CVE-2025-65104 - CVE House
Back to Database
Status published High CVE-2025-65104

Firebird: Information leak vulnerability in firebird3 client when used with newer server

Vulnerability Description

Firebird is an open-source relational database management system. In versions FB3 of the client library placed incorrect data length values into XSQLDA fields when communicating with FB4 or higher servers, resulting in an information leak. This issue is fixed by upgrading to the FB4 client or higher.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-65104

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

FirebirdSQL

View all reports →

Affected Software

firebird
Vulnerable Versions:
< 4.0.0

Timeline

Official Publish: April 17th, 2026
Last Modified: April 17th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L

Weaknesses (CWE)