VulnerabilityAnalyzed
CVE-2025-6965
There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available.
HIGH 7.2EPSS 75.8%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 75.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.
- CVSS 4.0
- 7.2 HIGHCVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 75.83% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-197
- Affected
- sqlite/sqlite · apple/ipados · apple/iphone os · apple/macos · apple/tvos · apple/visionos · apple/watchos · siemens/ruggedcom crossbow · siemens/sidis prime
- Source
- cve-coordination@google.com
References
- https://www.sqlite.org/src/info/5508b56fd24016c13981ec280ecdd833007c9d8dd595edb295b984c2b487b5c8Patch
- http://seclists.org/fulldisclosure/2025/Sep/49Third Party Advisory
- http://seclists.org/fulldisclosure/2025/Sep/53Third Party Advisory
- http://seclists.org/fulldisclosure/2025/Sep/56Third Party Advisory
- http://seclists.org/fulldisclosure/2025/Sep/57Third Party Advisory
- http://seclists.org/fulldisclosure/2025/Sep/58Third Party Advisory
- http://www.openwall.com/lists/oss-security/2025/09/06/1Third Party Advisory
- https://cert-portal.siemens.com/productcert/html/ssa-225816.htmlThird Party Advisory
- https://cert-portal.siemens.com/productcert/html/ssa-485750.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.