Show filters
95 Total Results
Displaying 21-30 of 95
Sort by:
Attacker Value
Unknown

CVE-2021-23404

Disclosure Date: September 08, 2021 (last updated November 28, 2024)
This affects all versions of package sqlite-web. The SQL dashboard area allows sensitive actions to be performed without validating that the request originated from the application. This could enable an attacker to trick a user into performing these actions unknowingly through a Cross Site Request Forgery (CSRF) attack.
Attacker Value
Unknown

CVE-2021-36690

Disclosure Date: August 24, 2021 (last updated November 08, 2023)
A segmentation fault can occur in the sqlite3.exe command-line component of SQLite 3.36.0 via the idxGetTableInfo function when there is a crafted SQL query. NOTE: the vendor disputes the relevance of this report because a sqlite3.exe user already has full privileges (e.g., is intentionally allowed to execute commands). This report does NOT imply any problem in the SQLite library.
Attacker Value
Unknown

CVE-2021-20227

Disclosure Date: March 23, 2021 (last updated November 28, 2024)
A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code execution by triggering a use-after-free. The highest threat from this vulnerability is to system availability.
Attacker Value
Unknown

CVE-2020-35870

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via an Auxdata API use-after-free.
Attacker Value
Unknown

CVE-2020-35871

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via an Auxdata API data race.
Attacker Value
Unknown

CVE-2020-35872

Disclosure Date: December 31, 2020 (last updated November 28, 2024)
An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via the repr(Rust) type.
Attacker Value
Unknown

CVE-2020-35867

Disclosure Date: December 31, 2020 (last updated November 28, 2024)
An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via create_module.
Attacker Value
Unknown

CVE-2020-35868

Disclosure Date: December 31, 2020 (last updated November 28, 2024)
An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via UnlockNotification.
Attacker Value
Unknown

CVE-2020-35869

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated because rusqlite::trace::log mishandles format strings.
Attacker Value
Unknown

CVE-2020-35866

Disclosure Date: December 31, 2020 (last updated November 28, 2024)
An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via VTab / VTabCursor.