Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-3119

Опубликовано: 25 мар. 2021
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

Zetetic SQLCipher 4.x before 4.4.3 has a NULL pointer dereferencing issue related to sqlcipher_export in crypto.c and sqlite3StrICmp in sqlite3.c. This may allow an attacker to perform a remote denial of service attack. For example, an SQL injection can be used to execute the crafted SQL command sequence, which causes a segmentation fault.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:zetetic:sqlcipher:*:*:*:*:*:*:*:*
Версия от 4.0 (включая) до 4.4.3 (исключая)

EPSS

Процентиль: 69%
0.00603
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-476

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 5 лет назад

Zetetic SQLCipher 4.x before 4.4.3 has a NULL pointer dereferencing issue related to sqlcipher_export in crypto.c and sqlite3StrICmp in sqlite3.c. This may allow an attacker to perform a remote denial of service attack. For example, an SQL injection can be used to execute the crafted SQL command sequence, which causes a segmentation fault.

CVSS3: 7.5
debian
почти 5 лет назад

Zetetic SQLCipher 4.x before 4.4.3 has a NULL pointer dereferencing is ...

CVSS3: 7.5
github
больше 3 лет назад

Zetetic SQLCipher 4.x before 4.4.3 has a NULL pointer dereferencing issue related to sqlcipher_export in crypto.c and sqlite3StrICmp in sqlite3.c. This may allow an attacker to perform a remote denial of service attack. For example, an SQL injection can be used to execute the crafted SQL command sequence, which causes a segmentation fault.

EPSS

Процентиль: 69%
0.00603
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-476