V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2007-5243
CVE
CriticalConfirmedExploit available

Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0.257, allow remote …

CVSS
9.3
Critical
EPSS
0.40
p98
Published
2007-01-01
Updated
2007-01-01
Description

Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0.257, allow remote attackers to execute arbitrary code via (1) a long service attach request on TCP port 3050 to the (a) SVC_attach or (b) INET_connect function, (2) a long create request on TCP port 3050 to the (c) isc_create_database or (d) jrd8_create_database function, (3) a long attach request on TCP port 3050 to the (e) isc_attach_database or (f) PWD_db_aliased function, or unspecified vectors involving the (4) jrd8_attach_database or (5) expand_filename2 function.

Tags · CWE
RCE
CWE-119
CAPEC-8
CAPEC-9
CAPEC-10
CAPEC-14
CAPEC-24
CAPEC-42
CAPEC-44
CAPEC-45
CAPEC-46
CAPEC-47
CAPEC-100
CAPEC-123
Affected products
Interbase
CVSS vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Timeline
2007-01-01
Published
2007-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: M
Medium
Authentication
Au: N
None (N)
Confidentiality Impact
C: C
Complete
Integrity Impact
I: C
Complete
Availability Impact
A: C
Complete
Exploit indicators
EPSS
0.401 · p98
Known exploited (KEV)
No
Known exploits — Сканер-ВС
10020
exploitdb · https://www.exploit-db.com/exploits/10020
Enterprise
10021
exploitdb · https://www.exploit-db.com/exploits/10021
Enterprise
16420
exploitdb · https://www.exploit-db.com/exploits/16420
Enterprise
16432
exploitdb · https://www.exploit-db.com/exploits/16432
Enterprise
16437
exploitdb · https://www.exploit-db.com/exploits/16437
Enterprise
16440
exploitdb · https://www.exploit-db.com/exploits/16440
Enterprise
16447
exploitdb · https://www.exploit-db.com/exploits/16447
Enterprise
16449
exploitdb · https://www.exploit-db.com/exploits/16449
Enterprise
16839
exploitdb · https://www.exploit-db.com/exploits/16839
Enterprise
16843
exploitdb · https://www.exploit-db.com/exploits/16843
Enterprise
16844
exploitdb · https://www.exploit-db.com/exploits/16844
Enterprise
9954
exploitdb · https://www.exploit-db.com/exploits/9954
Enterprise
Affected products
ProductVendorStatus
interbase*Tracked
Source databases
CVE