Modified
Published: 24 Dec 2019, 15:53
Last modified:05 Aug 2024, 02:32

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.3 MEDIUM
v3.1 (nvd)
EPSS Score
6.3% LOW
6% probability +1.56%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

24 Dec 2019, 15:53
Published
Vulnerability first disclosed
05 Aug 2024, 02:32
Last Modified
Vulnerability information updated

Description

SQLite 3.30.1 mishandles certain parser-tree rewriting, related to expr.c, vdbeaux.c, and window.c. This is caused by incorrect sqlite3WindowRewrite() error handling.

CVSS Metrics

  • v3.1MEDIUMScore: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:P/A:N

EPSS Trends

Current EPSS score: 6.30% Percentile: 91%

Techniques & Countermeasures

  • CWE-755Improper Handling of Exceptional Conditions

    The product does not handle or incorrectly handles an exceptional condition.

Affected Systems

  • apachebookkeeper

    4.12.1

  • netappcloud_backup

    na

  • oraclemysql_workbench

    ≤ 8.0.19

  • siemenssinec_infrastructure_network_services

    < 1.0.1.1

  • sqlitesqlite

    3.30.1

References (7)