SQLite Bug Forum

Forum
Login

Most recent threads

9.6 hours ago FTS3 `fts3ReadEndBlockField()` negates INT64_MIN text and triggers signed integer overflowno repliesOpen
9.6 hours ago FTS3 `fts3EvalNearTrim()` can overflow the position-list buffer during an in-place NEAR mergeno repliesOpen
10.5 hours ago WAL read-only `readonly_shm` path accepts page-size 0 and over-reads in `walChecksumBytes()`no repliesOpen
1.6 days ago Vuln53-34: FTS5 fts5IndexTombstoneRebuild Signed Integer Overflow on Corrupt Tombstone nElem Field2 posts spanning 13.3 hoursResolved
1.9 days ago Vuln56-37: fileio realpath() Missing OOM Check on mprintf Result Causes strlen(NULL) Crash2 posts spanning 2.9 hoursResolved
1.9 days ago Vuln54-35: RBU rbu_fossil_delta Signed Integer Overflow on Crafted Delta Output Size2 posts spanning 3.9 hoursResolved
2.0 days ago Vuln55-36: fossildelta delta_create Missing OOM Check Causes NULL Dereference2 posts spanning 2.9 hoursResolved
2.0 days ago Out-of-bounds read in deltaGetInt() when input contains no in-buffer terminator (ext/misc/fossildelta.c)4 posts spanning 2.8 hoursResolved
2.7 days ago Vuln52-33: replace() Bounds-Check Assert Signed Integer Overflow on Large Strings Under Raised SQLITE_MAX_LENGTH3 posts spanning 7.2 hoursResolved
2.8 days ago SQLite3 Non-deterministic Function Bypass in CREATE INDEX Expression Validation5 posts spanning 2.1 daysResolved
2.9 days ago Vuln51-32: FTS5 in-Memory Hash Signed Integer Overflow on Doclist Doubling Reachable Under Raised SQLITE_MAX_LENGTH2 posts spanning 5.3 hoursResolved
3.6 days ago Vuln50-31: FTS5 integrity-check Heap Buffer Over-Read in fts5IndexIntegrityCheckSegment2 posts spanning 1.8 hoursResolved
3.7 days ago Vuln49-30: FTS5 Reverse Iterator Heap Buffer Over-Read via Unvalidated szLeaf on Corrupt Segment Leaf4 posts spanning 4.3 hoursResolved
3.8 days ago Vuln48-29: FTS5 NEAR Query Heap Use-After-Free via In-Place Poslist Rewrite Realloc2 posts spanning 4.9 hoursResolved
3.9 days ago Vuln47-28: FTS5 snippet() Signed Integer Overflow on Attacker-Controlled nToken Argument2 posts spanning 2.9 hoursResolved
6.8 days ago SELECT DISTINCT ORDER BY returns different row order depending on index usage2 posts spanning 14.7 minutesResolved
7.7 days ago Vuln46-27: WhereTerm.nChild u8 Wraparound Skips Verification of Vector IN Components Past Index Width2 posts spanning 7.0 hoursResolved
7.9 days ago Vuln45-26: pcache1InitBulk do-while Loop Heap Buffer Overflow When -pagecache N=-1 Produces nBulk=02 posts spanning 5.1 hoursResolved
7.9 days ago SQLite uuid_str()/uuid_blob() TEXT Conversion OOM NULL Dereference DoS2 posts spanning 1.9 hoursResolved
7.9 days ago Vuln44-25: Vector IN Step-6 Ignores aiMap Permutation When the Engine Uses an Index With Reordered Columns2 posts spanning 4.8 hoursResolved
7.9 days ago wholenumberFilter() INT64 Bound Signed Overflow DoS2 posts spanning 1.7 hoursResolved
8.1 days ago .import CSV files: treatment of scientific notation has changed3 posts spanning 1.6 hoursResolved
8.5 days ago Vuln36-17: ICU LIKE Overlong UTF-8 Sequences Decode to Real Wildcards Bypassing Byte-Level Pattern Sanitization2 posts spanning 16.9 hoursResolved
8.6 days ago ALTER TABLE ... ALTER ... DROP NOT NULL only removes one not null constraint2 posts spanning 7.1 daysResolved
8.7 days ago Vuln43-24: R-Tree nodeRowidIndex Assertion Failure on Oversized Leaf Node via xConnect Accepting Unbounded Node Size2 posts spanning 2.1 hoursResolved
↓ Older...