sqlite kayıtları
sqlite üreticisine ait 66 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 5
- Düzeltme kaydı olan
- %87,9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-476 NULL Pointer Dereference11
- CWE-190 Integer Overflow or Wraparound7
- CWE-416 Use After Free6
- CWE-122 Heap-based Buffer Overflow4
- CWE-125 Out-of-bounds Read4
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
66 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
53Planlayın | CVE-2019-8457İstismar yok | SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tsqlite · sqlite · CWE-125 | Kritik9,8 | — | %45,4 | 30 May 2019 |
50Planlayın | CVE-2025-6965Kavram kanıtı | Integer Truncation on SQLitesqlite · sqlite · CWE-197 | Yüksek7,2 | — | %72,5 | 15 Tem 2025 |
43Planlayın | CVE-2015-5895Kavram kanıtı | Multiple unspecified vulnerabilities in SQLite before 3.8.10.2, as used in Apple iOS before 9, have unknown impact and attack vectors.sqlite · sqlite | Kritik10,0 | — | %9,2 | 18 Eyl 2015 |
42Planlayın | CVE-2017-10989İstismar yok | The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used in GDAL and other products, mishandles undersized RTree blobsqlite · sqlite · CWE-125 | Kritik9,8 | — | %8,6 | 7 Tem 2017 |
41Planlayın | CVE-2020-11656İstismar yok | In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a composqlite · sqlite · CWE-416 | Kritik9,8 | — | %7,6 | 8 Nis 2020 |
41Planlayın | CVE-2019-19646İstismar yok | pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.sqlite · sqlite · CWE-754 | Kritik9,8 | — | %5,4 | 9 Ara 2019 |
40Planlayın | CVE-2019-19317İstismar yok | lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which allows attackers to casqlite · sqlite · CWE-681 | Kritik9,8 | — | %4,3 | 5 Ara 2019 |
39İzleyin | CVE-2020-35527İstismar yok | In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE for views that have a nested FROM clause.sqlite · sqlite · CWE-119 | Kritik9,8 | — | %1,2 | 1 Eyl 2022 |
37İzleyin | CVE-2022-35737Kavram kanıtı | SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to asqlite · sqlite · CWE-129 | Yüksek7,5 | — | %22,8 | 3 Ağu 2022 |
37İzleyin | CVE-2022-31631İstismar yok | PDO::quote() may return unquoted stringphp · php · CWE-74 | Kritik9,1 | — | %2,2 | 12 Şub 2025 |
35İzleyin | CVE-2018-20346İstismar yok | SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries thsqlite · sqlite · CWE-190 | Yüksek8,1 | — | %10,3 | 21 Ara 2018 |
34İzleyin | CVE-2018-20506İstismar yok | SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries insqlite · sqlite · CWE-190 | Yüksek8,1 | — | %7,6 | 3 Nis 2019 |
34İzleyin | CVE-2019-5018İstismar yok | An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0.sqlite · sqlite · CWE-416 | Yüksek8,1 | — | %6,7 | 10 May 2019 |
34İzleyin | CVE-2026-11822İstismar yok | SQLite before 3.53.2 Memory Corruption in FTS5 Extensionsqlite · sqlite · CWE-122 | Yüksek8,5 | — | %0,3 | 9 Haz 2026 |
34İzleyin | CVE-2026-11824İstismar yok | SQLite before 3.53.2 Heap Buffer Overflow via FTS5 fts5ChunkIteratesqlite · sqlite · CWE-122 | Yüksek8,5 | — | %0,2 | 9 Haz 2026 |
32İzleyin | CVE-2019-19603İstismar yok | SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash.sqlite · sqlite | Yüksek7,5 | — | %8,3 | 9 Ara 2019 |
32İzleyin | CVE-2018-8740İstismar yok | In SQLite through 3.22.0, databases whose schema is corrupted using a CREATE TABLE AS statement could cause a NULL pointer dereference, relasqlite · sqlite · CWE-476 | Yüksek7,5 | — | %8,0 | 16 Mar 2018 |
32İzleyin | CVE-2019-19926İstismar yok | multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() calsqlite · sqlite · CWE-476 | Yüksek7,5 | — | %7,0 | 22 Ara 2019 |
32İzleyin | CVE-2018-20505İstismar yok | SQLite 3.25.2, when queries are run on a table with a malformed PRIMARY KEY, allows remote attackers to cause a denial of service (applicatisqlite · sqlite · CWE-89 | Yüksek7,5 | — | %7,0 | 3 Nis 2019 |
32İzleyin | CVE-2019-19880İstismar yok | exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values isqlite · sqlite · CWE-476 | Yüksek7,5 | — | %6,9 | 18 Ara 2019 |
32İzleyin | CVE-2019-19925İstismar yok | zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.sqlite · sqlite · CWE-434 | Yüksek7,5 | — | %6,8 | 24 Ara 2019 |
32İzleyin | CVE-2019-19923İstismar yok | flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side isqlite · sqlite · CWE-476 | Yüksek7,5 | — | %6,8 | 24 Ara 2019 |
32İzleyin | CVE-2019-9937İstismar yok | In SQLite 3.27.2, interleaving reads and writes in a single transaction with an fts5 virtual table will lead to a NULL Pointer Dereference isqlite · sqlite · CWE-476 | Yüksek7,5 | — | %6,0 | 22 Mar 2019 |
32İzleyin | CVE-2015-3416İstismar yok | The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floating-point cosqlite · sqlite · CWE-190 | Yüksek7,5 | — | %5,7 | 24 Nis 2015 |
31İzleyin | CVE-2019-9936İstismar yok | In SQLite 3.27.2, running fts5 prefix queries inside a transaction could trigger a heap-based buffer over-read in fts5HashEntrySort in sqlitsqlite · sqlite · CWE-125 | Yüksek7,5 | — | %4,8 | 22 Mar 2019 |
- CVE-2019-845753Planlayın
SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree t
KritikCVSS 9,8İstismar yokEPSS %45sqlite · sqlite30 May 2019
- CVE-2025-696550Planlayın
Integer Truncation on SQLite
YüksekCVSS 7,2Kavram kanıtıEPSS %73sqlite · sqlite15 Tem 2025
- CVE-2015-589543Planlayın
Multiple unspecified vulnerabilities in SQLite before 3.8.10.2, as used in Apple iOS before 9, have unknown impact and attack vectors.
