CVE-2020-11655

Modified
Published: 09 Apr 2020, 02:49
Last modified:04 Aug 2024, 11:35

Vulnerability Summary

Overall Risk (default)
medium
41/100
CVSS Score
7.5 HIGH
v3.1 (nvd)
EPSS Score
5.02% LOW
5% probability +0.13%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

09 Apr 2020, 02:49
Published
Vulnerability first disclosed
04 Aug 2024, 11:35
Last Modified
Vulnerability information updated

Description

SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query because the AggInfo object's initialization is mishandled.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 5.02% Percentile: 90%

Techniques & Countermeasures

  • CWE-665Improper Initialization

    The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.

Affected Systems

  • canonicalubuntu_linux

    16.04 | 18.04 | 19.10 | 20.04

  • debiandebian_linux

    8.0 | 9.0

  • netappontap_select_deploy_administration_utility

    na

  • oraclecommunications_element_manager

    ≥ 8.2.0, ≤ 8.2.2

  • oraclecommunications_messaging_server

    8.1

  • oraclecommunications_network_charging_and_control

    ≥ 12.0.0, ≤ 12.0.3 | 6.0.1 | 12.0.2

  • oraclecommunications_session_report_manager

    ≥ 8.2.0, ≤ 8.2.2

  • oraclecommunications_session_route_manager

    ≥ 8.2.0, ≤ 8.2.2

  • oracleenterprise_manager_ops_center

    12.4.0.0

  • oraclehyperion_infrastructure_technology

    11.1.2.4

  • oracleinstantis_enterprisetrack

    17.1 | 17.2 | 17.3

  • oraclemysql

    ≥ 8.0.0, ≤ 8.0.22

  • oraclemysql_workbench

    ≤ 8.0.22

  • oracleoutside_in_technology

    8.5.4 | 8.5.5

  • oraclezfs_storage_appliance_kit

    8.8

  • siemenssinec_infrastructure_network_services

    < 1.0.1.1

  • sqlitesqlite

    ≤ 3.31.1

  • tenabletenable.sc

    < 5.19.0

References (14)