CVE-2015-3416: Apple Mac OS X

High severity, CVSS 7.5. EPSS: 5.7% chance of exploitation in the next 30 days.

The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floating-point conversions, which allows context-dependent attackers to cause a denial of service (integer overflow and stack-based buffer overflow) or possibly have unspecified other impact via large integers in a crafted printf function call in a SELECT statement.

Affected products

  • Apple Mac OS X: up to and including 10.6.8
  • Apple watchOS: up to and including 1.0.1
  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.04 only
  • Debian Debian Linux: version 8.0 only
  • PHP PHP: from 5.4.0, before 5.4.42 (fixed in 5.4.42); from 5.5.0, before 5.5.26 (fixed in 5.5.26); from 5.6.0, before 5.6.10 (fixed in 5.6.10)
  • Sqlite Sqlite: up to and including 3.8.8.3

Published 2015-04-24. Last modified 2026-06-17.