sqlite records
66 published records for vendor sqlite.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 5
- With a fix record
- 87.9%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-476 NULL Pointer Dereference11
- CWE-190 Integer Overflow or Wraparound7
- CWE-416 Use After Free6
- CWE-122 Heap-based Buffer Overflow4
- CWE-125 Out-of-bounds Read4
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
The weakness classes this vendor ships most often: where to look.
CWEAll records
66 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
53Plan | CVE-2019-8457No exploit | SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tsqlite · sqlite · CWE-125 | Critical9.8 | — | 45.4% | May 30, 2019 |
50Plan | CVE-2025-6965Proof of concept | Integer Truncation on SQLitesqlite · sqlite · CWE-197 | High7.2 | — | 72.5% | Jul 15, 2025 |
43Plan | CVE-2015-5895Proof of concept | Multiple unspecified vulnerabilities in SQLite before 3.8.10.2, as used in Apple iOS before 9, have unknown impact and attack vectors.sqlite · sqlite | Critical10.0 | — | 9.2% | Sep 18, 2015 |
42Plan | CVE-2017-10989No exploit | The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used in GDAL and other products, mishandles undersized RTree blobsqlite · sqlite · CWE-125 | Critical9.8 | — | 8.6% | Jul 7, 2017 |
41Plan | CVE-2020-11656No exploit | In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a composqlite · sqlite · CWE-416 | Critical9.8 | — | 7.6% | Apr 8, 2020 |
41Plan | CVE-2019-19646No exploit | pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.sqlite · sqlite · CWE-754 | Critical9.8 | — | 5.4% | Dec 9, 2019 |
40Plan | CVE-2019-19317No exploit | lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which allows attackers to casqlite · sqlite · CWE-681 | Critical9.8 | — | 4.3% | Dec 5, 2019 |
39Monitor | CVE-2020-35527No exploit | In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE for views that have a nested FROM clause.sqlite · sqlite · CWE-119 | Critical9.8 | — | 1.2% | Sep 1, 2022 |
37Monitor | CVE-2022-35737Proof of concept | SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to asqlite · sqlite · CWE-129 | High7.5 | — | 22.8% | Aug 3, 2022 |
37Monitor | CVE-2022-31631No exploit | PDO::quote() may return unquoted stringphp · php · CWE-74 | Critical9.1 | — | 2.2% | Feb 12, 2025 |
35Monitor | CVE-2018-20346No exploit | SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries thsqlite · sqlite · CWE-190 | High8.1 | — | 10.3% | Dec 21, 2018 |
34Monitor | CVE-2018-20506No exploit | SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries insqlite · sqlite · CWE-190 | High8.1 | — | 7.6% | Apr 3, 2019 |
34Monitor | CVE-2019-5018No exploit | An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0.sqlite · sqlite · CWE-416 | High8.1 | — | 6.7% | May 10, 2019 |
34Monitor | CVE-2026-11822No exploit | SQLite before 3.53.2 Memory Corruption in FTS5 Extensionsqlite · sqlite · CWE-122 | High8.5 | — | 0.3% | Jun 9, 2026 |
34Monitor | CVE-2026-11824No exploit | SQLite before 3.53.2 Heap Buffer Overflow via FTS5 fts5ChunkIteratesqlite · sqlite · CWE-122 | High8.5 | — | 0.2% | Jun 9, 2026 |
32Monitor | CVE-2019-19603No exploit | SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash.sqlite · sqlite | High7.5 | — | 8.3% | Dec 9, 2019 |
32Monitor | CVE-2018-8740No exploit | In SQLite through 3.22.0, databases whose schema is corrupted using a CREATE TABLE AS statement could cause a NULL pointer dereference, relasqlite · sqlite · CWE-476 | High7.5 | — | 8.0% | Mar 16, 2018 |
32Monitor | CVE-2019-19926No exploit | multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() calsqlite · sqlite · CWE-476 | High7.5 | — | 7.0% | Dec 22, 2019 |
32Monitor | CVE-2018-20505No exploit | SQLite 3.25.2, when queries are run on a table with a malformed PRIMARY KEY, allows remote attackers to cause a denial of service (applicatisqlite · sqlite · CWE-89 | High7.5 | — | 7.0% | Apr 3, 2019 |
32Monitor | CVE-2019-19880No exploit | exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values isqlite · sqlite · CWE-476 | High7.5 | — | 6.9% | Dec 18, 2019 |
32Monitor | CVE-2019-19925No exploit | zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.sqlite · sqlite · CWE-434 | High7.5 | — | 6.8% | Dec 24, 2019 |
32Monitor | CVE-2019-19923No exploit | flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side isqlite · sqlite · CWE-476 | High7.5 | — | 6.8% | Dec 24, 2019 |
32Monitor | CVE-2019-9937No exploit | In SQLite 3.27.2, interleaving reads and writes in a single transaction with an fts5 virtual table will lead to a NULL Pointer Dereference isqlite · sqlite · CWE-476 | High7.5 | — | 6.0% | Mar 22, 2019 |
32Monitor | CVE-2015-3416No exploit | The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floating-point cosqlite · sqlite · CWE-190 | High7.5 | — | 5.7% | Apr 24, 2015 |
31Monitor | CVE-2019-9936No exploit | In SQLite 3.27.2, running fts5 prefix queries inside a transaction could trigger a heap-based buffer over-read in fts5HashEntrySort in sqlitsqlite · sqlite · CWE-125 | High7.5 | — | 4.8% | Mar 22, 2019 |
- CVE-2019-845753Plan
SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree t
CriticalCVSS 9.8No exploitEPSS 45%sqlite · sqliteMay 30, 2019
- CVE-2025-696550Plan
Integer Truncation on SQLite
HighCVSS 7.2Proof of conceptEPSS 73%sqlite · sqliteJul 15, 2025
- CVE-2015-589543Plan
Multiple unspecified vulnerabilities in SQLite before 3.8.10.2, as used in Apple iOS before 9, have unknown impact and attack vectors.
