CVE-2025-6965
high · 7.2There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.
7.2
CVSS
72.5%
EPSS (exploit prob.)
99th
EPSS percentile
2025-07-15
Published
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:D/RE:L/U:Green
Weaknesses
CWE-197
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| sqlite | sqlite | < 3.50.2 |
| apple | ipados | < 26.0.0 |
| apple | iphone_os | < 26.0.0 |
| apple | macos | < 26.0.0 |
| apple | tvos | < 26.0.0 |
| apple | visionos | < 26.0.0 |
| apple | watchos | < 26.0.0 |
| siemens | ruggedcom_crossbow | < 5.8 |
| siemens | sidis_prime | < 4.0.800 |
Check a specific version with /api/v1/cve/match.
References
- https://www.sqlite.org/src/info/5508b56fd24016c13981ec280ecdd833007c9d8dd595edb295b984c2b487b5c8
- http://seclists.org/fulldisclosure/2025/Sep/49
- http://seclists.org/fulldisclosure/2025/Sep/53
- http://seclists.org/fulldisclosure/2025/Sep/56
- http://seclists.org/fulldisclosure/2025/Sep/57
- http://seclists.org/fulldisclosure/2025/Sep/58
- http://www.openwall.com/lists/oss-security/2025/09/06/1
- https://cert-portal.siemens.com/productcert/html/ssa-225816.html
- https://cert-portal.siemens.com/productcert/html/ssa-485750.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-6965