Записи sqlite
66 опубликованных записей вендора sqlite.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 87,9 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-476 NULL Pointer Dereference11
- CWE-190 Integer Overflow or Wraparound7
- CWE-416 Use After Free6
- CWE-122 Heap-based Buffer Overflow4
- CWE-125 Out-of-bounds Read4
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
66 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
53В плане | CVE-2019-8457Эксплойта нет | SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tsqlite · sqlite · CWE-125 | Критическая9,8 | — | 45,4 % | 30 мая 2019 г. |
50В плане | CVE-2025-6965Proof of concept | Integer Truncation on SQLitesqlite · sqlite · CWE-197 | Высокая7,2 | — | 72,5 % | 15 июл. 2025 г. |
43В плане | CVE-2015-5895Proof of concept | Multiple unspecified vulnerabilities in SQLite before 3.8.10.2, as used in Apple iOS before 9, have unknown impact and attack vectors.sqlite · sqlite | Критическая10,0 | — | 9,2 % | 18 сент. 2015 г. |
42В плане | CVE-2017-10989Эксплойта нет | The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used in GDAL and other products, mishandles undersized RTree blobsqlite · sqlite · CWE-125 | Критическая9,8 | — | 8,6 % | 7 июл. 2017 г. |
41В плане | CVE-2020-11656Эксплойта нет | In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a composqlite · sqlite · CWE-416 | Критическая9,8 | — | 7,6 % | 8 апр. 2020 г. |
41В плане | CVE-2019-19646Эксплойта нет | pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.sqlite · sqlite · CWE-754 | Критическая9,8 | — | 5,4 % | 9 дек. 2019 г. |
40В плане | CVE-2019-19317Эксплойта нет | lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which allows attackers to casqlite · sqlite · CWE-681 | Критическая9,8 | — | 4,3 % | 5 дек. 2019 г. |
39Наблюдать | CVE-2020-35527Эксплойта нет | In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE for views that have a nested FROM clause.sqlite · sqlite · CWE-119 | Критическая9,8 | — | 1,2 % | 1 сент. 2022 г. |
37Наблюдать | CVE-2022-35737Proof of concept | SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to asqlite · sqlite · CWE-129 | Высокая7,5 | — | 22,8 % | 3 авг. 2022 г. |
37Наблюдать | CVE-2022-31631Эксплойта нет | PDO::quote() may return unquoted stringphp · php · CWE-74 | Критическая9,1 | — | 2,2 % | 12 февр. 2025 г. |
35Наблюдать | CVE-2018-20346Эксплойта нет | SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries thsqlite · sqlite · CWE-190 | Высокая8,1 | — | 10,3 % | 21 дек. 2018 г. |
34Наблюдать | CVE-2018-20506Эксплойта нет | SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries insqlite · sqlite · CWE-190 | Высокая8,1 | — | 7,6 % | 3 апр. 2019 г. |
34Наблюдать | CVE-2019-5018Эксплойта нет | An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0.sqlite · sqlite · CWE-416 | Высокая8,1 | — | 6,7 % | 10 мая 2019 г. |
34Наблюдать | CVE-2026-11822Эксплойта нет | SQLite before 3.53.2 Memory Corruption in FTS5 Extensionsqlite · sqlite · CWE-122 | Высокая8,5 | — | 0,3 % | 9 июн. 2026 г. |
34Наблюдать | CVE-2026-11824Эксплойта нет | SQLite before 3.53.2 Heap Buffer Overflow via FTS5 fts5ChunkIteratesqlite · sqlite · CWE-122 | Высокая8,5 | — | 0,2 % | 9 июн. 2026 г. |
32Наблюдать | CVE-2019-19603Эксплойта нет | SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash.sqlite · sqlite | Высокая7,5 | — | 8,3 % | 9 дек. 2019 г. |
32Наблюдать | CVE-2018-8740Эксплойта нет | In SQLite through 3.22.0, databases whose schema is corrupted using a CREATE TABLE AS statement could cause a NULL pointer dereference, relasqlite · sqlite · CWE-476 | Высокая7,5 | — | 8,0 % | 16 мар. 2018 г. |
32Наблюдать | CVE-2019-19926Эксплойта нет | multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() calsqlite · sqlite · CWE-476 | Высокая7,5 | — | 7,0 % | 22 дек. 2019 г. |
32Наблюдать | CVE-2018-20505Эксплойта нет | SQLite 3.25.2, when queries are run on a table with a malformed PRIMARY KEY, allows remote attackers to cause a denial of service (applicatisqlite · sqlite · CWE-89 | Высокая7,5 | — | 7,0 % | 3 апр. 2019 г. |
32Наблюдать | CVE-2019-19880Эксплойта нет | exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values isqlite · sqlite · CWE-476 | Высокая7,5 | — | 6,9 % | 18 дек. 2019 г. |
32Наблюдать | CVE-2019-19925Эксплойта нет | zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.sqlite · sqlite · CWE-434 | Высокая7,5 | — | 6,8 % | 24 дек. 2019 г. |
32Наблюдать | CVE-2019-19923Эксплойта нет | flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side isqlite · sqlite · CWE-476 | Высокая7,5 | — | 6,8 % | 24 дек. 2019 г. |
32Наблюдать | CVE-2019-9937Эксплойта нет | In SQLite 3.27.2, interleaving reads and writes in a single transaction with an fts5 virtual table will lead to a NULL Pointer Dereference isqlite · sqlite · CWE-476 | Высокая7,5 | — | 6,0 % | 22 мар. 2019 г. |
32Наблюдать | CVE-2015-3416Эксплойта нет | The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floating-point cosqlite · sqlite · CWE-190 | Высокая7,5 | — | 5,7 % | 24 апр. 2015 г. |
31Наблюдать | CVE-2019-9936Эксплойта нет | In SQLite 3.27.2, running fts5 prefix queries inside a transaction could trigger a heap-based buffer over-read in fts5HashEntrySort in sqlitsqlite · sqlite · CWE-125 | Высокая7,5 | — | 4,8 % | 22 мар. 2019 г. |
- CVE-2019-845753В плане
SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree t
КритическаяCVSS 9,8Эксплойта нетEPSS 45 %sqlite · sqlite30 мая 2019 г.
