CVE-2025-71316EPSS p30.1%
CVE-2025-71316CVE-2025-71316
Description
SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Windows C runtime converts Unicode characters to ANSI codepages. An attacker could use the '-L' option to load an arbitrary DLL with a crafted command line argument string that results in command line file arguments being misinterpreted as command line options. Fixed on or around 2025-12-26.
Scoring
| CVSS | 9.8 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.38% probability of exploitation · percentile 30.1% · 2026-06-18T12:00:27Z |
| Last modified | 2026-06-05 |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.