Zetetic maintains SQLCipher, a specialized encrypted-database library that extends SQLite with transparent encryption for sensitive data storage across mobile and embedded applications. The vendor's vulnerability profile centers on memory-safety issues characteristic of native codebases, with recurrence of NULL-pointer dereferences and use-after-free conditions that arise in the parser and query-execution layers of the database engine. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zetetic over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-3119HIGH Zetetic SQLCipher 4.x before 4.4.3 has a NULL pointer dereferencing issue related to sqlcipher_export in crypto.c and sqlite3StrICmp in sqlite3.c. This may allow an attacker to per | Mar 25, 2021 | 7.5 | 25 | NO | NO |
CVE-2020-27207HIGH Zetetic SQLCipher 4.x before 4.4.1 has a use-after-free, related to sqlcipher_codec_pragma and sqlite3Strlen30 in sqlite3.c. A remote denial of service attack can be performed. For | Nov 26, 2020 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zetetic.
Media articles that mention a CVE ID that affects a product developed by Zetetic — matched by CVE ID, not by vendor name.