VYPR

rpm package

suse/sqlite3&distro=SUSE Linux Enterprise Server 15 SP2-LTSS

pkg:rpm/suse/sqlite3&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSS

Vulnerabilities (4)

  • CVE-2023-2137Apr 19, 2023
    affected < 3.44.0-150000.3.23.1fixed 3.44.0-150000.3.23.1

    Heap buffer overflow in sqlite in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2022-46908Dec 12, 2022
    affected < 3.39.3-150000.3.20.1fixed 3.39.3-150000.3.20.1

    SQLite through 3.40.0, when relying on --safe for execution of an untrusted CLI script, does not properly implement the azProhibitedFunctions protection mechanism, and instead allows UDF functions such as WRITEFILE.

  • CVE-2022-35737Aug 3, 2022
    affected < 3.39.3-150000.3.17.1fixed 3.39.3-150000.3.17.1

    SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.

  • CVE-2021-36690Aug 24, 2021
    affected < 3.39.3-150000.3.17.1fixed 3.39.3-150000.3.17.1

    A segmentation fault can occur in the sqlite3.exe command-line component of SQLite 3.36.0 via the idxGetTableInfo function when there is a crafted SQL query. NOTE: the vendor disputes the relevance of this report because a sqlite3.exe user already has full privileges (e.g., is in