← All CVEs

CVE-2008-0387

high · 7.8

Integer overflow in Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6, 2.0.x before 2.0.4, and 2.1.x before 2.1.0 RC1 might allow remote attackers to execute arbitrary code via crafted (1) op_receive, (2) op_start, (3) op_start_and_receive, (4) op_send, (5) op_start_and_send, and (6) op_start_send_and_receive XDR requests, which triggers memory corruption.

7.8
CVSS
45.9%
EPSS (exploit prob.)
99th
EPSS percentile
2008-01-29
Published

AV:N/AC:L/Au:N/C:N/I:N/A:C

Weaknesses

CWE-189

Affected products

VendorProductAffected versions
firebirdsqlfirebird<= 1.0.3
firebirdsqlfirebird>= 1.5, < 1.5.6
firebirdsqlfirebird>= 2.0.0, < 2.0.4
firebirdsqlfirebird2.1.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2008-0387