Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-6965

80
FAUCET Score

CVE-2025-6965 is a critical memory corruption vulnerability (CWE-197) in SQLite versions prior to 3.50.2, where an excessive number of aggregate terms can lead to memory corruption. This vulnerability affects SQLite and has a CVSS score of 9.8 (Critical), indicating a network-exploitable flaw with no user interaction required, potentially leading to complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, suggesting high awareness and potential for future exploitation. Organizations are strongly advised to upgrade SQLite to version 3.50.2 or newer to mitigate this risk.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.50.2CPE matchmatch criteria
cpe:2.3:a:sqlite:sqlite:*:*:*:*:*:*:*:*
< 26.0.0CPE matchmatch criteria
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
< 26.0.0CPE matchmatch criteria
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
< 26.0.0CPE matchmatch criteria
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
< 26.0.0CPE matchmatch criteria
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

7.2HIGH

CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:D/RE:L/U:Green

Attack Vector
NETWORK
Attack Complexity
HIGH
Attack Requirements
PRESENT
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
HIGH
VS Availability
LOW
SS Confidentiality
LOW
SS Integrity
HIGH
SS Availability
LOW
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
74.39%
Probability of exploitation in next 30 days
EPSS Percentile
99.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
ExploitDB: EDB-52499 · Apr 8, 2026
This CVE's current EPSS score of 0.7439 is in the 99th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (106)

