Firebird
Firebirdsql · 47 CVEs
Firebird: Path Traversal + Arbitrary File Write Leads to Remote Code Execution
Apr 17, 2026
Firebird: DoS via malicious slice descriptor in slice packet
Apr 17, 2026
Firebird: DoS via `op_response` packet from client
Apr 17, 2026
Firebird has a buffer overflow when parsing corrupted slice packets
Apr 17, 2026
Firebird Null Pointer Dereference via CryptCallback causes DOS
Apr 17, 2026
Firebird server hangs when using specific clumplet on batch creation
Apr 17, 2026
Firebird has Pre-Auth DOS when Processing Out of Order CNCT_specific_data Segments
Apr 17, 2026
Firebird has potential server crash via null pointer dereference when processing op_slice packet
Apr 17, 2026
Firebird: Information leak vulnerability in firebird3 client when used with newer server
Apr 17, 2026
Firebird Non-Authorized Access to Encrypted Database Using Execute Statement on External
Aug 15, 2025
Firebird XDR Message Parsing NULL Pointer Dereference Denial-of-Service Vulnerability
Aug 15, 2025
WordPress FileBird – WordPress Media Library Folders & File Manager plugin <= 5.6.3 - Sensitive Data Exposure vulnerabi…
May 13, 2024
Server crash when using specific form of SET BIND statement
Mar 20, 2024
firebird: Firebird fbudf Module Authenticated Remote Code Execution
Mar 28, 2018
Insufficient checks in the UDF subsystem in Firebird 2.5.x before 2.5.7 and 3.0.x before 3.0.2 allow remote authenticat…
Mar 24, 2017
FireBird 2.5.5 allows remote authenticated users to cause a denial of service (daemon crash) by using service manager t…
Jan 13, 2016
The xdr_status_vector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote attackers to cause a d…
Dec 16, 2014
Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 before 26623, on Wind…
Mar 15, 2013
TraceManager in Firebird 2.5.0 and 2.5.1, when trace is enabled, allows remote authenticated users to cause a denial of…
Nov 20, 2012
firebird-superserver: NULL ptr dereference (DoS) by handling auxiliary connection(s)
Jul 29, 2009
Stack-based buffer overflow in Firebird before 2.0.4, and 2.1.x before 2.1.0 RC1, might allow remote attackers to execu…
Jan 29, 2008
Integer overflow in Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6, 2.0.x before 2.0.4, and 2.1.x before 2.1.0 RC1…
Jan 29, 2008
Stack-based buffer overflow in the process_packet function in fbserver.exe in Firebird SQL 2.0.2 allows remote attacker…
Oct 11, 2007
Multiple stack-based buffer overflows in Firebird LI 2.0.0.12748 and 2.0.1.12855, and WI 2.0.0.12748 and 2.0.1.12855, a…
Oct 6, 2007
Multiple stack-based buffer overflows in Firebird LI 1.5.3.4870 and 1.5.4.4910, and WI 1.5.3.4870 and 1.5.4.4910, allow…
Oct 6, 2007
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-40342 | Firebird: Path Traversal + Arbitrary File Write Leads to Remote Code Execution | CRITICAL | 0.84% | Apr 17, 2026 |
| CVE-2026-35215 | Firebird: DoS via malicious slice descriptor in slice packet | HIGH | 0.69% | Apr 17, 2026 |
| CVE-2026-34232 | Firebird: DoS via `op_response` packet from client | HIGH | 0.69% | Apr 17, 2026 |
| CVE-2026-33337 | Firebird has a buffer overflow when parsing corrupted slice packets | HIGH | 0.81% | Apr 17, 2026 |
| CVE-2026-28224 | Firebird Null Pointer Dereference via CryptCallback causes DOS | HIGH | 0.72% | Apr 17, 2026 |
| CVE-2026-28214 | Firebird server hangs when using specific clumplet on batch creation | MEDIUM | 0.59% | Apr 17, 2026 |
