CVE-2019-9937 describes a NULL Pointer Dereference vulnerability in SQLite version 3.27.2, specifically within its fts5 virtual table functionality, affecting the sqlite3.c, fts5_hash.c, and fts5_index.c components. This high-severity vulnerability (CVSS 7.5) can be triggered remotely with low attack complexity and no user interaction, potentially leading to a denial of service. While the vulnerability has a relatively low EPSS score and no known active exploitation, public exploit code, or significant community discussion, its potential for a complete system outage warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.27.2CPE matchmatch criteria | cpe:2.3:a:sqlite:sqlite:3.27.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.