Sybase maintains a modest but strategically positioned portfolio of database servers, application servers, and development platforms that serve enterprise customers with mission-critical data management and integration workloads. While its CVE volume is small, the vendor appears among the more prominent in the landscape due to the deployment depth of products such as Adaptive Server Enterprise and EAServer in backend infrastructure; its disclosures frequently acquire public exploit code, reflecting the appeal of database and server targets to attackers seeking operational leverage. The recurring weakness classes center on code injection, path traversal, and memory-buffer boundary issues that are characteristic of older server codebases where input validation and bounds-checking have accumulated exposure. Defenders should prioritize patches for internet-reachable or externally-connected instances of these products and treat this vendor's advisories as operationally significant despite modest overall volume; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sybase over time
Signals from CVEs in this vendor scope (37 CVEs).
37 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-2297MEDIUM Stack-based buffer overflow in TreeAction.do in Sybase EAServer 4.2.5 through 5.2 allows remote authenticated users to execute arbitrary code via a large javascript parameter. | Jul 19, 2005 | 4.6 | 69 | NO | YES |
CVE-2011-2474MEDIUM Directory traversal vulnerability in the HTTP Server in Sybase EAServer 6.3.1 Developer Edition allows remote attackers to read arbitrary files via a /.\../\../\ sequence in a path | Jun 9, 2011 | 5.0 | 61 | NO | YES |
CVE-2008-0912HIGH Multiple heap-based buffer overflows in mlsrv10.exe in Sybase MobiLink 10.0.1.3629 and earlier, as used by SQL Anywhere Developer Edition 10.0.1.3415 and probably other products, a | Feb 22, 2008 | 10.0 | 46 | NO | YES |
CVE-2016-7402CRITICAL SAP ASE 16.0 SP02 PL03 and prior versions allow attackers who own SourceDB and TargetDB databases to elevate privileges to sa (system administrator) via dbcc import_sproc SQL injec | Nov 3, 2016 | 9.8 | 30 | NO | NO |
CVE-2011-2475HIGH Format string vulnerability in ECTrace.dll in the iMailGateway service in the Internet Mail Gateway in OneBridge Server and DMZ Proxy in Sybase OneBridge Mobile Data Suite 5.5 and | Jun 9, 2011 | 10.0 | 30 | NO | NO |
CVE-2011-0496HIGH Unspecified vulnerability in Sybase EAServer 5.x and 6.x before 6.3 ESD#2, as used in Appeon, Replication Server Messaging Edition (RSME), and WorkSpace, allows remote attackers to | Jan 20, 2011 | 10.0 | 29 | NO | NO |
CVE-2005-0441HIGH Multiple stack-based buffer overflows in Sybase Adaptive Server Enterprise (ASE) 12.x before 12.5.3 ESD#1 allow remote authenticated users to execute arbitrary code via the (1) att | Dec 22, 2004 | 10.0 | 28 | NO | NO |
CVE-2002-2250HIGH Multiple buffer overflows in Sybase Adaptive Server 12.0 and 12.5 allow remote attackers to execute arbitrary code via (1) a long parameter to the xp_freedll extended stored proced | Dec 31, 2002 | 10.0 | 27 | NO | NO |
CVE-2017-5371HIGH Odata Server in SAP Adaptive Server Enterprise (ASE) 16 allows remote attackers to cause a denial of service (process crash) via a series of crafted requests, aka SAP Security Note | Jan 23, 2017 | 7.5 | 26 | NO | NO |
CVE-2013-6866HIGH SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows remote authenticated users to execute ar | Nov 23, 2013 | 9.0 | 26 | NO | NO |
Signals from CVEs in this vendor scope (37 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sybase.
Media articles that mention a CVE ID that affects a product developed by Sybase — matched by CVE ID, not by vendor name.