Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-0387

Опубликовано: 29 янв. 2008
Источник: nvd
CVSS2: 7.8
EPSS Средний

Описание

Integer overflow in Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6, 2.0.x before 2.0.4, and 2.1.x before 2.1.0 RC1 might allow remote attackers to execute arbitrary code via crafted (1) op_receive, (2) op_start, (3) op_start_and_receive, (4) op_send, (5) op_start_and_send, and (6) op_start_send_and_receive XDR requests, which triggers memory corruption.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:firebirdsql:firebird:*:*:*:*:*:*:*:*
Версия до 1.0.3 (включая)
cpe:2.3:a:firebirdsql:firebird:*:*:*:*:*:*:*:*
Версия от 1.5 (включая) до 1.5.6 (исключая)
cpe:2.3:a:firebirdsql:firebird:*:*:*:*:*:*:*:*
Версия от 2.0.0 (включая) до 2.0.4 (исключая)
cpe:2.3:a:firebirdsql:firebird:2.1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 98%
0.5991
Средний

7.8 High

CVSS2

Дефекты

CWE-189

Связанные уязвимости

ubuntu
почти 18 лет назад

Integer overflow in Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6, 2.0.x before 2.0.4, and 2.1.x before 2.1.0 RC1 might allow remote attackers to execute arbitrary code via crafted (1) op_receive, (2) op_start, (3) op_start_and_receive, (4) op_send, (5) op_start_and_send, and (6) op_start_send_and_receive XDR requests, which triggers memory corruption.

debian
почти 18 лет назад

Integer overflow in Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6 ...

github
больше 3 лет назад

Integer overflow in Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6, 2.0.x before 2.0.4, and 2.1.x before 2.1.0 RC1 might allow remote attackers to execute arbitrary code via crafted (1) op_receive, (2) op_start, (3) op_start_and_receive, (4) op_send, (5) op_start_and_send, and (6) op_start_send_and_receive XDR requests, which triggers memory corruption.

EPSS

Процентиль: 98%
0.5991
Средний

7.8 High

CVSS2

Дефекты

CWE-189