CVE-2008-0387

Firebird < 1.0.3, 1.5.x < 1.5.6, 2.0.x < 2.0.4, 2.1.x < 2.1.0 RC1 - Remote Code Execution via Crafted XDR Requests

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-0387. PoCs published by Damian Frizza.

AI-analyzed exploit summary This exploit targets an integer overflow vulnerability in Firebird SQL, allowing remote attackers to execute arbitrary code via crafted XDR requests. The PoC sends a malformed packet to trigger memory corruption.

Description

Integer overflow in Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6, 2.0.x before 2.0.4, and 2.1.x before 2.1.0 RC1 might allow remote attackers to execute arbitrary code via crafted (1) op_receive, (2) op_start, (3) op_start_and_receive, (4) op_send, (5) op_start_and_send, and (6) op_start_send_and_receive XDR requests, which triggers memory corruption.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Damian Frizza · phpremotemultiple
https://www.exploit-db.com/exploits/31050

This exploit targets an integer overflow vulnerability in Firebird SQL, allowing remote attackers to execute arbitrary code via crafted XDR requests. The PoC sends a malformed packet to trigger memory corruption.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6, 2.0.x before 2.0.4, and 2.1.x before 2.1.0 RC1
No auth needed
Prerequisites: Network access to the Firebird SQL server on port 3050
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (11)

Core 11
Core References
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200803-02.xml
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29203
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/39996
Third Party Advisory x_refsource_misc
http://www.coresecurity.com/?action=item&id=2095
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/487173/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29501
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3580
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/27403
Vendor Advisory x_refsource_confirm
http://tracker.firebirdsql.org/browse/CORE-1681
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2008/dsa-1529

Scores

EPSS 0.4587
EPSS Percentile 98.6%

Details

CWE
CWE-189
Status published
Products (2)
firebirdsql/firebird 2.1.0
firebirdsql/firebird < 1.0.3
Published Jan 29, 2008
Tracked Since Feb 18, 2026