📦

firebird

Vendor: firebirdsql

Actively Exploited 0 CISA KEV List
PoC / Exploits 8 Code Available
Total RCEs 9 Remote Access
Total CVEs 62 Total Indexed
Avg. EPSS 8.14% Exploit Prob.
Latest CVE CVE-2026-40342 Apr 17

Security Vulnerability Index

Page 5 / 7
7.5 CVSS

The (1) Mozilla 1.6, (2) Firebird 0.7 and (3) Firefox 0.8 web browsers do not properly verify that cached passwords for SSL encrypted sites are only sent via SSL encrypted sessions to the site, which allows a remote attacker to cause a cached password to be sent in cleartext to a spoofed site.

EPSS: 0.79%
7.5 CVSS

The (1) Mozilla 1.6, (2) Firebird 0.7, (3) Firefox 0.8, and (4) Netscape 7.1 web browsers do not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.

EPSS: 1.91%
5.0 CVSS
CVE-2004-2043
Exploit Found

Buffer overflow in ibserver for Firebird Database 1.0 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows remote attackers to cause a denial of service (crash) via a long database name, as demonstrated using the gsec command.

EPSS: 47.46%
4.6 CVSS
CVE-2003-0281
RCE Exploit Found

Buffer overflow in Firebird 1.0.2 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows local users to execute arbitrary code via a long INTERBASE environment variable when calling (1) gds_inet_server, (2) gds_lock_mgr, or (3) gds_drop.

EPSS: 0.12%
7.2 CVSS

Buffer overflow gds_lock_mgr of Interbase Database 6.x allows local users to gain privileges via a long ISC_LOCK_ENV environment variable (INTERBASE_LOCK).

EPSS: 0.05%
10.0 CVSS
CVE-2001-0008
Exploit Found

Backdoor account in Interbase database server allows remote attackers to overwrite arbitrary files using stored procedures.

EPSS: 20.17%