Search CVE reports


Toggle filters

1 – 3 of 3 results


CVE-2021-3119

Medium priority
Not affected

Zetetic SQLCipher 4.x before 4.4.3 has a NULL pointer dereferencing issue related to sqlcipher_export in crypto.c and sqlite3StrICmp in sqlite3.c. This may allow an attacker to perform a remote denial of service attack. For...

1 affected package

sqlcipher

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
sqlcipher Not affected Not affected
Show less packages

CVE-2020-27207

Medium priority
Needs evaluation

Zetetic SQLCipher 4.x before 4.4.1 has a use-after-free, related to sqlcipher_codec_pragma and sqlite3Strlen30 in sqlite3.c. A remote denial of service attack can be performed. For example, a SQL injection can be used to execute...

1 affected package

sqlcipher

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
sqlcipher Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2019-8457

Medium priority

Some fixes available 34 of 65

SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tables.

5 affected packages

sqlite3, db5.3, chromium, qtwebengine-opensource-src, sqlcipher

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
sqlite3 Fixed Fixed Fixed Fixed
db5.3 Fixed Fixed Fixed Fixed
chromium Not in release Not in release Not in release Not in release
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Needs evaluation
sqlcipher Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages