<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 12:27:40 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-07740</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-07740</link>
      <description>bdu:2026-07740</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-07740</guid>
    </item>
    <item>
      <title>EUVD-2026-292448</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-292448</link>
      <description>EUVD-2026-292448</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-292448</guid>
    </item>
    <item>
      <title>fkie_cve-2026-40342</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40342</link>
      <description>&lt;p&gt;Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader concatenates a user-supplied engine name into a filesystem path without filtering path separators or .. components. An authenticated user with CREATE FUNCTION privileges can use a crafted ENGINE name to load an arbitrary shared library from anywhere on the filesystem via path traversal. The library&amp;#39;s initialization code executes immediately during loading, before Firebird validates the module, achieving code execution as the server&amp;#39;s OS account. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader concatenates a user-supplied engine name into a filesystem path without filtering path separators or .. components. An authenticated user with CREATE FUNCTION privileges can use a crafted ENGINE name to load an arbitrary shared library from anywhere on the filesystem via path traversal. The library&amp;#39;s initialization code executes immediately during loading, before Firebird validates the module, achieving code execution as the server&amp;#39;s OS account. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-40342</guid>
    </item>
    <item>
      <title>OESA-2026-2013 — firebird security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2013</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: firebird&lt;/p&gt;
&lt;p&gt;Firebird is a relational database offering many ANSI SQL standard features that runs on Linux, Windows, MacOS and a variety of Unix platforms. Firebird offers excellent concurrency, high performance, and powerful language support for stored procedures and triggers. It has been used in production systems, under a variety of names, since 1981.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Firebird is an open-source relational database management system. In versions FB3 of the client library placed incorrect data length values into XSQLDA fields when communicating with FB4 or higher servers, resulting in an information leak. This issue is fixed by upgrading to the FB4 client or higher.(CVE-2025-65104)&lt;/p&gt;
&lt;p&gt;Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when processing CNCT_specific_data segments during authentication, the server assumes segments arrive in strictly ascending order. If segments arrive out of order, the Array class&amp;amp;apos;s grow() method computes a negative size value, causing a SIGSEGV crash. An unauthenticated attacker who knows only the server&amp;amp;apos;s IP and port can exploit this to crash the server. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14.(CVE-2026-27890)&lt;/p&gt;
&lt;p&gt;Firebird is an open-source relational database management system. In versions prior to 6.0.0, 5.0.4, 4.0.7 and 3.0.14, when processing an op_slice network packet, the server passes an unprepared structure containing a null pointer to the SDL_info() func…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: firebird&lt;/p&gt;
&lt;p&gt;Firebird is a relational database offering many ANSI SQL standard features that runs on Linux, Windows, MacOS and a variety of Unix platforms. Firebird offers excellent concurrency, high performance, and powerful language support for stored procedures and triggers. It has been used in production systems, under a variety of names, since 1981.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Firebird is an open-source relational database management system. In versions FB3 of the client library placed incorrect data length values into XSQLDA fields when communicating with FB4 or higher servers, resulting in an information leak. This issue is fixed by upgrading to the FB4 client or higher.(CVE-2025-65104)&lt;/p&gt;
&lt;p&gt;Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when processing CNCT_specific_data segments during authentication, the server assumes segments arrive in strictly ascending order. If segments arrive out of order, the Array class&amp;amp;apos;s grow() method computes a negative size value, causing a SIGSEGV crash. An unauthenticated attacker who knows only the server&amp;amp;apos;s IP and port can exploit this to crash the server. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14.(CVE-2026-27890)&lt;/p&gt;
&lt;p&gt;Firebird is an open-source relational database management system. In versions prior to 6.0.0, 5.0.4, 4.0.7 and 3.0.14, when processing an op_slice network packet, the server passes an unprepared structure containing a null pointer to the SDL_info() func…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2013</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:1868-1 — Security update for firebird</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:1868-1</link>
      <description>&lt;p&gt;Security update for firebird&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for firebird&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:1868-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-40342</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-40342</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: firebird3.0, Ubuntu:20.04:LTS: firebird3.0, Ubuntu:22.04:LTS: firebird3.0, Ubuntu:24.04:LTS: firebird3.0, Ubuntu:25.10: firebird3.0, Ubuntu:25.10: firebird4.0, Ubuntu:26.04:LTS: firebird3.0, Ubuntu:26.04:LTS: firebird4.0&lt;/p&gt;
&lt;p&gt;Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader concatenates a user-supplied engine name into a filesystem path without filtering path separators or .. components. An authenticated user with CREATE FUNCTION privileges can use a crafted ENGINE name to load an arbitrary shared library from anywhere on the filesystem via path traversal. The library&amp;#39;s initialization code executes immediately during loading, before Firebird validates the module, achieving code execution as the server&amp;#39;s OS account. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: firebird3.0, Ubuntu:20.04:LTS: firebird3.0, Ubuntu:22.04:LTS: firebird3.0, Ubuntu:24.04:LTS: firebird3.0, Ubuntu:25.10: firebird3.0, Ubuntu:25.10: firebird4.0, Ubuntu:26.04:LTS: firebird3.0, Ubuntu:26.04:LTS: firebird4.0&lt;/p&gt;
&lt;p&gt;Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader concatenates a user-supplied engine name into a filesystem path without filtering path separators or .. components. An authenticated user with CREATE FUNCTION privileges can use a crafted ENGINE name to load an arbitrary shared library from anywhere on the filesystem via path traversal. The library&amp;#39;s initialization code executes immediately during loading, before Firebird validates the module, achieving code execution as the server&amp;#39;s OS account. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-40342</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1171 — Firebird: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1171</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Firebird ausnutzen, um beliebigen Programmcode mit Administratorrechten auszuführen, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Firebird ausnutzen, um beliebigen Programmcode mit Administratorrechten auszuführen, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1171</guid>
    </item>
  </channel>
</rss>
