Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-13435

16
FAUCET Score

CVE-2020-13435 describes a segmentation fault vulnerability in SQLite versions up to 3.32.0, specifically within the sqlite3ExprCodeTarget function in expr.c, affecting various Fedora and SQLite distributions. Rated 5.5 Medium, this vulnerability has a local attack vector with low complexity, requiring local privileges and no user interaction, leading to high availability impact but no confidentiality or integrity compromise. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
<= 3.32.0CPE matchmatch criteria
cpe:2.3:a:sqlite:sqlite:*:*:*:*:*:*:*:*
32CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.64%
Probability of exploitation in next 30 days
EPSS Percentile
46.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0064 is in the 94th percentile among its peer group of 15,938 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (28)

microsoftpatch availablevia msrc
Product: 19212-17084Fixed in: 5.3.28-9
microsoftpatch availablevia msrc
Product: 16939-17084Fixed in: 18.2.1-1
microsoftpatch availablevia msrc
Product: 19856-17084Fixed in: 18.2.1-1
microsoftpatch availablevia msrc
Product: azl3 libdb 5.3.28-9 on Azure Linux 3.0Fixed in: 5.3.28-9
microsoftpatch availablevia msrc
Product: azl3 ceph 18.2.1-1 on Azure Linux 3.0Fixed in: 18.2.1-1
microsoftpatch availablevia msrc
Product: azl3 ceph 16.2.10-3 on Azure Linux 3.0Fixed in: 18.2.1-1
redhatpatch availablevia redhat_api
Product: Red Hat Openshift Data Foundation 4.19Fixed in: odf4/cephcsi-rhel9:sha256:4c44c079dccf8e9cbf0a1bbf295986fd496aeb0aa23ad8d324302e218f14ba8f
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift Data Foundation 4.19Fixed in: odf4/mcg-core-rhel9:sha256:3959ddbd5e30450cd65ba2cee8bcbe66fb260d5e17d864d20da1f8532a472f58
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift Data Foundation 4.19Fixed in: odf4/mcg-rhel9-operator:sha256:c0925c14fef769a74cefbf902659aefecea7aa6241f1281ff2f14712dd356747
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift Data Foundation 4.19Fixed in: odf4/ocs-client-console-rhel9:sha256:c9c249f77da5494a08151d90211799f46c501a136c63bdf5fab8528033c1a078
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift Data Foundation 4.19Fixed in: odf4/ocs-client-rhel9-operator:sha256:189525c32c30efde779dde1bc7a1310ea1845bb816cfe721081444f515c7fc14
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift Data Foundation 4.19Fixed in: odf4/ocs-metrics-exporter-rhel9:sha256:b9f32156698d517524707b1e62fb07d244fd3c5baa6c8e0dc63b7f3136ecb689
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift Data Foundation 4.19Fixed in: odf4/odf-cli-rhel9:sha256:b4b2fe4c505060bac1710c73e699ed13b0a5fea32e1ba16166f929fb8cceba33
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift Data Foundation 4.19Fixed in: odf4/odf-cloudnative-pg-rhel9-operator:sha256:b9c8f6ffca5a91d1184ef803bb4db14770cb35d305feb168412fa3a36c440d10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift Data Foundation 4.19Fixed in: odf4/odf-console-rhel9:sha256:7862c67b17eb6c291db11ecdf6e8c54fac9f2c6b45e816d0b8b79594c70faeaa
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift Data Foundation 4.19Fixed in: odf4/odf-cosi-sidecar-rhel9:sha256:819edb52f8559427f190f687840a5417de59662fa8bc5129e26e3ed2cf0e0276
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift Data Foundation 4.19Fixed in: odf4/odf-csi-addons-rhel9-operator:sha256:07979ff44a1e9132ce0df0cfd4b151ce0ab38c91c2ccbd62daed4b7654645a02
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift Data Foundation 4.19Fixed in: odf4/odf-csi-addons-sidecar-rhel9:sha256:91a659aa4db7d9410801f8120226ea41fca011b9853457d2225433b75ea87407
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift Data Foundation 4.19Fixed in: odf4/odf-multicluster-console-rhel9:sha256:398dcf8a25e4bd40310e9fc7451f9ec65b09da52cea0f147f9a3244d870c2ec8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift Data Foundation 4.19Fixed in: odf4/odf-multicluster-rhel9-operator:sha256:55f3d3d591472741f840b921533812a91653d084acbb74e2aea150695d2e4452
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift Data Foundation 4.19Fixed in: odf4/odf-must-gather-rhel9:sha256:c2d5160cf4d8fef47ca7caaf3b03052622cf49d75c6dd3ecd05f06bdc4e2291b
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift Data Foundation 4.19Fixed in: odf4/odf-rhel9-operator:sha256:e5387c81ea125ddc86211d548a45699f989c36c3cf7a2c815e8d79097e32749b
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift Data Foundation 4.19Fixed in: odf4/odr-rhel9-operator:sha256:dc5d9c9a06b8c5b0dc347d9b4465e2f26141d4f2be9cf7df36a862e942c3267a
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift Data Foundation 4.19Fixed in: odf4/rook-ceph-rhel9-operator:sha256:030161e80c9b75186b6843d08ca3173ea4c98614e9a20b434c00a1e7b535b8f7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift Data Foundation 4.19Fixed in: odf4/cephcsi-rhel9-operator:sha256:29fb0fd11d7a108f65416fc80abbd8bb50f64a173689e923753c01df79f531e3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift Data Foundation 4.19Fixed in: odf4/ocs-rhel9-operator:sha256:692d43c0ab28b5919129f1617b105fd348dd97d37d88dd1d911d61a26eb7601b
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: sqlite-0:3.26.0-15.el8
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: sqlite

Vendor Advisories (2)

redhatCVE-2020-13435Moderate

sqlite: NULL pointer dereference in sqlite3ExprCodeTarget()

May 23, 2020
microsoft2020-May/CVE-2020-13435

SQLite through 3.32.0 has a segmentation fault in sqlite3ExprCodeTarget in expr.c.

May 12, 2020

References

seclists.org / fulldisclosure/2020/Dec/32
seclists.org / fulldisclosure/2020/Nov/19
seclists.org / fulldisclosure/2020/Nov/20
seclists.org / fulldisclosure/2020/Nov/22
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/L7KXQWHIY2MQP4LNM6ODWJENMXYYQYBN
security.freebsd.org / advisories/FreeBSD-SA-20:22.sqlite.asc
security.gentoo.org / glsa/202007-26
security.netapp.com / advisory/ntap-20200528-0004
Third Party Advisory
support.apple.com / kb/HT211843
support.apple.com / kb/HT211844
support.apple.com / kb/HT211850
support.apple.com / kb/HT211931
support.apple.com / kb/HT211935
support.apple.com / kb/HT211952
usn.ubuntu.com / 4394-1
oracle.com / security-alerts/cpuApr2021.html
oracle.com / security-alerts/cpujul2020.html
sqlite.org / src/info/7a5279a25c57adf1
ExploitPatchVendor Advisory