VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 17 hours ago

CVE-2020-13871

7.5 High Not applicable

Description

SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions is too late.

CWE-416 · Use after free

Exploitation Status

No public exploit

Nothing published shows this CVE being exploited, which is not the same as ruling it out. nothing published in 6 years.

CVSS E:U

  • CISA KEV not listed
  • CISA Vulnrichment no assessment published
  • Indexed PoC none indexed
  • EPSS 4.4% chance in 30 days

Waratek Defense Posture

Not applicable

Not a Java vulnerability. Outside ARMR's domain entirely.

  • Protection none
  • Action not-needed none
  • Review automated upstream-data
  • Record active
Decided by non-java-upstream : A root cause in non-Java code: an OS kernel, a C library, or a bundled runtime
Finding The issuing CNA declared no affected product. The CVE's CPE data names sqlite/sqlite, whose code is not Java, so that is what the CVE is about — every other product on the record bundles it.

CVSS

7.5 HIGH v3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 2 metrics

VRT selects the newest version's highest entry and publishes it as cvssScore, newest rather than largest because scores are not comparable across versions, and highest rather than first because the first entry is frequently a CNA placeholder scoring 0.0 over NVD's own analysis.

VersionScoreBandVectorAssignerType
CVSS 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H NVD Primary published
CVSS 2.0 5.0 no band published AV:N/AC:L/Au:N/C:N/I:N/A:P NVD Primary

Affected Software & Releases

🏛️ Oracle CPU Advisories & Products

AdvisoryTypeQuarterProducts Oracle named in risk matrix
Oracle Critical Patch Update April 2021 CPU 2021-Q2 Oracle Communications Applications / Message Store (SQLite) (8.1)
Oracle Critical Patch Update January 2021 CPU 2021-Q1 Oracle Communications Applications / Common (SQLite) (6.0.1, 12.0.2)
Oracle MySQL / Workbench (SQLite) (8.0.22 and prior)

Indexed Oracle Components & Versions

FamilyComponentOracle's version cell (verbatim)Indexed as
Oracle Communications Applications Common (SQLite) 6.0.1, 12.0.2 6.0.1 · 12.0.2
Oracle Communications Applications Message Store (SQLite) 8.1 8.1
Oracle MySQL Workbench (SQLite) 8.0.22 and prior

🖥️ Product CPEs & Version Ranges

12 product(s) over 13 version claims (uncapped)
SourceVendorProductSchemeAffected Versions
nvd debian debian linux generic 9.0
nvd fedoraproject fedora generic 33
nvd netapp cloud backup generic any version
nvd netapp ontap select deploy administration utility generic any version
nvd oracle communications messaging server generic 8.1
nvd oracle communications network charging and control generic 6.0.1 · 12.0.2
nvd oracle enterprise manager ops center generic 12.4.0.0
nvd oracle hyperion infrastructure technology generic 11.1.2.4
nvd oracle mysql workbench generic ≤ 8.0.22
nvd oracle zfs storage appliance kit generic 8.8
nvd siemens sinec infrastructure network services generic < 1.0.1.1
nvd sqlite sqlite generic 3.32.2

References

URLTags
https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf Patch, Third Party Advisory
https://lists.debian.org/debian-lts-announce/2020/08/msg00037.html Mailing List, Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BN32AGQPMHZRNM6P6L5GZPETOWTGXOKP/
https://security.gentoo.org/glsa/202007-26 Mitigation, Third Party Advisory
https://security.netapp.com/advisory/ntap-20200619-0002/ Third Party Advisory
https://www.oracle.com/security-alerts/cpuApr2021.html Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2021.html Third Party Advisory
https://www.sqlite.org/src/info/79eff1d0383179c4 Patch, Vendor Advisory
https://www.sqlite.org/src/info/c8d3b9f0a750a529 Exploit, Vendor Advisory
https://www.sqlite.org/src/info/cd708fa84d2aaaea Exploit, Vendor Advisory

Timeline

Published 2020-06-06 Last modified 2026-06-17
Published2020-06-06By the CVE Program.
NVD record modified2026-06-17NVD's own last-modified date for this record.