No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 17 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Firebirdsql
Firebirdsql firebird |
|
| Vendors & Products |
Firebirdsql
Firebirdsql firebird |
Fri, 17 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 17 Apr 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when the server receives an op_crypt_key_callback packet without prior authentication, the port_server_crypt_callback handler is not initialized, resulting in a null pointer dereference and server crash. An unauthenticated attacker who knows only the server's IP and port can exploit this to crash the server. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14. | |
| Title | Firebird Null Pointer Dereference via CryptCallback causes DOS | |
| Weaknesses | CWE-476 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-17T19:31:38.952Z
Reserved: 2026-02-25T15:28:40.650Z
Link: CVE-2026-28224
Updated: 2026-04-17T19:31:27.860Z
Status : Received
Published: 2026-04-17T19:16:35.983
Modified: 2026-04-17T20:16:32.460
Link: CVE-2026-28224
No data.
OpenCVE Enrichment
Updated: 2026-04-17T20:30:15Z