CVE-2018-20346 PUBLISHED CVSS 8.100000381469727 HIGH

SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer over-flow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases), aka Magellan.

EPSS 13.21% · 94.1th percentile

Risk Scores

CVSS v3.0
8.100000381469727
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
13.21%
94.1th percentile

Affected Products

VendorProductVersions
ABBB&R Industrial Automation GmbH Automation Studio <6.5
ABBABB Ability Camera Connect <=2.0.0.42
ABBABB B&R Automation Studio <6.5

Timeline

References

Open in Interactive Console →