- CVE-2025-696550В плане
Integer Truncation on SQLite
ВысокаяCVSS 7,2Proof of conceptEPSS 73 %sqlite · sqlite15 июл. 2025 г.
- CVE-2015-589543В плане
Multiple unspecified vulnerabilities in SQLite before 3.8.10.2, as used in Apple iOS before 9, have unknown impact and attack vectors.
КритическаяCVSS 10,0Proof of conceptEPSS 9 %sqlite · sqlite18 сент. 2015 г.
- CVE-2017-1098942В плане
The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used in GDAL and other products, mishandles undersized RTree blob
КритическаяCVSS 9,8Эксплойта нетEPSS 9 %sqlite · sqlite7 июл. 2017 г.
- CVE-2020-1165641В плане
In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compo
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %sqlite · sqlite8 апр. 2020 г.
- CVE-2019-1964641В плане
pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %sqlite · sqlite9 дек. 2019 г.
- CVE-2019-1931740В плане
lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which allows attackers to ca
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %sqlite · sqlite5 дек. 2019 г.
- CVE-2020-3552739Наблюдать
In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE for views that have a nested FROM clause.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sqlite · sqlite1 сент. 2022 г.
- CVE-2022-3573737Наблюдать
SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a
ВысокаяCVSS 7,5Proof of conceptEPSS 23 %sqlite · sqlite3 авг. 2022 г.
- CVE-2022-3163137Наблюдать
PDO::quote() may return unquoted string
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %php · php12 февр. 2025 г.
- CVE-2018-2034635Наблюдать
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries th
ВысокаяCVSS 8,1Эксплойта нетEPSS 10 %sqlite · sqlite21 дек. 2018 г.
- CVE-2018-2050634Наблюдать
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in
ВысокаяCVSS 8,1Эксплойта нетEPSS 8 %sqlite · sqlite3 апр. 2019 г.
- CVE-2019-501834Наблюдать
An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0.
ВысокаяCVSS 8,1Эксплойта нетEPSS 7 %sqlite · sqlite10 мая 2019 г.
- CVE-2026-1182234Наблюдать
SQLite before 3.53.2 Memory Corruption in FTS5 Extension
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %sqlite · sqlite9 июн. 2026 г.
- CVE-2026-1182434Наблюдать
SQLite before 3.53.2 Heap Buffer Overflow via FTS5 fts5ChunkIterate
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %sqlite · sqlite9 июн. 2026 г.
- CVE-2019-1960332Наблюдать
SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash.
ВысокаяCVSS 7,5Эксплойта нетEPSS 8 %sqlite · sqlite9 дек. 2019 г.
- CVE-2018-874032Наблюдать
In SQLite through 3.22.0, databases whose schema is corrupted using a CREATE TABLE AS statement could cause a NULL pointer dereference, rela
ВысокаяCVSS 7,5Эксплойта нетEPSS 8 %sqlite · sqlite16 мар. 2018 г.
- CVE-2019-1992632Наблюдать
multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() cal
ВысокаяCVSS 7,5Эксплойта нетEPSS 7 %sqlite · sqlite22 дек. 2019 г.
- CVE-2018-2050532Наблюдать
SQLite 3.25.2, when queries are run on a table with a malformed PRIMARY KEY, allows remote attackers to cause a denial of service (applicati
ВысокаяCVSS 7,5Эксплойта нетEPSS 7 %sqlite · sqlite3 апр. 2019 г.
- CVE-2019-1988032Наблюдать
exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values i
ВысокаяCVSS 7,5Эксплойта нетEPSS 7 %sqlite · sqlite18 дек. 2019 г.
- CVE-2019-1992532Наблюдать
zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.
ВысокаяCVSS 7,5Эксплойта нетEPSS 7 %sqlite · sqlite24 дек. 2019 г.
- CVE-2019-1992332Наблюдать
flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side i
ВысокаяCVSS 7,5Эксплойта нетEPSS 7 %sqlite · sqlite24 дек. 2019 г.
- CVE-2019-993732Наблюдать
In SQLite 3.27.2, interleaving reads and writes in a single transaction with an fts5 virtual table will lead to a NULL Pointer Dereference i
ВысокаяCVSS 7,5Эксплойта нетEPSS 6 %sqlite · sqlite22 мар. 2019 г.
- CVE-2015-341632Наблюдать
The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floating-point co
ВысокаяCVSS 7,5Эксплойта нетEPSS 6 %sqlite · sqlite24 апр. 2015 г.
- CVE-2019-993631Наблюдать
In SQLite 3.27.2, running fts5 prefix queries inside a transaction could trigger a heap-based buffer over-read in fts5HashEntrySort in sqlit
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %sqlite · sqlite22 мар. 2019 г.