CVE-2015-3415
The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which al
The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact via a crafted CHECK clause, as demonstrated by CHECK(0&O>O) in a CREATE TABLE statement.
HIGH · CVSS 7.5
EPSS 0.0794
Schedule remediation
- EPSS percentile: top 8% of all CVEs by exploitation likelihood
- CVSS base score ≥ 7.0
Sigma rules2
YARA rules0