CVE-2017-10989
- EPSS 12.48%
- Published 07.07.2017 12:29:00
- Last modified 20.04.2025 01:37:25
The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used in GDAL and other products, mishandles undersized RTree blobs in a crafted database, leading to a heap-based buffer over-read or possibly unspecified other impact.
CVE-2016-6153
- EPSS 0.03%
- Published 26.09.2016 16:59:03
- Last modified 12.04.2025 10:46:40
os_unix.c in SQLite before 3.13.0 improperly implements the temporary directory search algorithm, which might allow local users to obtain sensitive information, cause a denial of service (application crash), or have unspecified other impact by levera...
CVE-2015-6607
- EPSS 0.4%
- Published 06.10.2015 17:59:25
- Last modified 12.04.2025 10:46:40
SQLite before 3.8.9, as used in Android before 5.1.1 LMY48T, allows attackers to gain privileges via a crafted application, aka internal bug 20099586.
- EPSS 25.98%
- Published 18.09.2015 12:00:24
- Last modified 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in SQLite before 3.8.10.2, as used in Apple iOS before 9, have unknown impact and attack vectors.
- EPSS 1.27%
- Published 12.08.2015 14:59:00
- Last modified 12.04.2025 10:46:40
Buffer overflow in the skip-scan optimization in SQLite 3.8.2 allows remote attackers to cause a denial of service (crash) via crafted SQL statements.
CVE-2015-3717
- EPSS 1.44%
- Published 03.07.2015 02:00:08
- Last modified 12.04.2025 10:46:40
Multiple buffer overflows in the printf functionality in SQLite, as used in Apple iOS before 8.4 and OS X before 10.10.4, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
CVE-2015-3416
- EPSS 5.09%
- Published 24.04.2015 17:59:02
- Last modified 12.04.2025 10:46:40
The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floating-point conversions, which allows context-dependent attackers to cause a denial of service (integer overflow and stack-b...
CVE-2015-3415
- EPSS 7.08%
- Published 24.04.2015 17:59:01
- Last modified 12.04.2025 10:46:40
The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact v...
CVE-2015-3414
- EPSS 7.08%
- Published 24.04.2015 17:59:00
- Last modified 12.04.2025 10:46:40
SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which allows context-dependent attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other im...
CVE-2008-6589
- EPSS 0.52%
- Published 03.04.2009 18:30:00
- Last modified 09.04.2025 00:30:58
Multiple cross-site scripting (XSS) vulnerabilities in LightNEasy "no database" (aka flat) version 1.2.2, and possibly SQLite version 1.2.2, allow remote attackers to inject arbitrary web script or HTML via the page parameter to (1) index.php and (2)...