FirebirdSQL versions prior to 5.0.4, 4.0.7, and 3.0.14 are vulnerable to information leaks due to improper validation of data lengths in specific network packets.
Claims
FirebirdSQL versions prior to 5.0.4, 4.0.7, and 3.0.14 are vulnerable to information leaks due to improper validation of data lengths in specific network packets.
Parent: FirebirdSQLEntity: Database Management SystemImpact: negativeDate: Apr 17, 2026Target: FirebirdSQL versions prior to 5.0.4, 4.0.7, and 3.0.14
FirebirdSQL versions prior to 5.0.4, 4.0.7, and 3.0.14 are vulnerable to potential system compromise due to unprepared structures and path manipulation in external engine plugins.
Parent: FirebirdSQLEntity: Database Management SystemImpact: negativeDate: Apr 17, 2026Target: FirebirdSQL versions prior to 5.0.4, 4.0.7, and 3.0.14
Source posts
๐จ EUVD-2026-23466
๐ Score: 6.0/10 (CVSS v3.1)
๐ฆ Product: firebird, firebird, firebird
๐ข Vendor: FirebirdSQL
๐
Updated: 2026-04-17
๐ Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the ClumpletReader::getClumpletSize() function can overflow the totalLength value when parsing a Wide type clumplet, caus...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23466
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 17, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-23486
๐ Score: 7.5/10 (CVSS v3.1)
๐ฆ Product: firebird, firebird, firebird
๐ข Vendor: FirebirdSQL
๐
Updated: 2026-04-17
๐ Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the xdr_status_vector() function does not handle the isc_arg_cstring type when decoding an op_response packet, causing a ...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23486
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 17, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-23490
๐ Score: 7.5/10 (CVSS v3.1)
๐ฆ Product: firebird, firebird, firebird
๐ข Vendor: FirebirdSQL
๐
Updated: 2026-04-17
๐ Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the sdl_desc() function does not validate the length of a decoded SDL descriptor from a slice packet. A zero-length descr...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23490
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 17, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-23482
๐ Score: 7.5/10 (CVSS v3.1)
๐ฆ Product: firebird, firebird, firebird
๐ข Vendor: FirebirdSQL
๐
Updated: 2026-04-17
๐ Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when deserializing a slice packet, the xdr_datum() function does not validate that a cstring length conforms to the slice...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23482
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 17, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-23496
๐ Score: 10.0/10 (CVSS v3.1)
๐ฆ Product: firebird, firebird, firebird
๐ข Vendor: FirebirdSQL
๐
Updated: 2026-04-17
๐ Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader concatenates a user-supplied engine name into a filesystem path without filtering path...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23496
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 17, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-23468
๐ Score: 8.2/10 (CVSS v3.1)
๐ฆ Product: firebird, firebird, firebird
๐ข Vendor: FirebirdSQL
๐
Updated: 2026-04-17
๐ Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when the server receives an op_crypt_key_callback packet without prior authentication, the port_server_crypt_callback han...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23468
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 17, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-23462
๐ Score: 7.5/10 (CVSS v3.1)
๐ฆ Product: firebird, firebird, firebird
๐ข Vendor: FirebirdSQL
๐
Updated: 2026-04-17
๐ Firebird is an open-source relational database management system. In versions prior to 6.0.0, 5.0.4, 4.0.7 and 3.0.14, when processing an op_slice network packet, the server passes an unprepared structure containing a null pointer to...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23462
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 17, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-23460
๐ Score: 8.2/10 (CVSS v3.1)
๐ฆ Product: firebird, firebird, firebird
๐ข Vendor: FirebirdSQL
๐
Updated: 2026-04-17
๐ Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14,, when processing CNCT_specific_data segments during authentication, the server assumes segments arrive in strictly ascend...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23460
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 17, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2025-209528
๐ Score: 7.9/10 (CVSS v3.1)
๐ฆ Product: firebird
๐ข Vendor: FirebirdSQL
๐
Updated: 2026-04-17
๐ Firebird is an open-source relational database management system. In versions FB3 of the client library placed incorrect data length values into XSQLDA fields when communicating with FB4 or higher servers, resulting in an information leak. This issue ...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-209528
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 17, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐ CVE-2026-33337 - High (7.5)
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when deserializing a slice packet, the xdr_datum() function does not validate that a cstring length conforms to the slice descriptor bo...
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-33337/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
0 boosts ยท 0 favs ยท 0 replies ยท Apr 17, 2026
#cve#vulnerability#infosec#cybersecurity#security#tenda