sqlite3-ruby
RubyGems3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting sqlite3-rubypage 1 of 1
- CVE-2011-0995LOWCVSS v2 2.1EG 2.1fixed in 1.2.42011-05-13
vulnerable: 0.5.0 ... 1.2.3 (10 versions)
The sqlite3-ruby gem in the rubygem-sqlite3 package before 1.2.4-0.5.1 in SUSE Linux Enterprise (SLE) 11 SP1 uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors.
- CVE-2026-54619LOWCVSS 2.0EG 2.0fixed in 2.9.52026-07-28
vulnerable: 0.5.0 ... 1.3.3.beta.1 (19 versions)
sqlite3 provides Ruby bindings for the SQLite3 embedded database. In version 2.9.4 and earlier, redefining a SQLite function with a different arity frees the previously registered function handler while SQLite may still reference it, resul…
- CVE-2026-54620LOWCVSS 2.0EG 2.0fixed in 2.9.52026-07-28
sqlite3 provides Ruby bindings for the SQLite3 embedded database. From 2.1.0 to 2.9.4, the callbacks used for SQLite aggregate functions can be freed while still referenced during aggregation, resulting in a use-after-free. This issue is f…
Check whether sqlite3-ruby is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for sqlite3-ruby CVEs against the assets you own.
Book a Demo →