// For flags

CVE-2007-5246

 

Severity Score

10.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple stack-based buffer overflows in Firebird LI 2.0.0.12748 and 2.0.1.12855, and WI 2.0.0.12748 and 2.0.1.12855, allow remote attackers to execute arbitrary code via (1) a long attach request on TCP port 3050 to the isc_attach_database function or (2) a long create request on TCP port 3050 to the isc_create_database function.

Múltiples desbordamientos de búfer en FFirebird LI 2.0.0.12748 and 2.0.1.12855, and WI 2.0.0.12748 and 2.0.1.12855, permite a atacantes remotos ejecutar código de su elección a través de (1) una petición larga de fijación del servicio sobre TCP puerto 3050 en la función isc_attach_database o (2) petición de creación larga sobre el puerto 3050 TCP en la función isc_create_database.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2007-10-06 CVE Reserved
  • 2007-10-06 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-09-16 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Firebirdsql
Search vendor "Firebirdsql"
Firebird
Search vendor "Firebirdsql" for product "Firebird"
2.0.0.12748
Search vendor "Firebirdsql" for product "Firebird" and version "2.0.0.12748"
linux
Affected
Firebirdsql
Search vendor "Firebirdsql"
Firebird
Search vendor "Firebirdsql" for product "Firebird"
2.0.0.12748
Search vendor "Firebirdsql" for product "Firebird" and version "2.0.0.12748"
windows
Affected
Firebirdsql
Search vendor "Firebirdsql"
Firebird
Search vendor "Firebirdsql" for product "Firebird"
2.0.1.12855
Search vendor "Firebirdsql" for product "Firebird" and version "2.0.1.12855"
linux
Affected
Firebirdsql
Search vendor "Firebirdsql"
Firebird
Search vendor "Firebirdsql" for product "Firebird"
2.0.1.12855
Search vendor "Firebirdsql" for product "Firebird" and version "2.0.1.12855"
windows
Affected