Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 04 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 04 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Windows C runtime converts Unicode characters to ANSI codepages. An attacker could use the '-L' option to load an arbitrary DLL with a crafted command line argument string that results in command line file arguments being misinterpreted as command line options. Fixed on or around 2025-12-26. | |
| Title | SQLite sqldiff remote code execution via argument injection | |
| Weaknesses | CWE-176 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2026-06-04T19:14:20.094Z
Reserved: 2026-06-04T17:08:59.278Z
Link: CVE-2025-71316
No data.
Status : Received
Published: 2026-06-04T19:16:27.170
Modified: 2026-06-04T20:16:56.947
Link: CVE-2025-71316
No data.
OpenCVE Enrichment
Updated: 2026-06-04T20:30:16Z