Heap Buffer Overflow Vulnerability in sqlite-vec Could Lead to Denial of Service
CVE-2024-46488

5.5MEDIUM

Key Information:

Vendor

sqlite

Vendor
CVE Published:
25 September 2024

What is CVE-2024-46488?

sqlite-vec v0.1.1 was discovered to contain a heap buffer overflow via the npy_token_next function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.
CVE-2024-46488 : Heap Buffer Overflow Vulnerability in sqlite-vec Could Lead to Denial of Service