Логотип exploitDog
bind:"CVE-2018-20506"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2018-20506"

Количество 10

Количество 10

ubuntu логотип

CVE-2018-20506

больше 6 лет назад

SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.

CVSS3: 8.1
EPSS: Средний
redhat логотип

CVE-2018-20506

больше 6 лет назад

SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.

CVSS3: 7
EPSS: Средний
nvd логотип

CVE-2018-20506

больше 6 лет назад

SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.

CVSS3: 8.1
EPSS: Средний
msrc логотип

CVE-2018-20506

около 1 года назад

CVSS3: 8.1
EPSS: Средний
debian логотип

CVE-2018-20506

больше 6 лет назад

SQLite before 3.25.3, when the FTS3 extension is enabled, encounters a ...

CVSS3: 8.1
EPSS: Средний
github логотип

GHSA-hfxx-8v8g-6rcx

больше 3 лет назад

SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.

CVSS3: 8.1
EPSS: Средний
fstec логотип

BDU:2020-02558

больше 6 лет назад

Уязвимость модуля виртуальных таблиц FTS3 системы управления базами данных SQLite, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.1
EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2019:1222-1

больше 6 лет назад

Security update for sqlite3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:0913-1

больше 6 лет назад

Security update for sqlite3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:0973-1

больше 6 лет назад

Security update for sqlite3

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2018-20506

SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.

CVSS3: 8.1
18%
Средний
больше 6 лет назад
redhat логотип
CVE-2018-20506

SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.

CVSS3: 7
18%
Средний
больше 6 лет назад
nvd логотип
CVE-2018-20506

SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.

CVSS3: 8.1
18%
Средний
больше 6 лет назад
msrc логотип
CVSS3: 8.1
18%
Средний
около 1 года назад
debian логотип
CVE-2018-20506

SQLite before 3.25.3, when the FTS3 extension is enabled, encounters a ...

CVSS3: 8.1
18%
Средний
больше 6 лет назад
github логотип
GHSA-hfxx-8v8g-6rcx

SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.

CVSS3: 8.1
18%
Средний
больше 3 лет назад
fstec логотип
BDU:2020-02558

Уязвимость модуля виртуальных таблиц FTS3 системы управления базами данных SQLite, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.1
18%
Средний
больше 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:1222-1

Security update for sqlite3

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:0913-1

Security update for sqlite3

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:0973-1

Security update for sqlite3

больше 6 лет назад

Уязвимостей на страницу