7.5
CVSSv3

CVE-2021-36690

Published: 24/08/2021 Updated: 11/04/2024
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

A segmentation fault can occur in the sqlite3.exe command-line component of SQLite 3.36.0 via the idxGetTableInfo function when there is a crafted SQL query. NOTE: the vendor disputes the relevance of this report because a sqlite3.exe user already has full privileges (e.g., is intentionally allowed to execute commands). This report does NOT imply any problem in the SQLite library.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sqlite sqlite 3.36.0

oracle zfs storage appliance kit 8.8

apple iphone os

apple macos

apple watchos

apple tvos

Vendor Advisories

There is a segmentation fault vulnerability in SQLite 3360 via the idxGetTableInfo function, in which a crafted SQL query can cause a denial of service ...