CVE-2008-0387
high · 7.8Integer overflow in Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6, 2.0.x before 2.0.4, and 2.1.x before 2.1.0 RC1 might allow remote attackers to execute arbitrary code via crafted (1) op_receive, (2) op_start, (3) op_start_and_receive, (4) op_send, (5) op_start_and_send, and (6) op_start_send_and_receive XDR requests, which triggers memory corruption.
7.8
CVSS
45.9%
EPSS (exploit prob.)
99th
EPSS percentile
2008-01-29
Published
AV:N/AC:L/Au:N/C:N/I:N/A:C
Weaknesses
CWE-189
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| firebirdsql | firebird | <= 1.0.3 |
| firebirdsql | firebird | >= 1.5, < 1.5.6 |
| firebirdsql | firebird | >= 2.0.0, < 2.0.4 |
| firebirdsql | firebird | 2.1.0 |
Check a specific version with /api/v1/cve/match.
References
- http://secunia.com/advisories/29203
- http://secunia.com/advisories/29501
- http://security.gentoo.org/glsa/glsa-200803-02.xml
- http://securityreason.com/securityalert/3580
- http://sourceforge.net/project/shownotes.php?group_id=9028&release_id=570800
- http://tracker.firebirdsql.org/browse/CORE-1681
- http://www.coresecurity.com/?action=item&id=2095
- http://www.debian.org/security/2008/dsa-1529
- http://www.securityfocus.com/archive/1/487173/100/0/threaded
- http://www.securityfocus.com/bid/27403
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39996
- http://secunia.com/advisories/29203
- http://secunia.com/advisories/29501
- http://security.gentoo.org/glsa/glsa-200803-02.xml
- http://securityreason.com/securityalert/3580
- http://sourceforge.net/project/shownotes.php?group_id=9028&release_id=570800
- http://tracker.firebirdsql.org/browse/CORE-1681
- http://www.coresecurity.com/?action=item&id=2095
- http://www.debian.org/security/2008/dsa-1529
- http://www.securityfocus.com/archive/1/487173/100/0/threaded
- http://www.securityfocus.com/bid/27403
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39996
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2008-0387