SQLite 3.37.0

CPE Details

SQLite 3.37.0
3.37.0
2022-02-17
16h54 +00:00
2022-03-04
18h06 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:sqlite:sqlite:3.37.0:*:*:*:*:*:*:*

Informations

Vendor

sqlite

Product

sqlite

Version

3.37.0

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-7104 2023-12-25 21h00 +00:00 A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The manipulation leads to heap-based buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-248999.
7.3
High
CVE-2022-46908 2022-12-11 23h00 +00:00 SQLite through 3.40.0, when relying on --safe for execution of an untrusted CLI script, does not properly implement the azProhibitedFunctions protection mechanism, and instead allows UDF functions such as WRITEFILE.
7.3
High
CVE-2022-35737 2022-08-02 22h00 +00:00 SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.
7.5
High
CVE-2021-45346 2022-02-13 23h00 +00:00 A Memory Leak vulnerability exists in SQLite Project SQLite3 3.35.1 and 3.37.0 via maliciously crafted SQL Queries (made via editing the Database File), it is possible to query a record, and leak subsequent bytes of memory that extend beyond the record, which could let a malicious user obtain sensitive information. NOTE: The developer disputes this as a vulnerability stating that If you give SQLite a corrupted database file and submit a query against the database, it might read parts of the database that you did not intend or expect.
4.3
Medium