Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Firebirdsql

First CVE: Feb 12, 2001Active for: 25 yearsTotal CVEs: 46
53.8
VTI Score
TOP TARGET

Firebirdsql is an open-source relational database engine that, despite a narrow product footprint centered on Firebird itself, occupies a position among more prominent database platforms in the vulnerability landscape. Its vulnerability profile is anchored in memory-safety and input-handling weakness classes—including buffer-boundary violations, NULL-pointer dereferences, improper input validation, and information-exposure flaws—that are characteristic of native database implementations managing untrusted query and network input. Notably, vulnerabilities affecting this vendor frequently acquire public exploit code, reflecting the accessibility of the open codebase and the appeal of database engines as targets for proof-of-concept research and operational testing. Defenders deploying Firebird should monitor upstream releases for memory-safety and parsing fixes, particularly where instances are network-exposed or process untrusted client queries; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
46
Total CVEs
More Total CVEs than 98% of tracked vendors
2.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Firebirdsql over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 12, 2001
25 years ago
Most Recent CVE
Apr 17, 2026
98 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (46 CVEs).

46 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2013-2492MEDIUM
Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 before 26623, on Windows allows remote attackers to execute arbitrary code via a c
Mar 15, 20136.858NOYES
CVE-2008-0387HIGH
Integer overflow in Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6, 2.0.x before 2.0.4, and 2.1.x before 2.1.0 RC1 might allow remote attackers to execute arbitrary code via cr
Jan 29, 20087.858NOYES
CVE-2001-0008HIGH
Backdoor account in Interbase database server allows remote attackers to overwrite arbitrary files using stored procedures.
Feb 12, 200110.044NOYES
CVE-2007-3181HIGH
Buffer overflow in fbserver.exe in Firebird SQL 2 before 2.0.1 allows remote attackers to execute arbitrary code via a large p_cnct_count value in a p_cnct structure in a connect (
Jun 12, 200710.041NOYES
CVE-2026-40342CRITICAL
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader concatenates a user-supplied engin
Apr 17, 20269.934NONO
CVE-2017-11509HIGH
An authenticated remote attacker can execute arbitrary code in Firebird SQL Server versions 2.5.7 and 3.0.2 by executing a malformed SQL statement.
Mar 28, 20188.831NONO
CVE-2009-2620MEDIUM
src/remote/server.cpp in fbserver.exe in Firebird SQL 1.5 before 1.5.6, 2.0 before 2.0.6, 2.1 before 2.1.3, and 2.5 before 2.5 Beta 2 allows remote attackers to cause a denial of s
Jul 29, 20095.030NOYES
CVE-2017-6369HIGH
Insufficient checks in the UDF subsystem in Firebird 2.5.x before 2.5.7 and 3.0.x before 3.0.2 allow remote authenticated users to execute code by using a 'system' entrypoint from
Mar 24, 20178.829NONO
CVE-2025-24975HIGH
Firebird is a relational database. Prior to snapshot versions 4.0.6.3183, 5.0.2.1610, and 6.0.0.609, Firebird is vulnerable if ExtConnPoolSize is not set equal to 0. If connections
Aug 15, 20258.828NONO
CVE-2007-5245HIGH
Multiple stack-based buffer overflows in Firebird LI 1.5.3.4870 and 1.5.4.4910, and WI 1.5.3.4870 and 1.5.4.4910, allow remote attackers to execute arbitrary code via (1) a long se
Oct 6, 200710.028NONO
View all 46 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products46 CVEs
39%
54%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network15 (32.6%)
Unknown31 (67.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (32.6%)
High0 (0.0%)
Unknown31 (67.4%)
User Interaction
None15 (32.6%)
Unknown31 (67.4%)
Required0 (0.0%)
Privileges Required
Low6 (13.0%)
High0 (0.0%)
None9 (19.6%)
Unknown31 (67.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (46 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
2.2% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
8 CVEs
17.4% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Firebirdsql.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Firebirdsql — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Firebirdsql's Products

View all 5 CNAs →

Top CWEs