CVE-2004-2043 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 11.9% (pctl 96)
Patch early
A public exploit exists.
Description
Buffer overflow in ibserver for Firebird Database 1.0 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows remote attackers to cause a denial of service (crash) via a long database name, as demonstrated using the gsec command.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
| EPSS | 11.87% — more likely to be exploited than 96% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2004-05-01 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| borland software | interbase |
| borland software | interbase superserver |
| firebirdsql | firebird |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Borland Interbase 7.x - Remote Buffer Overflow | 2004-06-25 |
| exploit-db | Firebird 1.0 - Remote Database Name Buffer Overrun | 2004-06-01 |
References
- http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0027.html
- http://marc.info/?l=bugtraq&m=108611386202493&w=2
- http://secunia.com/advisories/11756
- http://secunia.com/advisories/19350
- http://securitytracker.com/id?1010381
- http://www.debian.org/security/2006/dsa-1014
- http://www.osvdb.org/6408
- http://www.osvdb.org/6624
- http://www.securiteam.com/unixfocus/5AP0P0UCUO.html
- http://www.securityfocus.com/bid/10446
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16229
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16316
- http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0027.html
- http://marc.info/?l=bugtraq&m=108611386202493&w=2
- http://secunia.com/advisories/11756
- http://secunia.com/advisories/19350
- http://securitytracker.com/id?1010381
- http://www.debian.org/security/2006/dsa-1014
- http://www.osvdb.org/6408
- http://www.osvdb.org/6624
→ the Explorer · watch your stack · NVD