Debian Sqlite3 vulnerabilities
59 known vulnerabilities affecting debian/sqlite3.
Total CVEs
59
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH24MEDIUM16LOW12
Vulnerabilities
Page 1 of 3
CVE-2025-6965P2HIGHCVSS 7.2PoCfixed in sqlite3 3.40.1-2+deb12u2 (bookworm)2025
CVE-2025-6965 [HIGH] CVE-2025-6965: sqlite3 - There exists a vulnerability in SQLite versions before 3.50.2 where the number o...
There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.
Scope: local
bookworm: resolved (fixed in 3.40.1-2+deb12u2)
bullseye: open
forky: resolved (fixed in 3.46.1-7)
sid: resolved (fix
debian
CVE-2019-8457P3CRITICALCVSS 9.8fixed in db5.3 5.3.28+dfsg1-0.9 (bookworm)2019
CVE-2019-8457 [CRITICAL] CVE-2019-8457: db5.3 - SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound re...
SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tables.
Scope: local
bookworm: resolved (fixed in 5.3.28+dfsg1-0.9)
bullseye: open
forky: resolved (fixed in 5.3.28+dfsg1-0.9)
sid: resolved (fixed in 5.3.28+dfsg1-0.9)
trixie: resolved (fixed in 5.3.28+dfsg1-0.9)
debian
CVE-2018-20346P3HIGHCVSS 8.1fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-20346 [HIGH] CVE-2018-20346: chromium - SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer ...
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases), aka Magellan.
Scope: loc
debian
CVE-2018-20506P3HIGHCVSS 8.1fixed in sqlite3 3.25.3-1 (bookworm)2018
CVE-2018-20506 [HIGH] CVE-2018-20506: sqlite3 - SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer ...
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). T
debian
CVE-2025-3277P3LOWCVSS 6.9fixed in sqlite3 3.46.1-3 (forky)2025
CVE-2025-3277 [MEDIUM] CVE-2025-3277: sqlite3 - An integer overflow can be triggered in SQLite’s `concat_ws()` function. The res...
An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated size and thus a wild Heap Buffer overflow of size ~4GB can be triggered. This can result in arbitrary code execution.
Scope: local
bo
debian
CVE-2019-5018P3HIGHCVSS 8.1fixed in sqlite3 3.27.2-3 (bookworm)2019
CVE-2019-5018 [HIGH] CVE-2019-5018: sqlite3 - An exploitable use after free vulnerability exists in the window function functi...
An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0. A specially crafted SQL command can cause a use after free vulnerability, potentially resulting in remote code execution. An attacker can send a malicious SQL command to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 3.27.2-3)
bullseye: res
debian
CVE-2022-35737P3LOWCVSS 7.5fixed in sqlite3 3.39.2-1 (bookworm)2022
CVE-2022-35737 [HIGH] CVE-2022-35737: sqlite3 - SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds over...
SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.
Scope: local
bookworm: resolved (fixed in 3.39.2-1)
bullseye: open
forky: resolved (fixed in 3.39.2-1)
sid: resolved (fixed in 3.39.2-1)
trixie: resolved (fixed in 3.39.2-1)
debian
CVE-2017-2518P3CRITICALCVSS 9.8fixed in sqlite3 3.15.2-1 (bookworm)2017
CVE-2017-2518 [CRITICAL] CVE-2017-2518: sqlite3 - An issue was discovered in certain Apple products. iOS before 10.3.2 is affected...
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a crafted SQL s
debian
CVE-2017-2520P3CRITICALCVSS 9.8fixed in sqlite3 3.16.2-1 (bookworm)2017
CVE-2017-2520 [CRITICAL] CVE-2017-2520: sqlite3 - An issue was discovered in certain Apple products. iOS before 10.3.2 is affected...
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a crafted SQL s
debian
CVE-2017-2519P3CRITICALCVSS 9.8fixed in sqlite3 3.16.0-1 (bookworm)2017
CVE-2017-2519 [CRITICAL] CVE-2017-2519: sqlite3 - An issue was discovered in certain Apple products. iOS before 10.3.2 is affected...
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted SQL
debian
CVE-2020-11656P3LOWCVSS 9.8fixed in sqlite3 3.32.0-1 (bookworm)2020
CVE-2020-11656 [CRITICAL] CVE-2020-11656: sqlite3 - In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, a...
In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELECT statement.
Scope: local
bookworm: resolved (fixed in 3.32.0-1)
bullseye: resolved (fixed in 3.32.0-1)
forky: resolved (fixed in 3.32.0-1)
sid: resolved (fixed in 3.32.0-1)
trixie: resolved (fixed in 3.32.0-1)
debian
CVE-2025-7458P3MEDIUMCVSS 6.9fixed in sqlite3 3.42.0-1 (forky)2025
CVE-2025-7458 [MEDIUM] CVE-2025-7458: sqlite3 - An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite version...
