← Voltar à pesquisa de CVEs

CVE-2026-28224

Firebird

Descrição

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when the server receives an op_crypt_key_callback packet without prior authentication, the port_server_crypt_callback handler is not initialized, resulting in a null pointer dereference and server crash. An unauthenticated attacker who knows only the server-s IP and port can exploit this to crash the server. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14.

CVSS 8.2EPSS 0.46499999999999997%Risco 0.85
Ver fonte
Publicação
2026-04-17 19:16:35
Versões afetadas
<5.0.4,<4.0.7,<3.0.14
Tipo
Core software
Vetor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H