7.5

CVE-2025-70873

Medienbericht
Exploit
An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sqlite ≫ Sqlite Version < 3.51.1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.215
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-244 Improper Clearing of Heap Memory Before Release ('Heap Inspection')

Using realloc() to resize buffers that store sensitive information can leave the sensitive information exposed to attack, because it is not removed from memory.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
08.09.2026 20:38
https://sqlite.org/forum/forumpost/761eac3c82
Issue Tracking
https://sqlite.org/src/info/3d459f1fb1bd1b5e
Patch
Issue Tracking
https://gist.github.com/cnwangjihe/f496393f30f5ecec5b18c8f5ab072054
Third Party Advisory
Exploit