Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-2492

Опубликовано: 15 мар. 2013
Источник: nvd
CVSS2: 6.8
EPSS Высокий

Описание

Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 before 26623, on Windows allows remote attackers to execute arbitrary code via a crafted packet to TCP port 3050, related to a missing size check during extraction of a group number from CNCT information.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:firebirdsql:firebird:2.1.3:*:*:*:*:*:*:*
cpe:2.3:a:firebirdsql:firebird:2.1.4:*:*:*:*:*:*:*
cpe:2.3:a:firebirdsql:firebird:2.1.5:*:*:*:*:*:*:*
cpe:2.3:a:firebirdsql:firebird:2.5.1:*:*:*:*:*:*:*
cpe:2.3:a:firebirdsql:firebird:2.5.2:*:*:*:*:*:*:*
cpe:2.3:a:firebirdsql:firebird:2.5.3:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*

EPSS

Процентиль: 99%
0.85258
Высокий

6.8 Medium

CVSS2

Дефекты

CWE-119

Связанные уязвимости

ubuntu
почти 13 лет назад

Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 before 26623, on Windows allows remote attackers to execute arbitrary code via a crafted packet to TCP port 3050, related to a missing size check during extraction of a group number from CNCT information.

debian
почти 13 лет назад

Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 185 ...

github
больше 3 лет назад

Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 before 26623, on Windows allows remote attackers to execute arbitrary code via a crafted packet to TCP port 3050, related to a missing size check during extraction of a group number from CNCT information.

fstec
почти 13 лет назад

Уязвимость системы управления базами данных Firebird, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 99%
0.85258
Высокий

6.8 Medium

CVSS2

Дефекты

CWE-119