10
CVSSv2

CVE-2015-5895

Published: 18/09/2015 Updated: 22/12/2016
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple unspecified vulnerabilities in SQLite prior to 3.8.10.2, as used in Apple iOS prior to 9, have unknown impact and attack vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

sqlite sqlite

Vendor Advisories

Tenable Nessus and Nessus Enterprise are affected by two recently patched vulnerabilities in SQLite: SQLite resolve_backslashes() Function \ Command Handling Off-by-one Remote Heap Buffer Overflow: SQLite contains an off-by-one overflow condition in the resolve_backslashes() function The issue is triggered as user-supplied input is not properly ...

Exploits

# Exploit Title: SQLite3 controlled memory corruption PoC (0day) # Date: [date] # Exploit Author: Andras Kabai # Vendor Homepage: wwwsqliteorg/ # Software Link: wwwsqliteorg/downloadhtml # Version: 386, 3883 # Tested on: Ubuntu 1410, 64 bit 386 (latest available package), 3883 (built from the latest source code) Using ...