Skip to content
Noroxi

sqlite records

66 published records for vendor sqlite.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
5
With a fix record
87.9%
Median publish → KEV
No record has entered KEV

All records

66 records
  • SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree t

    CriticalCVSS 9.8No exploitEPSS 45%

    sqlite · sqliteMay 30, 2019

  • Integer Truncation on SQLite

    HighCVSS 7.2Proof of conceptEPSS 73%

    sqlite · sqliteJul 15, 2025

  • Multiple unspecified vulnerabilities in SQLite before 3.8.10.2, as used in Apple iOS before 9, have unknown impact and attack vectors.

    CriticalCVSS 10.0Proof of conceptEPSS 9%

    sqlite · sqliteSep 18, 2015

  • The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used in GDAL and other products, mishandles undersized RTree blob

    CriticalCVSS 9.8No exploitEPSS 9%

    sqlite · sqliteJul 7, 2017

  • In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compo

    CriticalCVSS 9.8No exploitEPSS 8%

    sqlite · sqliteApr 8, 2020

  • pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.

    CriticalCVSS 9.8No exploitEPSS 5%

    sqlite · sqliteDec 9, 2019

  • lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which allows attackers to ca

    CriticalCVSS 9.8No exploitEPSS 4%

    sqlite · sqliteDec 5, 2019

  • In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE for views that have a nested FROM clause.

    CriticalCVSS 9.8No exploitEPSS 1%

    sqlite · sqliteSep 1, 2022

  • SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a

    HighCVSS 7.5Proof of conceptEPSS 23%

    sqlite · sqliteAug 3, 2022

  • PDO::quote() may return unquoted string

    CriticalCVSS 9.1No exploitEPSS 2%

    php · phpFeb 12, 2025

  • SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries th

    HighCVSS 8.1No exploitEPSS 10%

    sqlite · sqliteDec 21, 2018

  • SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in

    HighCVSS 8.1No exploitEPSS 8%

    sqlite · sqliteApr 3, 2019

  • CVE-2019-5018
    34Monitor

    An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0.

    HighCVSS 8.1No exploitEPSS 7%

    sqlite · sqliteMay 10, 2019

  • SQLite before 3.53.2 Memory Corruption in FTS5 Extension

    HighCVSS 8.5No exploitEPSS 0%

    sqlite · sqliteJun 9, 2026

  • SQLite before 3.53.2 Heap Buffer Overflow via FTS5 fts5ChunkIterate

    HighCVSS 8.5No exploitEPSS 0%

    sqlite · sqliteJun 9, 2026

  • SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash.

    HighCVSS 7.5No exploitEPSS 8%

    sqlite · sqliteDec 9, 2019

  • CVE-2018-8740
    32Monitor

    In SQLite through 3.22.0, databases whose schema is corrupted using a CREATE TABLE AS statement could cause a NULL pointer dereference, rela

    HighCVSS 7.5No exploitEPSS 8%

    sqlite · sqliteMar 16, 2018

  • multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() cal

    HighCVSS 7.5No exploitEPSS 7%

    sqlite · sqliteDec 22, 2019

  • SQLite 3.25.2, when queries are run on a table with a malformed PRIMARY KEY, allows remote attackers to cause a denial of service (applicati

    HighCVSS 7.5No exploitEPSS 7%

    sqlite · sqliteApr 3, 2019

  • exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values i

    HighCVSS 7.5No exploitEPSS 7%

    sqlite · sqliteDec 18, 2019

  • zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.

    HighCVSS 7.5No exploitEPSS 7%

    sqlite · sqliteDec 24, 2019

  • flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side i

    HighCVSS 7.5No exploitEPSS 7%

    sqlite · sqliteDec 24, 2019

  • CVE-2019-9937
    32Monitor

    In SQLite 3.27.2, interleaving reads and writes in a single transaction with an fts5 virtual table will lead to a NULL Pointer Dereference i

    HighCVSS 7.5No exploitEPSS 6%

    sqlite · sqliteMar 22, 2019

  • CVE-2015-3416
    32Monitor

    The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floating-point co

    HighCVSS 7.5No exploitEPSS 6%

    sqlite · sqliteApr 24, 2015

  • CVE-2019-9936
    31Monitor

    In SQLite 3.27.2, running fts5 prefix queries inside a transaction could trigger a heap-based buffer over-read in fts5HashEntrySort in sqlit

    HighCVSS 7.5No exploitEPSS 5%

    sqlite · sqliteMar 22, 2019