---
cve: "CVE-2025-6965"
severity: "HIGH"
cvss: 7.2
epss: "74.9%"
vendor: "SQLite"
kev: false
exploited: false
published: "2025-07-15 14:15:31"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-08T02:54:17+02:00"
---

# CVE-2025-6965

> 7.2 HIGH

## Beschreibung

There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/S:N/AU:N/R:U/V:D/RE:L/U:Green
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Hoch | good |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |

## Exploit-Evidenz

- [EDB-52499 — SQLite 3.50.1 - Heap Overflow](https://www.exploit-db.com/exploits/52499)

## Patch verfügbar (OSV)

- 9d7c5df7f0e42528bf514b5231d58273bea47e40 (Commit)

## Referenzen

- <https://www.sqlite.org/src/info/5508b56fd24016c13981ec280ecdd833007c9d8dd595edb295b984c2b487b5c8>
- <http://seclists.org/fulldisclosure/2025/Sep/49>
- <http://seclists.org/fulldisclosure/2025/Sep/53>
- <http://seclists.org/fulldisclosure/2025/Sep/56>
- <http://seclists.org/fulldisclosure/2025/Sep/57>
- <http://seclists.org/fulldisclosure/2025/Sep/58>
- <http://www.openwall.com/lists/oss-security/2025/09/06/1>
- <https://cert-portal.siemens.com/productcert/html/ssa-225816.html>
- <https://cert-portal.siemens.com/productcert/html/ssa-485750.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2025-6965) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