autodeskpatch availablevia llm_extracted
View patch
freepbxpatch availablevia llm_extracted
View patch
honeywellpatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: 20296-17084Fixed in: 3.44.0-2
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2026 version 18.5Fixed in: 18.5.3
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 1809 for 32-bit SystemsFixed in: 10.0.17763.8276
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 1809 for x64-based SystemsFixed in: 10.0.17763.8276
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2019Fixed in: 10.0.17763.8276
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2019 (Server Core installation)Fixed in: 10.0.17763.8276
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2022Fixed in: 10.0.20348.4648
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2022 (Server Core installation)Fixed in: 10.0.20348.4648
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 21H2 for 32-bit SystemsFixed in: 10.0.19044.6809
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 21H2 for ARM64-based SystemsFixed in: 10.0.19044.6809
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 21H2 for x64-based SystemsFixed in: 10.0.19044.6809
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 22H2 for x64-based SystemsFixed in: 10.0.19045.6809
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 22H2 for ARM64-based SystemsFixed in: 10.0.19045.6809
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 22H2 for 32-bit SystemsFixed in: 10.0.19045.6809
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2025 (Server Core installation)Fixed in: 10.0.26100.32230
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2025Fixed in: 10.0.26100.32230
View patch
microsoftpatch availablevia msrc
Product: Windows 11 Version 25H2 for ARM64-based SystemsFixed in: 10.0.26200.7623
View patch
microsoftpatch availablevia msrc
Product: Windows 11 Version 25H2 for x64-based SystemsFixed in: 10.0.26200.7623
View patch
microsoftpatch availablevia msrc
Product: Windows 11 Version 23H2 for ARM64-based SystemsFixed in: 10.0.22631.6491
View patch
microsoftpatch availablevia msrc
Product: Windows 11 Version 23H2 for x64-based SystemsFixed in: 10.0.22631.6491
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2022, 23H2 Edition (Server Core installation)Fixed in: 10.0.25398.2092
View patch
microsoftpatch availablevia msrc
Product: Windows 11 Version 24H2 for ARM64-based SystemsFixed in: 10.0.26100.7623
View patch
microsoftpatch availablevia msrc
Product: Windows 11 Version 24H2 for x64-based SystemsFixed in: 10.0.26100.7623
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 1607 for 32-bit SystemsFixed in: 10.0.14393.8783
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 1607 for x64-based SystemsFixed in: 10.0.14393.8783
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2016Fixed in: 10.0.14393.8783
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2016 (Server Core installation)Fixed in: 10.0.14393.8783
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)Fixed in: 15.9.80
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)Fixed in: 16.11.56
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2022 version 17.12Fixed in: 17.12.20
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2022 version 17.14Fixed in: 17.14.32
View patch
microsoftpatch availablevia msrc
Product: cbl2 sqlite 3.39.2-4 on CBL Mariner 2.0Fixed in: 3.39.2-4
microsoftpatch availablevia msrc
Product: cbl2 sqlite 3.39.2-3 on CBL Mariner 2.0Fixed in: 3.39.2-4
microsoftpatch availablevia msrc
Product: azl3 sqlite 3.44.0-2 on Azure Linux 3.0Fixed in: 3.44.0-2
microsoftpatch availablevia msrc
Product: 19582-16823Fixed in: 3.39.2-4
microsoftpatch availablevia msrc
Product: 19759-17086Fixed in: 3.39.2-4
redhatpatch availablevia redhat_api
Product: RHOSS-1.36-RHEL-8Fixed in: openshift-serverless-1/logic-db-migrator-tool-rhel8:1.36.0-11
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.36-RHEL-8Fixed in: openshift-serverless-1/logic-jobs-service-ephemeral-rhel8:1.36.0-10
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.36-RHEL-8Fixed in: openshift-serverless-1/logic-jobs-service-postgresql-rhel8:1.36.0-10
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.36-RHEL-8Fixed in: openshift-serverless-1/logic-kn-workflow-cli-artifacts-rhel8:1.36.0-4
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.36-RHEL-8Fixed in: openshift-serverless-1/logic-management-console-rhel8:1.36.0-9
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.36-RHEL-8Fixed in: openshift-serverless-1/logic-operator-bundle:1.36.0-12
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.36-RHEL-8Fixed in: openshift-serverless-1/logic-rhel8-operator:1.36.0-18
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.36-RHEL-8Fixed in: openshift-serverless-1/logic-swf-builder-rhel8:1.36.0-11
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.36-RHEL-8Fixed in: openshift-serverless-1/logic-swf-devmode-rhel8:1.36.0-7
View patch
redhatpatch availablevia redhat_api
Product: cert-manager operator for Red Hat OpenShift 1.16Fixed in: cert-manager/jetstack-cert-manager-rhel9:sha256:ec9c6b34a40da29f3ee89b361d94879025a998d34309bf3b63c555f3c225eb16
View patch
redhatpatch availablevia redhat_api
Product: Compliance Operator 1Fixed in: compliance/openshift-compliance-content-rhel8:sha256:0642196267bef5bc68c20a5ee4d35c5dd139fbb00a905578a85cab5e220f445a
View patch
redhatpatch availablevia redhat_api
Product: Compliance Operator 1Fixed in: compliance/openshift-compliance-must-gather-rhel8:sha256:4953a7ea865ff38a4fe19d5536d8062870c262733c640a2c7e4bd9e0bfb3d498
View patch
redhatpatch availablevia redhat_api
Product: Compliance Operator 1Fixed in: compliance/openshift-compliance-openscap-rhel8:sha256:06ad8599c4b0170264e40a45b0126504c87c37f0832265c7ff6541d2385b2049
View patch
redhatpatch availablevia redhat_api
Product: Compliance Operator 1Fixed in: compliance/openshift-compliance-rhel8-operator:sha256:9bc1fca7173d0080640ff9900d362512e480012a616922f4763e8e6becd8f520
View patch
redhatpatch availablevia redhat_api
Product: File Integrity Operator 1Fixed in: compliance/openshift-file-integrity-rhel8-operator:sha256:364d11af112a5b1d3f28c9ea8b7aac678e111b9c7fca0516d61036904f318605
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.7Fixed in: advanced-cluster-security/rhacs-collector-rhel8:sha256:0ba8b652771a517a5c724bc91bbca265a8e86efdd2e83b504c8fb309715a3758
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AI Inference Server 3.2Fixed in: rhaiis/vllm-cuda-rhel9:sha256:bddcf7ab6d576572b6d60822c313ffebcd9869e4fde93e32ac327821f93cf32b
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AI Inference Server 3.2Fixed in: rhaiis/vllm-rocm-rhel9:sha256:7856bdb7ae0d643a7b9362c164d4d4fe3c0c7186f5fff73a7ae9835b3df52e57
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AI Inference Server 3.2Fixed in: rhaiis/model-opt-cuda-rhel9:sha256:14e32e88f1b89f59ed34a6d712746b82a6a54c6ed4727784f18aeff853abbdc7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AI Inference Server 3.2Fixed in: rhaiis/vllm-cuda-rhel9:sha256:dcb9d1cd005c40b6db6f893e56419e383b9dcc0d38315605cb1457e2af5354f7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ceph Storage 7Fixed in: rhceph/rhceph-7-rhel9:sha256:4d2f9dc5b2b33ee1c77bbfabcbbb9f4d94d343b04c4de2e4f8b3b81a1f0fd2fe
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ceph Storage 8Fixed in: rhceph/rhceph-8-rhel9:sha256:69c4edadc3bfd45dd982764b7f9d9a0f3a6d74d26a0443796aaa4a65455c62d1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ceph Storage 8Fixed in: rhceph/rhceph-8-rhel9:sha256:97a60239048123bc963d7c9ac2ad85caa6a254759e44c15f173ca12ea51e4719
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Discovery 2Fixed in: discovery/discovery-server-rhel9:sha256:c517869dacaf4d3650310d4a52e83706e0b311d6ebb4a9b37b1c7acff5c142ec
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Discovery 2Fixed in: discovery/discovery-server-rhel9:sha256:b4683720677a1e45efbfd291d8b130b530642221e8a55a49e931e1b8b2c81ac3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Discovery 2Fixed in: discovery/discovery-ui-rhel9:sha256:310df392f638ef6eca1a26db024ae2cb617db5932f886d2acddc92fb7289e740
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Insights proxy 1.5Fixed in: insights-proxy/insights-proxy-container-rhel9:sha256:c26d589f12647890b67aaa986f54d3f7c6f7f2563fb5a73f38d559e6138739d7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: sqlite-0:3.46.1-5.el10_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Insights proxy 1.5Fixed in: insights-proxy/insights-proxy-container-rhel9:sha256:345d8bc236043df01ce0557357d20fa443719dc943038f9648cfac0c5a465cfe
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7 Extended Lifecycle SupportFixed in: sqlite-0:3.7.17-9.el7_9.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: nodejs:22-8100020250717142920.6d880403
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: sqlite-0:3.26.0-20.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: mingw-sqlite-0:3.26.0.0-2.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: sqlite-0:3.26.0-6.el8_2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: spice-client-win-0:8.10-3.el8_2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: sqlite-0:3.26.0-13.el8_4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: spice-client-win-0:8.10-3.el8_4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnFixed in: sqlite-0:3.26.0-13.el8_4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnFixed in: spice-client-win-0:8.10-3.el8_4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportFixed in: sqlite-0:3.26.0-16.el8_6.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportFixed in: spice-client-win-0:8.10-3.el8_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceFixed in: sqlite-0:3.26.0-16.el8_6.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceFixed in: spice-client-win-0:8.10-3.el8_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsFixed in: sqlite-0:3.26.0-16.el8_6.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsFixed in: spice-client-win-0:8.10-3.el8_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceFixed in: sqlite-0:3.26.0-18.el8_8.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceFixed in: spice-client-win-0:8.10-3.el8_8.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsFixed in: sqlite-0:3.26.0-18.el8_8.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsFixed in: spice-client-win-0:8.10-3.el8_8.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: nodejs:22-9060020250721113755.rhel9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: sqlite-0:3.34.1-8.el9_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: sqlite-0:3.34.1-9.el9_7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsFixed in: sqlite-0:3.34.1-5.el9_0.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsFixed in: sqlite-0:3.34.1-6.el9_2.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: sqlite-0:3.34.1-7.el9_4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.12Fixed in: rhcos-412.86.202510291903-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.13Fixed in: rhcos-413.92.202510150118-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.14Fixed in: rhcos-414.92.202510211419-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.17Fixed in: rhcos-417.94.202510112152-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.18Fixed in: rhcos-418.94.202510230424-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.19Fixed in: rhcos-4.19.9.6.202510140714-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.20Fixed in: rhcos-4.20.9.6.202509251656-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Terminal 1.11 on RHEL 9Fixed in: web-terminal/web-terminal-rhel9-operator:1.11-19
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Terminal 1.11 on RHEL 9Fixed in: web-terminal/web-terminal-tooling-rhel9:1.11-8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Terminal 1.12 on RHEL 9Fixed in: web-terminal/web-terminal-tooling-rhel9:1.12-4
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.36-RHEL-8Fixed in: openshift-serverless-1/logic-data-index-ephemeral-rhel8:1.36.0-11
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.36-RHEL-8Fixed in: openshift-serverless-1/logic-data-index-postgresql-rhel8:1.36.0-11
View patch

