CVE-2020-13871SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions is too late.
CWE-416 · Use after free
No public exploit
Nothing published shows this CVE being exploited, which is not the same as ruling it out. nothing published in 6 years.
CVSS E:U
Not a Java vulnerability. Outside ARMR's domain entirely.
| Decided by | non-java-upstream : A root cause in non-Java code: an OS kernel, a C library, or a bundled runtime |
|---|---|
| Finding | The issuing CNA declared no affected product. The CVE's CPE data names sqlite/sqlite, whose code is not Java, so that is what the CVE is about — every other product on the record bundles it. |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2 metrics
VRT selects the newest version's highest entry and
publishes it as cvssScore, newest rather than largest because scores are not comparable
across versions, and highest rather than first because the first entry is frequently a CNA placeholder
scoring 0.0 over NVD's own analysis.
| Version | Score | Band | Vector | Assigner | Type | |
|---|---|---|---|---|---|---|
| CVSS 3.1 | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
NVD | Primary | published |
| CVSS 2.0 | 5.0 | no band published | AV:N/AC:L/Au:N/C:N/I:N/A:P |
NVD | Primary |
| Advisory | Type | Quarter | Products Oracle named in risk matrix |
|---|---|---|---|
| Oracle Critical Patch Update April 2021 ↗ | CPU | 2021-Q2 | Oracle Communications Applications / Message Store (SQLite) (8.1) |
| Oracle Critical Patch Update January 2021 ↗ | CPU | 2021-Q1 | Oracle Communications Applications / Common (SQLite) (6.0.1, 12.0.2) Oracle MySQL / Workbench (SQLite) (8.0.22 and prior) |
| Family | Component | Oracle's version cell (verbatim) | Indexed as |
|---|---|---|---|
| Oracle Communications Applications | Common (SQLite) | 6.0.1, 12.0.2 | 6.0.1 · 12.0.2 |
| Oracle Communications Applications | Message Store (SQLite) | 8.1 | 8.1 |
| Oracle MySQL | Workbench (SQLite) | 8.0.22 and prior |
| Source | Vendor | Product | Scheme | Affected Versions |
|---|---|---|---|---|
| nvd | debian | debian linux | generic | 9.0 |
| nvd | fedoraproject | fedora | generic | 33 |
| nvd | netapp | cloud backup | generic | any version |
| nvd | netapp | ontap select deploy administration utility | generic | any version |
| nvd | oracle | communications messaging server | generic | 8.1 |
| nvd | oracle | communications network charging and control | generic | 6.0.1 · 12.0.2 |
| nvd | oracle | enterprise manager ops center | generic | 12.4.0.0 |
| nvd | oracle | hyperion infrastructure technology | generic | 11.1.2.4 |
| nvd | oracle | mysql workbench | generic | ≤ 8.0.22 |
| nvd | oracle | zfs storage appliance kit | generic | 8.8 |
| nvd | siemens | sinec infrastructure network services | generic | < 1.0.1.1 |
| nvd | sqlite | sqlite | generic | 3.32.2 |
| URL | Tags |
|---|---|
| https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf | Patch, Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2020/08/msg00037.html | Mailing List, Third Party Advisory |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BN32AGQPMHZRNM6P6L5GZPETOWTGXOKP/ | |
| https://security.gentoo.org/glsa/202007-26 | Mitigation, Third Party Advisory |
| https://security.netapp.com/advisory/ntap-20200619-0002/ | Third Party Advisory |
| https://www.oracle.com/security-alerts/cpuApr2021.html | Third Party Advisory |
| https://www.oracle.com/security-alerts/cpujan2021.html | Third Party Advisory |
| https://www.sqlite.org/src/info/79eff1d0383179c4 | Patch, Vendor Advisory |
| https://www.sqlite.org/src/info/c8d3b9f0a750a529 | Exploit, Vendor Advisory |
| https://www.sqlite.org/src/info/cd708fa84d2aaaea | Exploit, Vendor Advisory |
| Published | 2020-06-06 | By the CVE Program. |
|---|---|---|
| NVD record modified | 2026-06-17 | NVD's own last-modified date for this record. |