Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qgrg-5hv8-3w32

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0. A specially crafted SQL command can cause a use after free vulnerability, potentially resulting in remote code execution. An attacker can send a malicious SQL command to trigger this vulnerability.

An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0. A specially crafted SQL command can cause a use after free vulnerability, potentially resulting in remote code execution. An attacker can send a malicious SQL command to trigger this vulnerability.

EPSS

Процентиль: 91%
0.07405
Низкий

8.1 High

CVSS3

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 6 лет назад

An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0. A specially crafted SQL command can cause a use after free vulnerability, potentially resulting in remote code execution. An attacker can send a malicious SQL command to trigger this vulnerability.

CVSS3: 8.1
redhat
больше 6 лет назад

An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0. A specially crafted SQL command can cause a use after free vulnerability, potentially resulting in remote code execution. An attacker can send a malicious SQL command to trigger this vulnerability.

CVSS3: 8.1
nvd
больше 6 лет назад

An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0. A specially crafted SQL command can cause a use after free vulnerability, potentially resulting in remote code execution. An attacker can send a malicious SQL command to trigger this vulnerability.

CVSS3: 8.1
debian
больше 6 лет назад

An exploitable use after free vulnerability exists in the window funct ...

CVSS3: 8.1
fstec
почти 6 лет назад

Уязвимость системы управления базами данных SQLite, связанная с использованием памяти после освобождения, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 91%
0.07405
Низкий

8.1 High

CVSS3

Дефекты

CWE-416