โ† All reports

FirebirdSQL versions prior to 5.0.4, 4.0.7, and 3.0.14 are vulnerable to information leaks due to improper validation of data lengths in specific network packets.

CybersecurityApr 17, 2026score 0.2810 posts ยท 0 replies across 2 instances
Multiple vulnerabilities were reported in FirebirdSQL versions prior to 5.0.4, 4.0.7, and 3.0.14, affecting data integrity and security. These issues involve improper validation of data lengths, unprepared structures, and potential path manipulation, leading to information leaks and potential system compromise.

Claims

FirebirdSQL versions prior to 5.0.4, 4.0.7, and 3.0.14 are vulnerable to information leaks due to improper validation of data lengths in specific network packets.
Parent: FirebirdSQLEntity: Database Management SystemImpact: negativeDate: Apr 17, 2026Target: FirebirdSQL versions prior to 5.0.4, 4.0.7, and 3.0.14
FirebirdSQL versions prior to 5.0.4, 4.0.7, and 3.0.14 are vulnerable to potential system compromise due to unprepared structures and path manipulation in external engine plugins.
Parent: FirebirdSQLEntity: Database Management SystemImpact: negativeDate: Apr 17, 2026Target: FirebirdSQL versions prior to 5.0.4, 4.0.7, and 3.0.14

Source posts

@[email protected]
๐Ÿšจ EUVD-2026-23466 ๐Ÿ“Š Score: 6.0/10 (CVSS v3.1) ๐Ÿ“ฆ Product: firebird, firebird, firebird ๐Ÿข Vendor: FirebirdSQL ๐Ÿ“… Updated: 2026-04-17 ๐Ÿ“ Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the ClumpletReader::getClumpletSize() function can overflow the totalLength value when parsing a Wide type clumplet, caus... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23466 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 17, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-23486 ๐Ÿ“Š Score: 7.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: firebird, firebird, firebird ๐Ÿข Vendor: FirebirdSQL ๐Ÿ“… Updated: 2026-04-17 ๐Ÿ“ Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the xdr_status_vector() function does not handle the isc_arg_cstring type when decoding an op_response packet, causing a ... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23486 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 17, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-23490 ๐Ÿ“Š Score: 7.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: firebird, firebird, firebird ๐Ÿข Vendor: FirebirdSQL ๐Ÿ“… Updated: 2026-04-17 ๐Ÿ“ Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the sdl_desc() function does not validate the length of a decoded SDL descriptor from a slice packet. A zero-length descr... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23490 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 17, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-23482 ๐Ÿ“Š Score: 7.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: firebird, firebird, firebird ๐Ÿข Vendor: FirebirdSQL ๐Ÿ“… Updated: 2026-04-17 ๐Ÿ“ Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when deserializing a slice packet, the xdr_datum() function does not validate that a cstring length conforms to the slice... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23482 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 17, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-23496 ๐Ÿ“Š Score: 10.0/10 (CVSS v3.1) ๐Ÿ“ฆ Product: firebird, firebird, firebird ๐Ÿข Vendor: FirebirdSQL ๐Ÿ“… Updated: 2026-04-17 ๐Ÿ“ Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader concatenates a user-supplied engine name into a filesystem path without filtering path... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23496 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 17, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-23468 ๐Ÿ“Š Score: 8.2/10 (CVSS v3.1) ๐Ÿ“ฆ Product: firebird, firebird, firebird ๐Ÿข Vendor: FirebirdSQL ๐Ÿ“… Updated: 2026-04-17 ๐Ÿ“ Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when the server receives an op_crypt_key_callback packet without prior authentication, the port_server_crypt_callback han... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23468 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 17, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-23462 ๐Ÿ“Š Score: 7.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: firebird, firebird, firebird ๐Ÿข Vendor: FirebirdSQL ๐Ÿ“… Updated: 2026-04-17 ๐Ÿ“ Firebird is an open-source relational database management system. In versions prior to 6.0.0, 5.0.4, 4.0.7 and 3.0.14, when processing an op_slice network packet, the server passes an unprepared structure containing a null pointer to... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23462 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 17, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-23460 ๐Ÿ“Š Score: 8.2/10 (CVSS v3.1) ๐Ÿ“ฆ Product: firebird, firebird, firebird ๐Ÿข Vendor: FirebirdSQL ๐Ÿ“… Updated: 2026-04-17 ๐Ÿ“ Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14,, when processing CNCT_specific_data segments during authentication, the server assumes segments arrive in strictly ascend... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23460 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 17, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2025-209528 ๐Ÿ“Š Score: 7.9/10 (CVSS v3.1) ๐Ÿ“ฆ Product: firebird ๐Ÿข Vendor: FirebirdSQL ๐Ÿ“… Updated: 2026-04-17 ๐Ÿ“ Firebird is an open-source relational database management system. In versions FB3 of the client library placed incorrect data length values into XSQLDA fields when communicating with FB4 or higher servers, resulting in an information leak. This issue ... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-209528 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 17, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐ŸŸ  CVE-2026-33337 - High (7.5) Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when deserializing a slice packet, the xdr_datum() function does not validate that a cstring length conforms to the slice descriptor bo... ๐Ÿ”— https://www.thehackerwire.com/vulnerability/CVE-2026-33337/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
0 boosts ยท 0 favs ยท 0 replies ยท Apr 17, 2026
#cve#vulnerability#infosec#cybersecurity#security#tenda