← Vulnerability feed

Vulnerability record · CVE-2007-5243 · published 6 October 2007

CVE-2007-5243: Borland software interbase memory buffer overflow vulnerability

BBorland Software · Interbase

Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0.257, allow remote attackers to execute arbitrary code via (1) a long service attach request on TCP port 3050 to the (a) SVC_attach or (b) INET_connect function, (2) a long create request on TCP port 3050 to the (c) isc_create_database or (d) jrd8_create_database function, (3) a long attach request on TCP port 3050 to the (e) isc_attach_database or (f) PWD_db_aliased function, or unspecified vectors involving the (4) jrd8_attach_database or (5) expand_filename2 function.

9.3 CVSS 2.0 High EPSS 40% · top 1.4% CWE-119 · Memory buffer overflow
9.3CVSS 2.0 base score
40%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
36References, 8 tagged exploit
16 Jun 2026Last modified by NVD

Description

Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0.257, allow remote attackers to execute arbitrary code via (1) a long service attach request on TCP port 3050 to the (a) SVC_attach or (b) INET_connect function, (2) a long create request on TCP port 3050 to the (c) isc_create_database or (d) jrd8_create_database function, (3) a long attach request on TCP port 3050 to the (e) isc_attach_database or (f) PWD_db_aliased function, or unspecified vectors involving the (4) jrd8_attach_database or (5) expand_filename2 function.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-5243 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2001-0008Borland software interbase vulnerabilityBackdoor account in Interbase database server allows remote attackers to overwrite arbitrary files using stored procedures.EPSS 13%9.3CVE-2007-5244Borland software interbase memory buffer overflow vulnerabilityStack-based buffer overflow in Borland InterBase LI 8.0.0.53 through 8.1.0.253 on Linux, and possibly unspecified versions on Solaris, allows remote …EPSS 38%7.5CVE-2007-3566Borland InterBase database service stack buffer overflow via create requestThe database service ibserver.exe in Borland InterBase 2007 before SP2 has a stack-based buffer overflow triggered by a long size value in a create r…EPSS 66%analysed7.5CVE-2004-1833Borland software interbase vulnerabilityThe admin.ib file in Borland Interbase 7.1 for Linux has default world writable permissions, which allows local users to gain database administrative…EPSS 2.2%7.2CVE-2003-0197Borland software interbase vulnerabilityBuffer overflow gds_lock_mgr of Interbase Database 6.x allows local users to gain privileges via a long ISC_LOCK_ENV environment variable (INTERBASE_…EPSS 0.54%7.2CVE-2002-1514Borland software interbase vulnerabilitygds_lock_mgr in Borland InterBase allows local users to overwrite files and gain privileges via a symlink attack on a "isc_init1.X" temporary file, a…EPSS 0.84%5.0CVE-2004-2043Borland software interbase vulnerabilityBuffer overflow in ibserver for Firebird Database 1.0 and other versions before 1.5, and possibly other products that use the InterBase codebase, all…EPSS 12%4.6CVE-2002-2087Borland software interbase vulnerabilityBuffer overflow in Borland InterBase 6.0 allows local users to execute arbitrary code via a long INTERBASE environment variable when calling (1) gds_…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2007-5243), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.