| CVE-2026-27890 | Firebird has Pre-Auth DOS when Processing Out of Order CNCT_specific_data Segments | HIGH | 0.72% | Apr 17, 2026 |
| CVE-2026-28212 | Firebird has potential server crash via null pointer dereference when processing op_slice packet | HIGH | 0.75% | Apr 17, 2026 |
| CVE-2025-65104 | Firebird: Information leak vulnerability in firebird3 client when used with newer server | HIGH | 0.18% | Apr 17, 2026 |
| CVE-2025-24975 | Firebird Non-Authorized Access to Encrypted Database Using Execute Statement on External | HIGH | 0.52% | Aug 15, 2025 |
| CVE-2025-54989 | Firebird XDR Message Parsing NULL Pointer Dereference Denial-of-Service Vulnerability | HIGH | 0.58% | Aug 15, 2025 |
| CVE-2024-35166 | WordPress FileBird – WordPress Media Library Folders & File Manager plugin <= 5.6.3 - Sensitive Data Exposure vulnerability | HIGH | 0.57% | May 13, 2024 |
| CVE-2023-41038 | Server crash when using specific form of SET BIND statement | HIGH | 0.66% | Mar 20, 2024 |
| CVE-2017-11509 | firebird: Firebird fbudf Module Authenticated Remote Code Execution | HIGH | 6.18% | Mar 28, 2018 |
| CVE-2017-6369 | Insufficient checks in the UDF subsystem in Firebird 2.5.x before 2.5.7 and 3.0.x before 3.0.2 allow remote authenticated users to execute code by using a 'sys… | HIGH | 3.27% | Mar 24, 2017 |
| CVE-2016-1569 | FireBird 2.5.5 allows remote authenticated users to cause a denial of service (daemon crash) by using service manager to invoke the gbak utility with an invali… | MEDIUM | 2.30% | Jan 13, 2016 |
| CVE-2014-9323 | The xdr_status_vector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote attackers to cause a denial of service (NULL pointer dereferen… | MEDIUM | 2.90% | Dec 16, 2014 |
| CVE-2013-2492 | Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 before 26623, on Windows allows remote attackers to execute a… | MEDIUM | 42.17% | Mar 15, 2013 |
| CVE-2012-5529 | TraceManager in Firebird 2.5.0 and 2.5.1, when trace is enabled, allows remote authenticated users to cause a denial of service (NULL pointer dereference and c… | LOW | 1.84% | Nov 20, 2012 |
| CVE-2009-2620 | firebird-superserver: NULL ptr dereference (DoS) by handling auxiliary connection(s) | MEDIUM | 8.63% | Jul 29, 2009 |
| CVE-2008-0467 | Stack-based buffer overflow in Firebird before 2.0.4, and 2.1.x before 2.1.0 RC1, might allow remote attackers to execute arbitrary code via a long username. | HIGH | 6.44% | Jan 29, 2008 |
| CVE-2008-0387 | Integer overflow in Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6, 2.0.x before 2.0.4, and 2.1.x before 2.1.0 RC1 might allow remote attackers to execute… | HIGH | 45.87% | Jan 29, 2008 |
| CVE-2007-4992 | Stack-based buffer overflow in the process_packet function in fbserver.exe in Firebird SQL 2.0.2 allows remote attackers to execute arbitrary code via a long r… | HIGH | 7.69% | Oct 11, 2007 |
| CVE-2007-5246 | Multiple stack-based buffer overflows in Firebird LI 2.0.0.12748 and 2.0.1.12855, and WI 2.0.0.12748 and 2.0.1.12855, allow remote attackers to execute arbitra… | HIGH | 6.64% | Oct 6, 2007 |
| CVE-2007-5245 | Multiple stack-based buffer overflows in Firebird LI 1.5.3.4870 and 1.5.4.4910, and WI 1.5.3.4870 and 1.5.4.4910, allow remote attackers to execute arbitrary c… | HIGH | 8.88% | Oct 6, 2007 |
Showing 1 to 25 of 47 CVEs