High severity8.1NVD Advisory· Published May 10, 2019· Updated Jun 17, 2026
CVE-2019-5018
CVE-2019-5018
Description
An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0. A specially crafted SQL command can cause a use after free vulnerability, potentially resulting in remote code execution. An attacker can send a malicious SQL command to trigger this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8- Sqlite3/Sqlite3description
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*+ 4 more
- cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
6- talosintelligence.com/vulnerability_reports/TALOS-2019-0777nvdExploitThird Party Advisory
- packetstormsecurity.com/files/152809/Sqlite3-Window-Function-Remote-Code-Execution.htmlnvdThird Party AdvisoryVDB Entry
- security.gentoo.org/glsa/201908-09nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20190521-0001/nvdThird Party Advisory
- usn.ubuntu.com/4205-1/nvdThird Party Advisory
- www.securityfocus.com/bid/108294nvdBroken Link
News mentions
0No linked articles in our index yet.