7.5

CVE-2019-19880

exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled.

Data is provided by the National Vulnerability Database (NVD)
SqliteSqlite Version3.30.1
NetappCloud Backup Version-
DebianDebian Linux Version9.0
DebianDebian Linux Version10.0
SusePackage Hub Version-
   SuseLinux Enterprise Version12.0
OpensuseBackports Sle Version15.0 Updatesp1
OpensuseLeap Version15.1
OracleMysql Workbench Version <= 8.0.19
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 8.44% 0.92
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.