CORE-1403.
nvd
CVE-2007-4669MEDIUMCVSS 4.0≤ 2.0.12007-09-04
CVE-2007-4669 [MEDIUM] CWE-200 CVE-2007-4669: The Services API in Firebird before 2.0.2 allows remote authenticated users without SYSDBA privilege The Services API in Firebird before 2.0.2 allows remote authenticated users without SYSDBA privileges to read the server log (firebird.log), aka CORE-1148.
nvd
CVE-2007-4668MEDIUMCVSS 5.0≤ 2.0.12007-09-04
CVE-2007-4668 [MEDIUM] CWE-119 CVE-2007-4668: Unspecified vulnerability in the server in Firebird before 2.0.2 allows remote attackers to determin Unspecified vulnerability in the server in Firebird before 2.0.2 allows remote attackers to determine the existence of arbitrary files, and possibly obtain other "file access," via unknown vectors, aka CORE-1312.
nvd