An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT statement with a large number of expressions in the ORDER BY clause.
Scope: local
bookwo
debian
CVE-2017-10989P3CRITICALCVSS 9.8fixed in sqlite3 3.19.3-3 (bookworm)2017
CVE-2017-10989 [CRITICAL] CVE-2017-10989: sqlite3 - The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used ...
The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used in GDAL and other products, mishandles undersized RTree blobs in a crafted database, leading to a heap-based buffer over-read or possibly unspecified other impact.
Scope: local
bookworm: resolved (fixed in 3.19.3-3)
bullseye: resolved (fixed in 3.19.3-3)
forky: resolved (fixed in 3.1
debian
CVE-2023-7104P3MEDIUMCVSS 5.5fixed in sqlite3 3.40.1-2+deb12u1 (bookworm)2023
CVE-2023-7104 [MEDIUM] CVE-2023-7104: sqlite3 - A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as criti...
A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The manipulation leads to heap-based buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerabili
debian
CVE-2021-36690P3LOWCVSS 7.5fixed in sqlite3 3.36.0-2 (bookworm)2021
CVE-2021-36690 [HIGH] CVE-2021-36690: sqlite3 - A segmentation fault can occur in the sqlite3.exe command-line component of SQLi...
A segmentation fault can occur in the sqlite3.exe command-line component of SQLite 3.36.0 via the idxGetTableInfo function when there is a crafted SQL query. NOTE: the vendor disputes the relevance of this report because a sqlite3.exe user already has full privileges (e.g., is intentionally allowed to execute commands). This report does NOT imply any problem in the
debian
CVE-2017-2513P3CRITICALCVSS 9.8fixed in sqlite3 3.15.2-1 (bookworm)2017
CVE-2017-2513 [CRITICAL] CVE-2017-2513: sqlite3 - An issue was discovered in certain Apple products. iOS before 10.3.2 is affected...
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "SQLite" component. A use-after-free vulnerability allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a craft
debian
CVE-2020-35527P3CRITICALCVSS 9.8fixed in sqlite3 3.32.0-1 (bookworm)2020
CVE-2020-35527 [CRITICAL] CVE-2020-35527: sqlite3 - In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE f...
In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE for views that have a nested FROM clause.
Scope: local
bookworm: resolved (fixed in 3.32.0-1)
bullseye: resolved (fixed in 3.32.0-1)
forky: resolved (fixed in 3.32.0-1)
sid: resolved (fixed in 3.32.0-1)
trixie: resolved (fixed in 3.32.0-1)
debian
CVE-2019-5827P3HIGHCVSS 8.8fixed in chromium 75.0.3770.80-1 (bookworm)2019
CVE-2019-5827 [HIGH] CVE-2019-5827: chromium - Integer overflow in SQLite via WebSQL in Google Chrome prior to 74.0.3729.131 al...
Integer overflow in SQLite via WebSQL in Google Chrome prior to 74.0.3729.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 75.0.3770.80-1)
bullseye: resolved (fixed in 75.0.3770.80-1)
forky: resolved (fixed in 75.0.3770.80-1)
sid: resolved (fixed in 75.0.3770.80-1)
trixie: resolved
debian
CVE-2019-9936P3LOWCVSS 7.5fixed in sqlite3 3.27.2-2 (bookworm)2019
CVE-2019-9936 [HIGH] CVE-2019-9936: sqlite3 - In SQLite 3.27.2, running fts5 prefix queries inside a transaction could trigger...
In SQLite 3.27.2, running fts5 prefix queries inside a transaction could trigger a heap-based buffer over-read in fts5HashEntrySort in sqlite3.c, which may lead to an information leak. This is related to ext/fts5/fts5_hash.c.
Scope: local
bookworm: resolved (fixed in 3.27.2-2)
bullseye: resolved (fixed in 3.27.2-2)
forky: resolved (fixed in 3.27.2-2)
sid: resolved (fi
debian
CVE-2018-20505P3HIGHCVSS 7.5fixed in sqlite3 3.25.3-1 (bookworm)2018
CVE-2018-20505 [HIGH] CVE-2018-20505: sqlite3 - SQLite 3.25.2, when queries are run on a table with a malformed PRIMARY KEY, all...
SQLite 3.25.2, when queries are run on a table with a malformed PRIMARY KEY, allows remote attackers to cause a denial of service (application crash) by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases).
Scope: local
bookworm: resolved (fixed in 3.25.3-1)
bullseye: resolved (fixed in 3.25.3-1)
forky: resolved (fixed in 3.25
debian
1 / 3Next →