CVE-2008-0387

Firebird < 1.0.3 - Numeric Error

Title source: rule

Description

Integer overflow in Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6, 2.0.x before 2.0.4, and 2.1.x before 2.1.0 RC1 might allow remote attackers to execute arbitrary code via crafted (1) op_receive, (2) op_start, (3) op_start_and_receive, (4) op_send, (5) op_start_and_send, and (6) op_start_send_and_receive XDR requests, which triggers memory corruption.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Damian Frizza · phpremotemultiple
https://www.exploit-db.com/exploits/31050

Scores

EPSS 0.5991
EPSS Percentile 98.3%

Details

CWE
CWE-189
Status published
Products (2)
firebirdsql/firebird 2.1.0
firebirdsql/firebird < 1.0.3
Published Jan 29, 2008
Tracked Since Feb 18, 2026