Threats Tagged 'cve-2025-3277'
View all threats tagged with 'cve-2025-3277'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-3277'
Click on any threat for detailed analysis and mitigation recommendations
Red Hat Security Advisory: nodejs:22 security updateCVE-2025-3277 0 Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): * c-ares: c-ares has a use-after-free in read_answers() (CVE-2025-31498) * SQLite: integer overflow in SQLite (CVE-2025-3277) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 05/13/2025, 14:02:21 UTC Added: 06/02/2026, 21:43:37 UTC |
0 An integer overflow vulnerability exists in SQLite's concat_ws() function, leading to a heap buffer overflow of approximately 4GB. This occurs because a truncated integer is used for buffer allocation, but the original size is used when writing data, causing memory corruption. This flaw can result in arbitrary code execution. The vulnerability affects specific versions of SQLite and Node.js packages on Red Hat Enterprise Linux 8. A security update addressing this issue is available from Red Hat. Join the discussion | GCVE Database | 04/16/2025, 07:42:43 UTC Added: 06/02/2026, 21:43:37 UTC |
An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated size and thus a wild Heap Buffer overflow of size ~4GB can be triggered. This can result in arbitrary code execution. Join the discussion | CVE Database V5 | 04/14/2025, 16:50:48 UTC Added: 05/27/2025, 14:58:20 UTC |
Showing 1 to 3 of 3 results