Asg017 develops SQLite-vec, a vector-search extension for SQLite that expands the database engine's capability for similarity queries and machine-learning workloads. The vendor's observed vulnerability profile centers on memory-safety issues within the extension, specifically heap-based buffer overflows and out-of-bounds write conditions that reflect the low-level pointer manipulation inherent to native extension code. Current severity, exploitation activity, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Asg017 over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-46488MEDIUM sqlite-vec v0.1.1 was discovered to contain a heap buffer overflow via the npy_token_next function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a cra | Sep 25, 2024 | 5.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Asg017.
Media articles that mention a CVE ID that affects a product developed by Asg017 — matched by CVE ID, not by vendor name.