KritikCVSS 10,0Kavram kanıtıEPSS %9sqlite · sqlite18 Eyl 2015
- CVE-2017-1098942Planlayın
The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used in GDAL and other products, mishandles undersized RTree blob
KritikCVSS 9,8İstismar yokEPSS %9sqlite · sqlite7 Tem 2017
- CVE-2020-1165641Planlayın
In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compo
KritikCVSS 9,8İstismar yokEPSS %8sqlite · sqlite8 Nis 2020
- CVE-2019-1964641Planlayın
pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.
KritikCVSS 9,8İstismar yokEPSS %5sqlite · sqlite9 Ara 2019
- CVE-2019-1931740Planlayın
lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which allows attackers to ca
KritikCVSS 9,8İstismar yokEPSS %4sqlite · sqlite5 Ara 2019
- CVE-2020-3552739İzleyin
In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE for views that have a nested FROM clause.
KritikCVSS 9,8İstismar yokEPSS %1sqlite · sqlite1 Eyl 2022
- CVE-2022-3573737İzleyin
SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a
YüksekCVSS 7,5Kavram kanıtıEPSS %23sqlite · sqlite3 Ağu 2022
- CVE-2022-3163137İzleyin
PDO::quote() may return unquoted string
KritikCVSS 9,1İstismar yokEPSS %2php · php12 Şub 2025
- CVE-2018-2034635İzleyin
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries th
YüksekCVSS 8,1İstismar yokEPSS %10sqlite · sqlite21 Ara 2018
- CVE-2018-2050634İzleyin
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in
YüksekCVSS 8,1İstismar yokEPSS %8sqlite · sqlite3 Nis 2019
- CVE-2019-501834İzleyin
An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0.
YüksekCVSS 8,1İstismar yokEPSS %7sqlite · sqlite10 May 2019
- CVE-2026-1182234İzleyin
SQLite before 3.53.2 Memory Corruption in FTS5 Extension
YüksekCVSS 8,5İstismar yokEPSS %0sqlite · sqlite9 Haz 2026
- CVE-2026-1182434İzleyin
SQLite before 3.53.2 Heap Buffer Overflow via FTS5 fts5ChunkIterate
YüksekCVSS 8,5İstismar yokEPSS %0sqlite · sqlite9 Haz 2026
- CVE-2019-1960332İzleyin
SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash.
YüksekCVSS 7,5İstismar yokEPSS %8sqlite · sqlite9 Ara 2019
- CVE-2018-874032İzleyin
In SQLite through 3.22.0, databases whose schema is corrupted using a CREATE TABLE AS statement could cause a NULL pointer dereference, rela
YüksekCVSS 7,5İstismar yokEPSS %8sqlite · sqlite16 Mar 2018
- CVE-2019-1992632İzleyin
multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() cal
YüksekCVSS 7,5İstismar yokEPSS %7sqlite · sqlite22 Ara 2019
- CVE-2018-2050532İzleyin
SQLite 3.25.2, when queries are run on a table with a malformed PRIMARY KEY, allows remote attackers to cause a denial of service (applicati
YüksekCVSS 7,5İstismar yokEPSS %7sqlite · sqlite3 Nis 2019
- CVE-2019-1988032İzleyin
exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values i
YüksekCVSS 7,5İstismar yokEPSS %7sqlite · sqlite18 Ara 2019
- CVE-2019-1992532İzleyin
zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.
YüksekCVSS 7,5İstismar yokEPSS %7sqlite · sqlite24 Ara 2019
- CVE-2019-1992332İzleyin
flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side i
YüksekCVSS 7,5İstismar yokEPSS %7sqlite · sqlite24 Ara 2019
- CVE-2019-993732İzleyin
In SQLite 3.27.2, interleaving reads and writes in a single transaction with an fts5 virtual table will lead to a NULL Pointer Dereference i
YüksekCVSS 7,5İstismar yokEPSS %6sqlite · sqlite22 Mar 2019
- CVE-2015-341632İzleyin
The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floating-point co
YüksekCVSS 7,5İstismar yokEPSS %6sqlite · sqlite24 Nis 2015
- CVE-2019-993631İzleyin
In SQLite 3.27.2, running fts5 prefix queries inside a transaction could trigger a heap-based buffer over-read in fts5HashEntrySort in sqlit
YüksekCVSS 7,5İstismar yokEPSS %5sqlite · sqlite22 Mar 2019