Search CVE reports


Toggle filters

1 – 10 of 90 results


CVE-2026-54620

Medium priority
Needs evaluation

sqlite3 provides Ruby bindings for the SQLite3 embedded database. From 2.1.0 to 2.9.4, the callbacks used for SQLite aggregate functions can be freed while still referenced during aggregation, resulting in a use-after-free. This...

1 affected package

ruby-sqlite3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-sqlite3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-54619

Medium priority
Needs evaluation

sqlite3 provides Ruby bindings for the SQLite3 embedded database. In version 2.9.4 and earlier, redefining a SQLite function with a different arity frees the previously registered function handler while SQLite may still reference...

1 affected package

ruby-sqlite3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-sqlite3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-50813

Medium priority

Some fixes available 3 of 12

An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path

2 affected packages

sqlite, sqlite3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
sqlite Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
sqlite3 Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2026-50812

Medium priority

Some fixes available 3 of 12

A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attacker who can supply a malformed changeset blob to cause a denial of service....

2 affected packages

sqlite, sqlite3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
sqlite Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
sqlite3 Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2026-11824

Medium priority

Some fixes available 4 of 12

SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with...

2 affected packages

sqlite, sqlite3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
sqlite Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
sqlite3 Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2026-11822

Medium priority

Some fixes available 4 of 12

SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database...

2 affected packages

sqlite, sqlite3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
sqlite Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
sqlite3 Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2025-70873

Medium priority
Not affected

An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.

2 affected packages

sqlite, sqlite3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
sqlite Not in release Not affected Not affected Not affected
sqlite3 Not affected Not affected Not affected Not affected
Show less packages

CVE-2025-52099

Medium priority
Fixed

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2025-29088. Reason: This record is a duplicate of CVE-2025-29088. Notes: All CVE users should reference CVE-2025-29088 instead of this record. All references...

2 affected packages

sqlite, sqlite3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
sqlite Not in release Not affected Not affected Not affected
sqlite3 Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-7709

Medium priority
Fixed

An integer overflow exists in the FTS5 https://sqlite.org/fts5.html  extension. It occurs when the size of an array of tombstone pointers is calculated and truncated into a 32-bit integer. A pointer to partially controlled data...

2 affected packages

sqlite, sqlite3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
sqlite Not in release Not affected Not affected Not affected
sqlite3 Fixed Not affected Not affected Not affected
Show less packages

CVE-2025-7458

Medium priority
Needs evaluation

An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive...

2 affected packages

sqlite, sqlite3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
sqlite Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
sqlite3 Not affected Not affected Not affected Not affected Not affected
Show less packages