Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-9937

21
FAUCET Score

CVE-2019-9937 describes a NULL Pointer Dereference vulnerability in SQLite version 3.27.2, specifically within its fts5 virtual table functionality, affecting the sqlite3.c, fts5_hash.c, and fts5_index.c components. This high-severity vulnerability (CVSS 7.5) can be triggered remotely with low attack complexity and no user interaction, potentially leading to a denial of service. While the vulnerability has a relatively low EPSS score and no known active exploitation, public exploit code, or significant community discussion, its potential for a complete system outage warrants attention.

Impacted Technologies

VendorProductVersion(s)CPE
3.27.2CPE matchmatch criteria
cpe:2.3:a:sqlite:sqlite:3.27.2:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

7.5HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.0

Exploit Intelligence

EPSS Score
6.25%
Probability of exploitation in next 30 days
EPSS Percentile
92.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0625 is in the 88th percentile among its peer group of 51,553 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: sqlite

Vendor Advisories (1)

redhatCVE-2019-9937Low

sqlite: null-pointer dereference in function fts5ChunkIterate in sqlite3.c

Mar 18, 2019

References

lists.opensuse.org / opensuse-security-announce/2019-05/msg00026.html
lists.debian.org / debian-lts-announce/2020/08/msg00037.html
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/EXD2GYJVTDGEQPUNMMMC5TB7MQXOBBMO
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/N66U5PY5UJU4XBFZJH7QNKIDNAVIB4OP
security.gentoo.org / glsa/201908-09
security.netapp.com / advisory/ntap-20190416-0005
Third Party Advisory
sqlite.org / src/info/45c73deb440496e8
PatchVendor Advisory
usn.ubuntu.com / 4019-1
mail-archive.com / sqlite-users%40mailinglists.sqlite.org/msg114383.html
mail-archive.com / sqlite-users%40mailinglists.sqlite.org/msg114393.html
oracle.com / security-alerts/cpujan2020.html
oracle.com / technetwork/security-advisory/cpuoct2019-5072832.html
securityfocus.com / bid/107562
Third Party AdvisoryVDB Entry