CVE-2008-0387
RCETitle: Firebirdsql Firebird RCE
RCE
Proof Of Concept
PoC Available for CVE-2008-0387
CWE Category
CWE-189
Published Date
Jan 29, 2008
Modified Date
Apr 09, 2025
Exploit Status
Available
Score
7.8
CVSS v2.0
Exploit Probability (EPSS)
59.91%
Vulnerability Summary
CVE-2008-0387: Integer overflow in Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6, 2.0.x before 2.0.4, and 2.1.x before 2.1.0 RC1 might allow remote attackers to execute arbitrary code via crafted (1) op_receive, (2) op_start, (3) op_start_and_receive, (4) op_send, (5) op_start_and_send, and (6) op_start_send_and_receive XDR requests, which triggers memory corruption.
Impacted Vendors
Reference Links
http://secunia.com/advisories/29203
http://secunia.com/advisories/29501
http://security.gentoo.org/glsa/glsa-200803-02.xml
http://securityreason.com/securityalert/3580
http://sourceforge.net/project/shownotes.php?group_id=9028&release_id=570800
http://tracker.firebirdsql.org/browse/CORE-1681
http://www.coresecurity.com/?action=item&id=2095
http://www.debian.org/security/2008/dsa-1529
http://www.securityfocus.com/archive/1/487173/100/0/threaded
http://www.securityfocus.com/bid/27403
https://exchange.xforce.ibmcloud.com/vulnerabilities/39996
http://secunia.com/advisories/29203
http://secunia.com/advisories/29501
http://security.gentoo.org/glsa/glsa-200803-02.xml
http://securityreason.com/securityalert/3580
http://sourceforge.net/project/shownotes.php?group_id=9028&release_id=570800
http://tracker.firebirdsql.org/browse/CORE-1681
http://www.coresecurity.com/?action=item&id=2095
http://www.debian.org/security/2008/dsa-1529
http://www.securityfocus.com/archive/1/487173/100/0/threaded
http://www.securityfocus.com/bid/27403
https://exchange.xforce.ibmcloud.com/vulnerabilities/39996
CVSS v2.0
Source Entity
[email protected]
Severity
HIGH
7.8
Access Vector
N/A
Authentication
N/A
RAW VECTOR
AV:N/AC:L/Au:N/C:N/I:N/A:C
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2008-0387 Exploits & PoCs (Proof Of Concept)
Exploit-DB
https://www.exploit-db.com/exploits/31050
MODIFIED
Vulnerability data or affected products updated.
PUBLISHED
Vulnerability first announced in NVD.
Attack Vector Matrix
Access Vector
N/A
Complexity
N/A
Privileges
N/A
Interaction
NONE
CVSS Vector String
AV:N/AC:L/Au:N/C:N/I:N/A:C
Affected Stack
No specific products linked.