Debian Sqlite3 vulnerabilities
59 known vulnerabilities affecting debian/sqlite3.
Total CVEs
59
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH24MEDIUM16LOW12
Vulnerabilities
Page 3 of 3
CVE-2015-3414P4HIGHCVSS 7.5fixed in sqlite3 3.8.9-1 (bookworm)2015
CVE-2015-3414 [HIGH] CVE-2015-3414: sqlite3 - SQLite before 3.8.9 does not properly implement the dequoting of collation-seque...
SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which allows context-dependent attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via a crafted COLLATE clause, as demonstrated by COLLATE"""""""" at the end of a SELECT statement.
Scope: local
boo
debian
CVE-2019-19924P4MEDIUMCVSS 5.3fixed in sqlite3 3.30.1+fossil191229-1 (bookworm)2019
CVE-2019-19924 [MEDIUM] CVE-2019-19924: sqlite3 - SQLite 3.30.1 mishandles certain parser-tree rewriting, related to expr.c, vdbea...
SQLite 3.30.1 mishandles certain parser-tree rewriting, related to expr.c, vdbeaux.c, and window.c. This is caused by incorrect sqlite3WindowRewrite() error handling.
Scope: local
bookworm: resolved (fixed in 3.30.1+fossil191229-1)
bullseye: resolved (fixed in 3.30.1+fossil191229-1)
forky: resolved (fixed in 3.30.1+fossil191229-1)
sid: resolved (fixed in 3.30.1+fo
debian
CVE-2019-16168P4MEDIUMCVSS 6.5fixed in sqlite3 3.29.0-2 (bookworm)2019
CVE-2019-16168 [MEDIUM] CVE-2019-16168: sqlite3 - In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browse...
In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner."
Scope: local
bookworm: resolved (fixed in 3.29.0-2)
bullseye: resolved (fixed in 3.29.0-2)
forky: resolved (fixed in 3.29.0-2)
sid: resolved (fixed in
debian
CVE-2025-7709P4MEDIUMCVSS 6.9fixed in sqlite3 3.46.1-8 (forky)2025
CVE-2025-7709 [MEDIUM] CVE-2025-7709: sqlite3 - An integer overflow exists in the FTS5 https://sqlite.org/fts5.html extension....
An integer overflow exists in the FTS5 https://sqlite.org/fts5.html extension. It occurs when the size of an array of tombstone pointers is calculated and truncated into a 32-bit integer. A pointer to partially controlled data can then be written out of bounds.
Scope: local
bookworm: open
bullseye: resolved
forky: resolved (fixed in 3.46.1-8)
sid: resolved (fixed in
debian
CVE-2020-13630P4HIGHCVSS 7.0fixed in sqlite3 3.32.0-1 (bookworm)2020
CVE-2020-13630 [HIGH] CVE-2020-13630: sqlite3 - ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow,...
ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.
Scope: local
bookworm: resolved (fixed in 3.32.0-1)
bullseye: resolved (fixed in 3.32.0-1)
forky: resolved (fixed in 3.32.0-1)
sid: resolved (fixed in 3.32.0-1)
trixie: resolved (fixed in 3.32.0-1)
debian
CVE-2019-19242P4MEDIUMCVSS 5.9fixed in sqlite3 3.30.1+fossil191229-1 (bookworm)2019
CVE-2019-19242 [MEDIUM] CVE-2019-19242: sqlite3 - SQLite 3.30.1 mishandles pExpr->y.pTab, as demonstrated by the TK_COLUMN case in...
SQLite 3.30.1 mishandles pExpr->y.pTab, as demonstrated by the TK_COLUMN case in sqlite3ExprCodeTarget in expr.c.
