Borland Software's vulnerability profile centers on a focused set of development tools and database products spanning Delphi, C++ Builder, and InterBase, which occupy a notable presence among legacy enterprise and embedded systems. The recurring exposure involves memory-safety issues and buffer-boundary weaknesses characteristic of native-code development platforms and embedded database engines, and public exploit code has frequently become available for vulnerabilities in this vendor's products. Current severity, exploitation activity, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Borland Software over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-3566HIGH Stack-based buffer overflow in the database service (ibserver.exe) in Borland InterBase 2007 before SP2 allows remote attackers to execute arbitrary code via a long size value in a | Jul 26, 2007 | 7.5 | 72 | NO | YES |
CVE-2007-5243HIGH Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0.257, allow remote attackers to execute arbitrary code via ( | Oct 6, 2007 | 9.3 | 69 | NO | YES |
CVE-2004-0204HIGH Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2 | Aug 6, 2004 | 7.5 | 68 | NO | YES |
CVE-2007-5244HIGH Stack-based buffer overflow in Borland InterBase LI 8.0.0.53 through 8.1.0.253 on Linux, and possibly unspecified versions on Solaris, allows remote attackers to execute arbitrary | Oct 6, 2007 | 9.3 | 62 | NO | YES |
CVE-2001-0008HIGH Backdoor account in Interbase database server allows remote attackers to overwrite arbitrary files using stored procedures. | Feb 12, 2001 | 10.0 | 44 | NO | YES |
CVE-2004-2043MEDIUM Buffer overflow in ibserver for Firebird Database 1.0 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows remote attackers to cause a | May 1, 2004 | 5.0 | 27 | NO | YES |
CVE-2002-1514HIGH gds_lock_mgr in Borland InterBase allows local users to overwrite files and gain privileges via a symlink attack on a "isc_init1.X" temporary file, as demonstrated by modifying the | Apr 2, 2003 | 7.2 | 27 | NO | YES |
CVE-2004-2121MEDIUM Multiple directory traversal vulnerabilities in Borland Web Server (BWS) 1.0b3 and earlier allow remote attackers to read and download arbitrary files via (1) multi-dot "......" se | Dec 31, 2004 | 5.0 | 23 | NO | YES |
CVE-2002-2087MEDIUM Buffer overflow in Borland InterBase 6.0 allows local users to execute arbitrary code via a long INTERBASE environment variable when calling (1) gds_drop, (2) gds_lock_mgr, or (3) | Dec 31, 2002 | 4.6 | 21 | NO | YES |
CVE-2006-6201HIGH Heap-based buffer overflow in Borland idsql32.dll 5.1.0.4, as used by RevilloC MailServer; 5.2.0.2 as used by Borland Developer Studio 2006; and possibly other versions allows remo | Dec 1, 2006 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Borland Software.
Media articles that mention a CVE ID that affects a product developed by Borland Software — matched by CVE ID, not by vendor name.