« List of all CVEs

CVE-2019-5018

Published: 5/10/2019 Last updated: 8/4/2024 Reserved: 1/4/2019

An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0. A specially crafted SQL command can cause a use after free vulnerability, potentially resulting in remote code execution. An attacker can send a malicious SQL command to trigger this vulnerability.

CNA assigner: talos (b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b) Requested by: n/a

Metrics

Version Score Severity Vector String
3.0 8.1 High CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Opam packages affected (4)

conf-mingw-w64-sqlite3-i686 conf-mingw-w64-sqlite3-x86_64 conf-sqlite3 lemonade-sqlite

Products affected (1)

Product Vendor Version
Sqlite3 n/a < 10.0.10240.20890

References (12)