Scope: local
bookworm: resolved (fixed in 3.30.1+fossil191229-1)
bullseye: resolved (fixed in 3.30.1+fossil191229-1)
forky: resolved (fixed in 3.30.1+fossil191229-1)
sid: resolved (fixed in 3.30.1+fossil191229-1)
trixie: resolved (fixed in 3.30.1+fossi
debian
CVE-2013-7443P4MEDIUMCVSS 5.0fixed in sqlite3 3.8.3-1 (bookworm)2013
CVE-2013-7443 [MEDIUM] CVE-2013-7443: sqlite3 - Buffer overflow in the skip-scan optimization in SQLite 3.8.2 allows remote atta...
Buffer overflow in the skip-scan optimization in SQLite 3.8.2 allows remote attackers to cause a denial of service (crash) via crafted SQL statements.
Scope: local
bookworm: resolved (fixed in 3.8.3-1)
bullseye: resolved (fixed in 3.8.3-1)
forky: resolved (fixed in 3.8.3-1)
sid: resolved (fixed in 3.8.3-1)
trixie: resolved (fixed in 3.8.3-1)
debian
CVE-2021-20227P4MEDIUMCVSS 5.5fixed in sqlite3 3.34.1-1 (bookworm)2021
CVE-2021-20227 [MEDIUM] CVE-2021-20227: sqlite3 - A flaw was found in SQLite's SELECT query functionality (src/select.c). This fla...
A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code execution by triggering a use-after-free. The highest threat from this vulnerability is to system availability.
Scope: local
bookworm: resolved (fixed
debian
CVE-2020-13631P4MEDIUMCVSS 5.5fixed in sqlite3 3.32.0-1 (bookworm)2020
CVE-2020-13631 [MEDIUM] CVE-2020-13631: sqlite3 - SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of ...
SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c.
Scope: local
bookworm: resolved (fixed in 3.32.0-1)
bullseye: resolved (fixed in 3.32.0-1)
forky: resolved (fixed in 3.32.0-1)
sid: resolved (fixed in 3.32.0-1)
trixie: resolved (fixed in 3.32.0-1)
debian
CVE-2020-15358P4MEDIUMCVSS 5.5fixed in sqlite3 3.32.3-1 (bookworm)2020
CVE-2020-15358 [MEDIUM] CVE-2020-15358: sqlite3 - In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leadi...
In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.
Scope: local
bookworm: resolved (fixed in 3.32.3-1)
bullseye: resolved (fixed in 3.32.3-1)
forky: resolved (fixed in 3.32.3-1)
sid: resolved (fixed in 3.32.3-1)
trixie: resolve
debian
CVE-2020-13434P4MEDIUMCVSS 5.5fixed in sqlite3 3.32.1-1 (bookworm)2020
CVE-2020-13434 [MEDIUM] CVE-2020-13434: sqlite3 - SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf....
SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.
Scope: local
bookworm: resolved (fixed in 3.32.1-1)
bullseye: resolved (fixed in 3.32.1-1)
forky: resolved (fixed in 3.32.1-1)
sid: resolved (fixed in 3.32.1-1)
trixie: resolved (fixed in 3.32.1-1)
debian
CVE-2016-6153P4MEDIUMCVSS 5.9fixed in sqlite3 3.13.0-1 (bookworm)2016
CVE-2016-6153 [MEDIUM] CVE-2016-6153: sqlite3 - os_unix.c in SQLite before 3.13.0 improperly implements the temporary directory ...
os_unix.c in SQLite before 3.13.0 improperly implements the temporary directory search algorithm, which might allow local users to obtain sensitive information, cause a denial of service (application crash), or have unspecified other impact by leveraging use of the current working directory for temporary files.
Scope: local
bookworm: resolved (fixed in 3.13.0-1)
bul
debian
CVE-2020-13435P4MEDIUMCVSS 5.5fixed in sqlite3 3.32.1-1 (bookworm)2020
CVE-2020-13435 [MEDIUM] CVE-2020-13435: sqlite3 - SQLite through 3.32.0 has a segmentation fault in sqlite3ExprCodeTarget in expr....
SQLite through 3.32.0 has a segmentation fault in sqlite3ExprCodeTarget in expr.c.
