7.5
CVE-2020-11655
- EPSS 4.89%
- Published 09.04.2020 03:15:11
- Last modified 21.11.2024 04:58:20
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query because the AggInfo object's initialization is mishandled.
Data is provided by the National Vulnerability Database (NVD)
Netapp ≫ Ontap Select Deploy Administration Utility Version-
Debian ≫ Debian Linux Version8.0
Debian ≫ Debian Linux Version9.0
Canonical ≫ Ubuntu Linux Version16.04 SwEditionlts
Canonical ≫ Ubuntu Linux Version18.04 SwEditionlts
Canonical ≫ Ubuntu Linux Version19.10
Canonical ≫ Ubuntu Linux Version20.04 SwEditionlts
Oracle ≫ Communications Element Manager Version >= 8.2.0 <= 8.2.2
Oracle ≫ Communications Network Charging And Control Version >= 12.0.0 <= 12.0.3
Oracle ≫ Communications Network Charging And Control Version6.0.1
Oracle ≫ Communications Network Charging And Control Version12.0.2
Oracle ≫ Communications Session Report Manager Version >= 8.2.0 <= 8.2.2
Oracle ≫ Communications Session Route Manager Version >= 8.2.0 <= 8.2.2
Oracle ≫ Enterprise Manager Ops Center Version12.4.0.0
Oracle ≫ Hyperion Infrastructure Technology Version11.1.2.4
Oracle ≫ Instantis Enterprisetrack Version17.1
Oracle ≫ Instantis Enterprisetrack Version17.2
Oracle ≫ Instantis Enterprisetrack Version17.3
Oracle ≫ Mysql Workbench Version <= 8.0.22
Oracle ≫ Outside In Technology Version8.5.4
Oracle ≫ Outside In Technology Version8.5.5
Oracle ≫ Zfs Storage Appliance Kit Version8.8
Oracle ≫ Communications Messaging Server Version8.1
Siemens ≫ Sinec Infrastructure Network Services Version < 1.0.1.1
Tenable ≫ Tenable.Sc Version < 5.19.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 4.89% | 0.892 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
CWE-665 Improper Initialization
The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.