CVE-2024-35515

EUVD-2024-2789
Insecure deserialization in sqlitedict up to v2.1.0 allows attackers to execute arbitrary code.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 74%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
sqlitedictsqlitedict
𝑥
≤ 2.1.0
ADP
Debian logo
Debian Releases
Debian Product
Codename
sqlitedict
bookworm
unimportant
forky
unimportant
sid
unimportant
trixie
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
sqlitedict
focal
dne
jammy
dne
noble
needs-triage
oracular
ignored
plucky
needs-triage
questing
needs-triage