Show filters
95 Total Results
Displaying 61-70 of 95
Sort by:
Attacker Value
Unknown

CVE-2019-9936

Disclosure Date: March 22, 2019 (last updated November 08, 2023)
In SQLite 3.27.2, running fts5 prefix queries inside a transaction could trigger a heap-based buffer over-read in fts5HashEntrySort in sqlite3.c, which may lead to an information leak. This is related to ext/fts5/fts5_hash.c.
0
Attacker Value
Unknown

CVE-2019-9083

Disclosure Date: March 21, 2019 (last updated November 27, 2024)
SQLiteManager 1.20 and 1.24 allows SQL injection via the /sqlitemanager/main.php dbsel parameter. NOTE: This product is discontinued.
0
Attacker Value
Unknown

CVE-2019-19959

Disclosure Date: February 28, 2019 (last updated February 21, 2025)
ext/misc/zipfile.c in SQLite 3.30.1 mishandles certain uses of INSERT INTO in situations involving embedded '\0' characters in filenames, leading to a memory-management error that can be detected by (for example) valgrind.
Attacker Value
Unknown

CVE-2018-20346

Disclosure Date: December 21, 2018 (last updated November 08, 2023)
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases), aka Magellan.
0
Attacker Value
Unknown

CVE-2017-16050

Disclosure Date: June 04, 2018 (last updated November 26, 2024)
`sqlite.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
0
Attacker Value
Unknown

CVE-2017-16051

Disclosure Date: June 04, 2018 (last updated November 26, 2024)
`sqliter` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
0
Attacker Value
Unknown

CVE-2017-16049

Disclosure Date: June 04, 2018 (last updated November 26, 2024)
`nodesqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
0
Attacker Value
Unknown

CVE-2017-16048

Disclosure Date: June 04, 2018 (last updated November 26, 2024)
`node-sqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
0
Attacker Value
Unknown

CVE-2016-10695

Disclosure Date: June 04, 2018 (last updated November 26, 2024)
The npm-test-sqlite3-trunk module provides asynchronous, non-blocking SQLite3 bindings. npm-test-sqlite3-trunk downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote server.
0
Attacker Value
Unknown

CVE-2018-8740

Disclosure Date: March 17, 2018 (last updated November 08, 2023)
In SQLite through 3.22.0, databases whose schema is corrupted using a CREATE TABLE AS statement could cause a NULL pointer dereference, related to build.c and prepare.c.
0