Vendor Advisories (7)

microsoft2026-Apr/CVE-2025-6965

Integer Truncation on SQLite

Apr 14, 2026
honeywellllm-honeywell-c82b5cfda9df97a3CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
autodeskllm-autodesk-c365b674a2ff5a3aCRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
freepbxllm-freepbx-e54908c7967265f6CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
nugetGHSA-2m69-gcr7-jv3qhigh

SQLitePCLRaw.lib.e_sqlite3 has a vulnerable dependency on SQLite

Jul 15, 2025
redhatCVE-2025-6965Important

sqlite: Integer Truncation in SQLite

Jul 15, 2025
microsoft2025-Jul/CVE-2025-6965Important

Integer Truncation on SQLite

Jul 8, 2025

References

cert-portal.siemens.com / productcert/html/ssa-225816.html
Third Party Advisory
cert-portal.siemens.com / productcert/html/ssa-485750.html
Third Party Advisory
seclists.org / fulldisclosure/2025/Sep/49
Third Party Advisory
seclists.org / fulldisclosure/2025/Sep/53
Third Party Advisory
seclists.org / fulldisclosure/2025/Sep/56
Third Party Advisory
seclists.org / fulldisclosure/2025/Sep/57
Third Party Advisory
seclists.org / fulldisclosure/2025/Sep/58
Third Party Advisory
openwall.com / lists/oss-security/2025/09/06/1
Third Party Advisory
sqlite.org / src/info/5508b56fd24016c13981ec280ecdd833007c9d8dd595edb295b984c2b487b5c8
Patch