Firebirdsql is an open-source relational database engine that, despite a narrow product footprint centered on Firebird itself, occupies a position among more prominent database platforms in the vulnerability landscape. Its vulnerability profile is anchored in memory-safety and input-handling weakness classes—including buffer-boundary violations, NULL-pointer dereferences, improper input validation, and information-exposure flaws—that are characteristic of native database implementations managing untrusted query and network input. Notably, vulnerabilities affecting this vendor frequently acquire public exploit code, reflecting the accessibility of the open codebase and the appeal of database engines as targets for proof-of-concept research and operational testing. Defenders deploying Firebird should monitor upstream releases for memory-safety and parsing fixes, particularly where instances are network-exposed or process untrusted client queries; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Firebirdsql over time
Signals from CVEs in this vendor scope (46 CVEs).
46 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-2492MEDIUM Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 before 26623, on Windows allows remote attackers to execute arbitrary code via a c | Mar 15, 2013 | 6.8 | 58 | NO | YES |
CVE-2008-0387HIGH Integer overflow in Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6, 2.0.x before 2.0.4, and 2.1.x before 2.1.0 RC1 might allow remote attackers to execute arbitrary code via cr | Jan 29, 2008 | 7.8 | 58 | NO | YES |
CVE-2001-0008HIGH Backdoor account in Interbase database server allows remote attackers to overwrite arbitrary files using stored procedures. | Feb 12, 2001 | 10.0 | 44 | NO | YES |
CVE-2007-3181HIGH Buffer overflow in fbserver.exe in Firebird SQL 2 before 2.0.1 allows remote attackers to execute arbitrary code via a large p_cnct_count value in a p_cnct structure in a connect ( | Jun 12, 2007 | 10.0 | 41 | NO | YES |
CVE-2026-40342CRITICAL Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader concatenates a user-supplied engin | Apr 17, 2026 | 9.9 | 34 | NO | NO |
CVE-2017-11509HIGH An authenticated remote attacker can execute arbitrary code in Firebird SQL Server versions 2.5.7 and 3.0.2 by executing a malformed SQL statement. | Mar 28, 2018 | 8.8 | 31 | NO | NO |
CVE-2009-2620MEDIUM src/remote/server.cpp in fbserver.exe in Firebird SQL 1.5 before 1.5.6, 2.0 before 2.0.6, 2.1 before 2.1.3, and 2.5 before 2.5 Beta 2 allows remote attackers to cause a denial of s | Jul 29, 2009 | 5.0 | 30 | NO | YES |
CVE-2017-6369HIGH Insufficient checks in the UDF subsystem in Firebird 2.5.x before 2.5.7 and 3.0.x before 3.0.2 allow remote authenticated users to execute code by using a 'system' entrypoint from | Mar 24, 2017 | 8.8 | 29 | NO | NO |
CVE-2025-24975HIGH Firebird is a relational database. Prior to snapshot versions 4.0.6.3183, 5.0.2.1610, and 6.0.0.609, Firebird is vulnerable if ExtConnPoolSize is not set equal to 0. If connections | Aug 15, 2025 | 8.8 | 28 | NO | NO |
CVE-2007-5245HIGH Multiple stack-based buffer overflows in Firebird LI 1.5.3.4870 and 1.5.4.4910, and WI 1.5.3.4870 and 1.5.4.4910, allow remote attackers to execute arbitrary code via (1) a long se | Oct 6, 2007 | 10.0 | 28 | NO | NO |
Signals from CVEs in this vendor scope (46 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Firebirdsql.
Media articles that mention a CVE ID that affects a product developed by Firebirdsql — matched by CVE ID, not by vendor name.