Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

nvd логотип

CVE-2025-71316

3 месяца назад

SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Windows C runtime converts Unicode characters to ANSI codepages. An attacker could use the '-L' option to load an arbitrary DLL with a crafted command line argument string that results in command line file arguments being misinterpreted as command line options. Fixed on or around 2025-12-26.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2025-71316

3 месяца назад

SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Wi ...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-gxv8-whj6-g59f

3 месяца назад

SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Windows C runtime converts Unicode characters to ANSI codepages. An attacker could use the '-L' option to load an arbitrary DLL with a crafted command line argument string that results in command line file arguments being misinterpreted as command line options. Fixed on or around 2025-12-26.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-71316

SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Windows C runtime converts Unicode characters to ANSI codepages. An attacker could use the '-L' option to load an arbitrary DLL with a crafted command line argument string that results in command line file arguments being misinterpreted as command line options. Fixed on or around 2025-12-26.

CVSS3: 9.8
0%
Низкий
3 месяца назад
debian логотип
CVE-2025-71316

SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Wi ...

CVSS3: 9.8
0%
Низкий
3 месяца назад
github логотип
GHSA-gxv8-whj6-g59f

SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Windows C runtime converts Unicode characters to ANSI codepages. An attacker could use the '-L' option to load an arbitrary DLL with a crafted command line argument string that results in command line file arguments being misinterpreted as command line options. Fixed on or around 2025-12-26.

CVSS3: 9.8
0%
Низкий
3 месяца назад

Уязвимостей на страницу