Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2026-40342

4 месяца назад

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader concatenates a user-supplied engine name into a filesystem path without filtering path separators or .. components. An authenticated user with CREATE FUNCTION privileges can use a crafted ENGINE name to load an arbitrary shared library from anywhere on the filesystem via path traversal. The library's initialization code executes immediately during loading, before Firebird validates the module, achieving code execution as the server's OS account. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14.

CVSS3: 9.9
EPSS: Низкий
nvd логотип

CVE-2026-40342

4 месяца назад

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader concatenates a user-supplied engine name into a filesystem path without filtering path separators or .. components. An authenticated user with CREATE FUNCTION privileges can use a crafted ENGINE name to load an arbitrary shared library from anywhere on the filesystem via path traversal. The library's initialization code executes immediately during loading, before Firebird validates the module, achieving code execution as the server's OS account. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14.

CVSS3: 9.9
EPSS: Низкий
debian логотип

CVE-2026-40342

4 месяца назад

Firebird is an open-source relational database management system. In v ...

CVSS3: 9.9
EPSS: Низкий
redos логотип

ROS-20260515-73-0001

3 месяца назад

Уязвимость firebird

CVSS3: 9.9
EPSS: Низкий
fstec логотип

BDU:2026-07740

4 месяца назад

Уязвимость системы управления базами данных Firebird, связанная с неверным ограничением имени пути к каталогу, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.9
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1868-1

3 месяца назад

Security update for firebird

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-40342

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader concatenates a user-supplied engine name into a filesystem path without filtering path separators or .. components. An authenticated user with CREATE FUNCTION privileges can use a crafted ENGINE name to load an arbitrary shared library from anywhere on the filesystem via path traversal. The library's initialization code executes immediately during loading, before Firebird validates the module, achieving code execution as the server's OS account. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14.

CVSS3: 9.9
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-40342

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader concatenates a user-supplied engine name into a filesystem path without filtering path separators or .. components. An authenticated user with CREATE FUNCTION privileges can use a crafted ENGINE name to load an arbitrary shared library from anywhere on the filesystem via path traversal. The library's initialization code executes immediately during loading, before Firebird validates the module, achieving code execution as the server's OS account. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14.

CVSS3: 9.9
1%
Низкий
4 месяца назад
debian логотип
CVE-2026-40342

Firebird is an open-source relational database management system. In v ...

CVSS3: 9.9
1%
Низкий
4 месяца назад
redos логотип
ROS-20260515-73-0001

Уязвимость firebird

CVSS3: 9.9
1%
Низкий
3 месяца назад
fstec логотип
BDU:2026-07740

Уязвимость системы управления базами данных Firebird, связанная с неверным ограничением имени пути к каталогу, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.9
1%
Низкий
4 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1868-1

Security update for firebird

3 месяца назад

Уязвимостей на страницу