SQLite Bug Forum: Forum

3 min read Original article ↗
3.3 hours ago Vuln66-47: View Linear-Chain Stack Overflow via `selectExpander` -> `viewGetColumnNames` Mutual Recursion2 posts spanning 9.7 hoursResolved
4.3 hours ago Vuln67-48: STAT4 loadStatTbl 32-bit size_t Multiplication Overflow Causes Heap Buffer Overflow2 posts spanning 71.0 minutesResolved
6.0 hours ago sqlite3ExprAffinity() Fails to Traverse TK_UPLUS, Causing Wrong Query Results3 posts spanning 68.2 minutesResolved
6.1 hours ago sha1_query Zeroblob NULL Pointer Dereference DoS2 posts spanning 3.2 hoursResolved
7.3 hours ago SQLite `quote()`/`sqlite3QuoteValue()` Embedded NUL Text Data Loss2 posts spanning 19.0 minutesNot Planned
24.1 hours ago Vuln62-43: ALTER TABLE DROP CONSTRAINT Silently Retains DEFAULT, COLLATE and GENERATED Clause Values in the Stored Schema4 posts spanning 12.8 hoursResolved
24.3 hours ago Vuln65-46: Compile-Time Trigger Chain Stack Overflow in `codeRowTrigger`2 posts spanning 10.1 hoursResolved
25.4 hours ago UPSERT RealAffinity Register Mapping Bug with Virtual Generated Columns2 posts spanning 6.5 hoursResolved
25.6 hours ago Vuln63-44: generate_series() Drops WHERE value >= X / > X When X Is a Float Above INT64_MAX2 posts spanning 10.9 hoursResolved
26.1 hours ago Vuln57-38: FTS3 matchinfo() Heap Buffer Overflow via 32-bit size_t Wraparound in fts3MatchinfoSize2 posts spanning 29.6 hoursResolved
27.3 hours ago Vuln59-40: FTS5 fts5StructureDecode 32-bit Integer Overflow in nTotal Allocation Causes Heap OOB Write2 posts spanning 25.4 hoursResolved
29.1 hours ago Vuln58-39: FTS5 fts5ParseTokenize Sets nQueryTerm=0 for Colocated Synonym Tokens When tokendata=12 posts spanning 24.7 hoursResolved
29.9 hours ago Vuln64-45: JSONB-to-Text Translator Discards Payload Size for NULL/TRUE/FALSE, Injecting Phantom Array Elements2 posts spanning 4.9 hoursResolved
30.8 hours ago Vuln38-19: decimal_round Loses the Carry-Out Digit and Returns Wrong Result on Carry-Past-MSD Inputs7 posts spanning 12.2 daysResolved
1.7 days ago Heap buffer overflow (write) in kvvfsDecode() in os_kv.c2 posts spanning 3.5 hoursResolved
1.8 days ago Vuln60-41: blobio Extension readblob/writeblob NULL Column Argument Dereferences NULL Pointer in sqlite3StrICmp2 posts spanning 6.8 hoursResolved
1.8 days ago Vuln61-42: CSV Virtual Table csvtabOpen 32-bit size_t Integer Overflow in nByte Allocation Causes Heap OOB2 posts spanning 5.4 hoursResolved
3.0 days ago Backward incompatible output: Order of command-line options "-header" and "-csv" changes output2 posts spanning 6.3 hoursResolved
3.1 days ago CREATE INDEX with LIKE accepted, then SQLITE_CORRUPT after `PRAGMA case_sensitive_like` change2 posts spanning 11.1 hoursResolved
3.6 days ago SQLite3 Non-deterministic Function Bypass in CREATE INDEX Expression Validation6 posts spanning 5.6 daysResolved
4.1 days ago FTS3 `fts3EvalNearTrim()` can overflow the position-list buffer during an in-place NEAR merge2 posts spanning 16.4 hoursResolved
4.1 days ago FTS3 `fts3ReadEndBlockField()` negates INT64_MIN text and triggers signed integer overflow2 posts spanning 14.7 hoursResolved
4.2 days ago WAL read-only `readonly_shm` path accepts page-size 0 and over-reads in `walChecksumBytes()`2 posts spanning 14.0 hoursResolved
6.0 days ago Vuln53-34: FTS5 fts5IndexTombstoneRebuild Signed Integer Overflow on Corrupt Tombstone nElem Field2 posts spanning 13.3 hoursResolved
6.3 days ago Vuln56-37: fileio realpath() Missing OOM Check on mprintf Result Causes strlen(NULL) Crash2 posts spanning 2.9 hoursResolved
↓ Older...