Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
SQLite sqldiff remote code execution via argument injection
Vulnerability Description
SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Windows C runtime converts Unicode characters to ANSI codepages. An attacker could use the '-L' option to load an arbitrary DLL with a crafted command line argument string that results in command line file arguments being misinterpreted as command line options. Fixed on or around 2025-12-26.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
Unicode编码处理不恰当
Vulnerability Title
SQLite sqldiff 安全漏洞
Vulnerability Description
SQLite sqldiff是SQLite开源的一个SQLite数据库差异比较工具。 SQLite sqldiff存在安全漏洞,该漏洞源于Windows C运行时转换Unicode字符为ANSI代码页时未安全处理,攻击者可通过-L选项加载任意DLL,导致命令行文件参数被误解为命令行选项。
CVSS Information
N/A
Vulnerability Type
N/A