Scope: local
bookworm: resolved (fixed in 3.32.1-1)
bullseye: resolved (fixed in 3.32.1-1)
forky: resolved (fixed in 3.32.1-1)
sid: resolved (fixed in 3.32.1-1)
trixie: resolved (fixed in 3.32.1-1)
debian
CVE-2020-13632P4MEDIUMCVSS 5.5fixed in sqlite3 3.32.0-1 (bookworm)2020
CVE-2020-13632 [MEDIUM] CVE-2020-13632: sqlite3 - ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference v...
ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query.
Scope: local
bookworm: resolved (fixed in 3.32.0-1)
bullseye: resolved (fixed in 3.32.0-1)
forky: resolved (fixed in 3.32.0-1)
sid: resolved (fixed in 3.32.0-1)
trixie: resolved (fixed in 3.32.0-1)
debian
CVE-2019-19645P4MEDIUMCVSS 5.5fixed in sqlite3 3.30.1+fossil191229-1 (bookworm)2019
CVE-2019-19645 [MEDIUM] CVE-2019-19645: sqlite3 - alter.c in SQLite through 3.30.1 allows attackers to trigger infinite recursion ...
alter.c in SQLite through 3.30.1 allows attackers to trigger infinite recursion via certain types of self-referential views in conjunction with ALTER TABLE statements.
Scope: local
bookworm: resolved (fixed in 3.30.1+fossil191229-1)
bullseye: resolved (fixed in 3.30.1+fossil191229-1)
forky: resolved (fixed in 3.30.1+fossil191229-1)
sid: resolved (fixed in 3.30.1+f
debian
CVE-2024-0232P4LOWCVSS 4.7fixed in sqlite3 3.43.2-1 (forky)2024
CVE-2024-0232 [MEDIUM] CVE-2024-0232: sqlite3 - A heap use-after-free issue has been identified in SQLite in the jsonParseAddNod...
A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed i
debian
CVE-2017-13685P4LOWCVSS 5.5fixed in sqlite3 3.20.1-1 (bookworm)2017
CVE-2017-13685 [MEDIUM] CVE-2017-13685: sqlite3 - The dump_callback function in SQLite 3.20.0 allows remote attackers to cause a d...
The dump_callback function in SQLite 3.20.0 allows remote attackers to cause a denial of service (EXC_BAD_ACCESS and application crash) via a crafted file.
Scope: local
bookworm: resolved (fixed in 3.20.1-1)
bullseye: resolved (fixed in 3.20.1-1)
forky: resolved (fixed in 3.20.1-1)
sid: resolved (fixed in 3.20.1-1)
trixie: resolved (fixed in 3.20.1-1)
debian
CVE-2025-29088P4LOWCVSS 5.6fixed in sqlite3 3.46.1-4 (forky)2025
CVE-2025-29088 [MEDIUM] CVE-2025-29088: sqlite3 - In SQLite 3.49.0 before 3.49.1, certain argument values to sqlite3_db_config (in...
In SQLite 3.49.0 before 3.49.1, certain argument values to sqlite3_db_config (in the C-language API) can cause a denial of service (application crash). An sz*nBig multiplication is not cast to a 64-bit integer, and consequently some memory allocations may be incorrect.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 3.46.1-4)
sid: resolved (fi
debian
CVE-2020-24736P4MEDIUMCVSS 5.5fixed in sqlite3 3.27.2-1 (bookworm)2020
CVE-2020-24736 [MEDIUM] CVE-2020-24736: sqlite3 - Buffer Overflow vulnerability found in SQLite3 v.3.27.1 and before allows a loca...
Buffer Overflow vulnerability found in SQLite3 v.3.27.1 and before allows a local attacker to cause a denial of service via a crafted script.
Scope: local
bookworm: resolved (fixed in 3.27.2-1)
bullseye: resolved (fixed in 3.27.2-1)
forky: resolved (fixed in 3.27.2-1)
sid: resolved (fixed in 3.27.2-1)
trixie: resolved (fixed in 3.27.2-1)
debian
← Previous3 / 3