Vulnerabilities > Borland Software

DATE CVE VULNERABILITY TITLE RISK
2007-10-06 CVE-2007-5244 Buffer Errors vulnerability in Borland Software Interbase Li8.0.0.253/Li8.0.0.53/Li8.0.0.54
Stack-based buffer overflow in Borland InterBase LI 8.0.0.53 through 8.1.0.253 on Linux, and possibly unspecified versions on Solaris, allows remote attackers to execute arbitrary code via a long attach request on TCP port 3050 to the open_marker_file function.
network
borland-software CWE-119
critical
9.3
2007-10-06 CVE-2007-5243 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Borland Software Interbase
Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0.257, allow remote attackers to execute arbitrary code via (1) a long service attach request on TCP port 3050 to the (a) SVC_attach or (b) INET_connect function, (2) a long create request on TCP port 3050 to the (c) isc_create_database or (d) jrd8_create_database function, (3) a long attach request on TCP port 3050 to the (e) isc_attach_database or (f) PWD_db_aliased function, or unspecified vectors involving the (4) jrd8_attach_database or (5) expand_filename2 function.
network
borland-software CWE-119
critical
9.3
2007-07-26 CVE-2007-3566 Remote Stack Based Buffer Overflow vulnerability in Borland Software Interbase 2007
Stack-based buffer overflow in the database service (ibserver.exe) in Borland InterBase 2007 before SP2 allows remote attackers to execute arbitrary code via a long size value in a create request to port 3050/tcp.
network
low complexity
borland-software
7.5
2006-12-01 CVE-2006-6201 Remote Heap Buffer Overflow vulnerability in Borland IDSQL32.DLL Library
Heap-based buffer overflow in Borland idsql32.dll 5.1.0.4, as used by RevilloC MailServer; 5.2.0.2 as used by Borland Developer Studio 2006; and possibly other versions allows remote attackers to execute arbitrary code via a long SQL statement, related to use of the DbiQExec function.
network
low complexity
borland-software revilloc
7.5
2006-02-10 CVE-2006-0634 Local Security vulnerability in Borland Software C++ Builder 6
Borland C++Builder 6 (BCB6) with Update Pack 4 Enterprise edition (ent_upd4) evaluates the "i>sizeof(int)" expression to false when i equals -1, which might introduce integer overflow vulnerabilities into applications that could be exploited by context-dependent attackers.
local
low complexity
borland-software
4.6
2004-12-31 CVE-2004-2121 Directory Traversal vulnerability in Borland Webserver for Corel Paradox
Multiple directory traversal vulnerabilities in Borland Web Server (BWS) 1.0b3 and earlier allow remote attackers to read and download arbitrary files via (1) multi-dot "......" sequences, or (2) "%5c%2e%2e" (encoded "\..") sequences, in the URL.
network
low complexity
borland-software
5.0
2004-08-06 CVE-2004-0204 Directory Traversal vulnerability in Business Objects Crystal Reports Web Form Viewer
Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and other products, allows remote attackers to read and delete arbitrary files via ".." sequences in the dynamicimag argument to crystalimagehandler.aspx.
7.5
2004-05-01 CVE-2004-2043 Remote Pre-Authentication Database Name Buffer Overrun vulnerability in Firebird
Buffer overflow in ibserver for Firebird Database 1.0 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows remote attackers to cause a denial of service (crash) via a long database name, as demonstrated using the gsec command.
network
low complexity
borland-software firebirdsql
5.0
2004-03-20 CVE-2004-1833 Privilege Escalation vulnerability in Borland Interbase Database User
The admin.ib file in Borland Interbase 7.1 for Linux has default world writable permissions, which allows local users to gain database administrative privileges.
network
low complexity
borland-software
7.5
2003-04-11 CVE-2003-0197 Local Security vulnerability in Interbase
Buffer overflow gds_lock_mgr of Interbase Database 6.x allows local users to gain privileges via a long ISC_LOCK_ENV environment variable (INTERBASE_LOCK).
local
low complexity
borland-software firebirdsql
7.2