Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sybase

First CVE: Apr 11, 2000Active for: 26 yearsTotal CVEs: 37
43.2
VTI Score
High

Sybase maintains a modest but strategically positioned portfolio of database servers, application servers, and development platforms that serve enterprise customers with mission-critical data management and integration workloads. While its CVE volume is small, the vendor appears among the more prominent in the landscape due to the deployment depth of products such as Adaptive Server Enterprise and EAServer in backend infrastructure; its disclosures frequently acquire public exploit code, reflecting the appeal of database and server targets to attackers seeking operational leverage. The recurring weakness classes center on code injection, path traversal, and memory-buffer boundary issues that are characteristic of older server codebases where input validation and bounds-checking have accumulated exposure. Defenders should prioritize patches for internet-reachable or externally-connected instances of these products and treat this vendor's advisories as operationally significant despite modest overall volume; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
37
Total CVEs
More Total CVEs than 98% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Sybase over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 11, 2000
26 years ago
Most Recent CVE
Apr 24, 2018
3,013 days ago

Products(14 total)

Top CVEs

Signals from CVEs in this vendor scope (37 CVEs).

37 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2005-2297MEDIUM
Stack-based buffer overflow in TreeAction.do in Sybase EAServer 4.2.5 through 5.2 allows remote authenticated users to execute arbitrary code via a large javascript parameter.
Jul 19, 20054.669NOYES
CVE-2011-2474MEDIUM
Directory traversal vulnerability in the HTTP Server in Sybase EAServer 6.3.1 Developer Edition allows remote attackers to read arbitrary files via a /.\../\../\ sequence in a path
Jun 9, 20115.061NOYES
CVE-2008-0912HIGH
Multiple heap-based buffer overflows in mlsrv10.exe in Sybase MobiLink 10.0.1.3629 and earlier, as used by SQL Anywhere Developer Edition 10.0.1.3415 and probably other products, a
Feb 22, 200810.046NOYES
CVE-2016-7402CRITICAL
SAP ASE 16.0 SP02 PL03 and prior versions allow attackers who own SourceDB and TargetDB databases to elevate privileges to sa (system administrator) via dbcc import_sproc SQL injec
Nov 3, 20169.830NONO
CVE-2011-2475HIGH
Format string vulnerability in ECTrace.dll in the iMailGateway service in the Internet Mail Gateway in OneBridge Server and DMZ Proxy in Sybase OneBridge Mobile Data Suite 5.5 and
Jun 9, 201110.030NONO
CVE-2011-0496HIGH
Unspecified vulnerability in Sybase EAServer 5.x and 6.x before 6.3 ESD#2, as used in Appeon, Replication Server Messaging Edition (RSME), and WorkSpace, allows remote attackers to
Jan 20, 201110.029NONO
CVE-2005-0441HIGH
Multiple stack-based buffer overflows in Sybase Adaptive Server Enterprise (ASE) 12.x before 12.5.3 ESD#1 allow remote authenticated users to execute arbitrary code via the (1) att
Dec 22, 200410.028NONO
CVE-2002-2250HIGH
Multiple buffer overflows in Sybase Adaptive Server 12.0 and 12.5 allow remote attackers to execute arbitrary code via (1) a long parameter to the xp_freedll extended stored proced
Dec 31, 200210.027NONO
CVE-2017-5371HIGH
Odata Server in SAP Adaptive Server Enterprise (ASE) 16 allows remote attackers to cause a denial of service (process crash) via a series of crafted requests, aka SAP Security Note
Jan 23, 20177.526NONO
CVE-2013-6866HIGH
SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows remote authenticated users to execute ar
Nov 23, 20139.026NONO
View all 37 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products37 CVEs
41%
51%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network3 (8.1%)
Unknown34 (91.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (8.1%)
High0 (0.0%)
Unknown34 (91.9%)
User Interaction
None3 (8.1%)
Unknown34 (91.9%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (8.1%)
Unknown34 (91.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (37 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
5.4% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
8.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sybase.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sybase — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sybase's Products

View all 2 CNAs →

Top CWEs