Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-8929


In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of its heap containing data from other SQL requests and possible other data belonging to different users of the same server.


Published

2024-11-22T07:15:03.447

Last Modified

2025-07-02T20:11:20.063

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.8 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-125
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application php php < 8.1.31 Yes
Application php php < 8.2.26 Yes
Application php php < 8.3.14 Yes

References