CriticalCVSS 10.0Proof of conceptEPSS 9%sqlite · sqliteSep 18, 2015
- CVE-2017-1098942Plan
The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used in GDAL and other products, mishandles undersized RTree blob
CriticalCVSS 9.8No exploitEPSS 9%sqlite · sqliteJul 7, 2017
- CVE-2020-1165641Plan
In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compo
CriticalCVSS 9.8No exploitEPSS 8%sqlite · sqliteApr 8, 2020
- CVE-2019-1964641Plan
pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.
CriticalCVSS 9.8No exploitEPSS 5%sqlite · sqliteDec 9, 2019
- CVE-2019-1931740Plan
lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which allows attackers to ca
CriticalCVSS 9.8No exploitEPSS 4%sqlite · sqliteDec 5, 2019
- CVE-2020-3552739Monitor
In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE for views that have a nested FROM clause.
CriticalCVSS 9.8No exploitEPSS 1%sqlite · sqliteSep 1, 2022
- CVE-2022-3573737Monitor
SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a
HighCVSS 7.5Proof of conceptEPSS 23%sqlite · sqliteAug 3, 2022
- CVE-2022-3163137Monitor
PDO::quote() may return unquoted string
CriticalCVSS 9.1No exploitEPSS 2%php · phpFeb 12, 2025
- CVE-2018-2034635Monitor
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries th
HighCVSS 8.1No exploitEPSS 10%sqlite · sqliteDec 21, 2018
- CVE-2018-2050634Monitor
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in
HighCVSS 8.1No exploitEPSS 8%sqlite · sqliteApr 3, 2019
- CVE-2019-501834Monitor
An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0.
HighCVSS 8.1No exploitEPSS 7%sqlite · sqliteMay 10, 2019
- CVE-2026-1182234Monitor
SQLite before 3.53.2 Memory Corruption in FTS5 Extension
HighCVSS 8.5No exploitEPSS 0%sqlite · sqliteJun 9, 2026
- CVE-2026-1182434Monitor
SQLite before 3.53.2 Heap Buffer Overflow via FTS5 fts5ChunkIterate
HighCVSS 8.5No exploitEPSS 0%sqlite · sqliteJun 9, 2026
- CVE-2019-1960332Monitor
SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash.
HighCVSS 7.5No exploitEPSS 8%sqlite · sqliteDec 9, 2019
- CVE-2018-874032Monitor
In SQLite through 3.22.0, databases whose schema is corrupted using a CREATE TABLE AS statement could cause a NULL pointer dereference, rela
HighCVSS 7.5No exploitEPSS 8%sqlite · sqliteMar 16, 2018
- CVE-2019-1992632Monitor
multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() cal
HighCVSS 7.5No exploitEPSS 7%sqlite · sqliteDec 22, 2019
- CVE-2018-2050532Monitor
SQLite 3.25.2, when queries are run on a table with a malformed PRIMARY KEY, allows remote attackers to cause a denial of service (applicati
HighCVSS 7.5No exploitEPSS 7%sqlite · sqliteApr 3, 2019
- CVE-2019-1988032Monitor
exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values i
HighCVSS 7.5No exploitEPSS 7%sqlite · sqliteDec 18, 2019
- CVE-2019-1992532Monitor
zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.
HighCVSS 7.5No exploitEPSS 7%sqlite · sqliteDec 24, 2019
- CVE-2019-1992332Monitor
flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side i
HighCVSS 7.5No exploitEPSS 7%sqlite · sqliteDec 24, 2019
- CVE-2019-993732Monitor
In SQLite 3.27.2, interleaving reads and writes in a single transaction with an fts5 virtual table will lead to a NULL Pointer Dereference i
HighCVSS 7.5No exploitEPSS 6%sqlite · sqliteMar 22, 2019
- CVE-2015-341632Monitor
The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floating-point co
HighCVSS 7.5No exploitEPSS 6%sqlite · sqliteApr 24, 2015
- CVE-2019-993631Monitor
In SQLite 3.27.2, running fts5 prefix queries inside a transaction could trigger a heap-based buffer over-read in fts5HashEntrySort in sqlit
HighCVSS 7.5No exploitEPSS 5%sqlite · sqliteMar 22, 2019