// For flags

CVE-2007-5245

 

Severity Score

10.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

3
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple stack-based buffer overflows in Firebird LI 1.5.3.4870 and 1.5.4.4910, and WI 1.5.3.4870 and 1.5.4.4910, allow remote attackers to execute arbitrary code via (1) a long service attach request on TCP port 3050 to the SVC_attach function or (2) unspecified vectors involving the INET_connect function.

Múltiples desbordamientos de búfer en Firebird LI 1.5.3.4870 y 1.5.4.4910, y WI 1.5.3.4870 y 1.5.4.4910, permite a atacantes remotos ejecutar código de su elección a través de (1) una petición larga de fijación del servicio sobre TCP puerto 3050 en la función SVC_attach o (2) vectores no especificados afectando a la función INET_connect.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2007-10-06 CVE Reserved
  • 2007-10-06 CVE Published
  • 2024-07-02 EPSS Updated
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Firebirdsql
Search vendor "Firebirdsql"
Firebird
Search vendor "Firebirdsql" for product "Firebird"
1.5.3.4870
Search vendor "Firebirdsql" for product "Firebird" and version "1.5.3.4870"
linux
Affected
Firebirdsql
Search vendor "Firebirdsql"
Firebird
Search vendor "Firebirdsql" for product "Firebird"
1.5.3.4870
Search vendor "Firebirdsql" for product "Firebird" and version "1.5.3.4870"
windows
Affected
Firebirdsql
Search vendor "Firebirdsql"
Firebird
Search vendor "Firebirdsql" for product "Firebird"
1.5.4.4910
Search vendor "Firebirdsql" for product "Firebird" and version "1.5.4.4910"
linux
Affected
Firebirdsql
Search vendor "Firebirdsql"
Firebird
Search vendor "Firebirdsql" for product "Firebird"
1.5.4.4910
Search vendor "Firebirdsql" for product "Firebird" and version "1.5.4.4910"
windows
Affected