SQLite 3.27.0

CPE Details

SQLite 3.27.0
3.27.0
2019-09-10
17h17 +00:00
2019-09-10
17h17 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:sqlite:sqlite:3.27.0:*:*:*:*:*:*:*

Informations

Vendor

sqlite

Product

sqlite

Version

3.27.0

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-7104 2023-12-25
21h00 +00:00
A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The manipulation leads to heap-based buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-248999.
7.3
High
CVE-2022-35737 2022-08-02
22h00 +00:00
SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.
7.5
High
CVE-2020-15358 2020-06-27
09h39 +00:00
In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.
5.5
Medium
CVE-2020-13630 2020-05-27
12h42 +00:00
ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.
7
High
CVE-2020-13631 2020-05-27
12h42 +00:00
SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c.
5.5
Medium
CVE-2020-13632 2020-05-27
12h42 +00:00
ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query.
5.5
Medium
CVE-2020-13434 2020-05-24
19h55 +00:00
SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.
5.5
Medium
CVE-2020-13435 2020-05-24
19h55 +00:00
SQLite through 3.32.0 has a segmentation fault in sqlite3ExprCodeTarget in expr.c.
5.5
Medium
CVE-2020-11655 2020-04-09
00h49 +00:00
SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query because the AggInfo object's initialization is mishandled.
7.5
High
CVE-2020-11656 2020-04-09
00h49 +00:00
In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELECT statement.
9.8
Critical
CVE-2019-19646 2019-12-09
17h36 +00:00
pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.
9.8
Critical
CVE-2019-19645 2019-12-09
14h15 +00:00
alter.c in SQLite through 3.30.1 allows attackers to trigger infinite recursion via certain types of self-referential views in conjunction with ALTER TABLE statements.
5.5
Medium
CVE-2019-16168 2019-09-09
14h07 +00:00
In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner."
6.5
Medium
CVE-2019-8457 2019-05-30
13h51 +00:00
SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tables.
9.8
Critical