CVE-2022-35737

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/08/2022
Last modified:
13/02/2026

Description

SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sqlite:sqlite:*:*:*:*:*:*:*:* 1.0.12 (including) 3.39.2 (excluding)
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*
cpe:2.3:a:splunk:universal_forwarder:*:*:*:*:*:*:*:* 8.2.0 (including) 8.2.12 (excluding)
cpe:2.3:a:splunk:universal_forwarder:*:*:*:*:*:*:*:* 9.0.0 (including) 9.0.6 (excluding)
cpe:2.3:a:splunk:universal_forwarder:9.1.0:*:*:*:*:*:*:*