ZeroHour

CVE-2021-20227

CVSS 3.1
5.5 medium
EPSS
<1%p41
Published
()
Modified
Description

A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code execution by triggering a use-after-free. The highest threat from this vulnerability is to system availability.

Vendors
sqliteoracle
Products
sqlite, communications network charging and control, enterprise manager for oracle database, jd edwards enterpriseone tools, mysql workbench, outside in technology, zfs storage appliance kit
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.