Description
An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0. A specially crafted SQL command can cause a use after free vulnerability, potentially resulting in remote code execution. An attacker can send a malicious SQL command to trigger this vulnerability.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2022-21365 Vulnerability (CVE-2022-21365)
Moodle Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2011-4203)
Drupal Core 8.8.x Security Bypass (8.8.0 - 8.8.9)
Jenkins Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-3665)
WordPress Plugin WP Security Question Cross-Site Request Forgery (1.0.5)