Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2022-35737

Опубликовано: 09 янв. 2024
Источник: msrc
EPSS Средний

Описание

MITRE: CVE-2022-35737 SQLite allows an array-bounds overflow

FAQ

Why is the MITRE Corporation the assigning CNA (CVE Numbering Authority)?

CVE-2022-35737 is regarding a vulnerability in SQLite. MITRE assigned this CVE number on behalf of the SQLite organization. Microsoft has included the updated library in Windows that addresses this vulnerability.

Обновления

ПродуктСтатьяОбновление
Windows 10 Version 1809 for 32-bit Systems
Windows 10 Version 1809 for x64-based Systems
Windows 10 Version 1809 for ARM64-based Systems
Windows Server 2019
Windows Server 2019 (Server Core installation)
Windows Server 2022
Windows Server 2022 (Server Core installation)
Windows 10 Version 21H2 for 32-bit Systems
Windows 10 Version 21H2 for ARM64-based Systems
Windows 10 Version 21H2 for x64-based Systems

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 98%
0.65609
Средний

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 3 года назад

SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.

CVSS3: 5.9
redhat
почти 3 года назад

SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.

CVSS3: 7.5
nvd
почти 3 года назад

SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.

CVSS3: 7.5
debian
почти 3 года назад

SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-b ...

rocky
больше 2 лет назад

Moderate: sqlite security update

EPSS

Процентиль: 98%
0.65609
Средний