Vulnerability Description
Firebird is an open-source relational database management system. In versions FB3 of the client library placed incorrect data length values into XSQLDA fields when communicating with FB4 or higher servers, resulting in an information leak. This issue is fixed by upgrading to the FB4 client or higher.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Firebirdsql | Firebird | < 3.0.14 |
Related Weaknesses (CWE)
References
- https://github.com/FirebirdSQL/firebird/releases/tag/v4.0.0ProductRelease Notes
- https://github.com/FirebirdSQL/firebird/security/advisories/GHSA-mfpr-9886-xjhgVendor Advisory
FAQ
What is CVE-2025-65104?
CVE-2025-65104 is a vulnerability with a CVSS score of 7.9 (HIGH). Firebird is an open-source relational database management system. In versions FB3 of the client library placed incorrect data length values into XSQLDA fields when communicating with FB4 or higher ser...
How severe is CVE-2025-65104?
CVE-2025-65104 has been rated HIGH with a CVSS base score of 7.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-65104?
Check the references section above for vendor advisories and patch information. Affected products include: Firebirdsql Firebird.