CVE-2019-16168

Modified
Published: 09 Sept 2019, 16:07
Last modified:28 May 2026, 18:37

Vulnerability Summary

Overall Risk (default)
medium
26/100
CVSS Score
6.5 MEDIUM
v3.1 (nvd)
EPSS Score
1.09% LOW
1% probability +0.24%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

09 Sept 2019, 16:07
Published
Vulnerability first disclosed
28 May 2026, 18:37
Last Modified
Vulnerability information updated

Description

In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner."

CVSS Metrics

  • v3.1MEDIUMScore: 6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 1.09% Percentile: 78%

Techniques & Countermeasures

  • CWE-369Divide By Zero

    The product divides a value by zero.

Affected Systems

  • canonicalubuntu_linux

    12.04 | 16.04 | 18.04 | 19.04 | 19.10

  • debiandebian_linux

    9.0

  • fedoraprojectfedora

    30

  • mcafeepolicy_auditor

    < 6.5.1

  • netappactive_iq_unified_manager

    ≥ 7.3 | ≥ 9.5

  • netappe-series_santricity_os_controller

    ≥ 11.0.0, ≤ 11.60.3

  • netapponcommand_insight

    na

  • netapponcommand_workflow_automation

    na

  • netappontap_select_deploy_administration_utility

    na

  • netappsantricity_unified_manager

    na

  • netappsteelstore_cloud_integrated_storage

    na

  • oraclecommunications_design_studio

    7.3.4.3.0 | 7.3.5.5.0 | 7.4.0.4.0

  • oraclejdk

    1.8.0:update231

  • oraclejre

    1.8.0:update231

  • oraclemysql

    ≥ 8.0.0, ≤ 8.0.18

  • oracleoutside_in_technology

    8.5.4

  • UnknownSolaris

    11

  • oraclezfs_storage_appliance

    8.8

  • sqlitesqlite

    ≥ 3.8.5, ≤ 3.29.0

  • tenablenessus_agent

    ≤ 8.2.3

References (17)