Логотип exploitDog
bind:CVE-2018-20506
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-20506

Количество 10

Количество 10

ubuntu логотип

CVE-2018-20506

почти 7 лет назад

SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2018-20506

около 7 лет назад

SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2018-20506

почти 7 лет назад

SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.

CVSS3: 8.1
EPSS: Низкий
msrc логотип

CVE-2018-20506

больше 1 года назад

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2018-20506

почти 7 лет назад

SQLite before 3.25.3, when the FTS3 extension is enabled, encounters a ...

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-hfxx-8v8g-6rcx

больше 3 лет назад

SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.

CVSS3: 8.1
EPSS: Низкий
fstec логотип

BDU:2020-02558

почти 7 лет назад

Уязвимость модуля виртуальных таблиц FTS3 системы управления базами данных SQLite, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.1
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:1222-1

почти 7 лет назад

Security update for sqlite3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:0913-1

почти 7 лет назад

Security update for sqlite3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:0973-1

почти 7 лет назад

Security update for sqlite3

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2018-20506

SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.

CVSS3: 8.1
8%
Низкий
почти 7 лет назад
redhat логотип
CVE-2018-20506

SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.

CVSS3: 7
8%
Низкий
около 7 лет назад
nvd логотип
CVE-2018-20506

SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.

CVSS3: 8.1
8%
Низкий
почти 7 лет назад
msrc логотип
CVSS3: 8.1
8%
Низкий
больше 1 года назад
debian логотип
CVE-2018-20506

SQLite before 3.25.3, when the FTS3 extension is enabled, encounters a ...

CVSS3: 8.1
8%
Низкий
почти 7 лет назад
github логотип
GHSA-hfxx-8v8g-6rcx

SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.

CVSS3: 8.1
8%
Низкий
больше 3 лет назад
fstec логотип
BDU:2020-02558

Уязвимость модуля виртуальных таблиц FTS3 системы управления базами данных SQLite, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.1
8%
Низкий
почти 7 лет назад
suse-cvrf логотип
openSUSE-SU-2019:1222-1

Security update for sqlite3

почти 7 лет назад
suse-cvrf логотип
SUSE-SU-2019:0913-1

Security update for sqlite3

почти 7 лет назад
suse-cvrf логотип
SUSE-SU-2019:0973-1

Security update for sqlite3

почти 7 лет назад

Уязвимостей на страницу