Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
  Debian DLA | 
                DLA-3986-1 | php7.4 security update | 
  Debian DSA | 
                DSA-5819-1 | php8.2 security update | 
  EUVD | 
                EUVD-2024-49638 | In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of its heap containing data from other SQL requests and possible other data belonging to different users of the same server. | 
  Ubuntu USN | 
                USN-7157-1 | PHP vulnerabilities | 
  Ubuntu USN | 
                USN-7157-3 | PHP vulnerabilities | 
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 03 Nov 2025 23:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
         | 
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        
        epss
         
  | 
    
        
        
        epss
         
  | 
Wed, 02 Jul 2025 20:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Php
         Php php  | 
|
| CPEs | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Php
         Php php  | 
Tue, 29 Apr 2025 06:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Redhat
         Redhat enterprise Linux  | 
|
| CPEs | cpe:/a:redhat:enterprise_linux:9 | |
| Vendors & Products | 
        
        Redhat
         Redhat enterprise Linux  | 
Fri, 10 Jan 2025 13:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
         | 
Tue, 26 Nov 2024 02:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
         | |
| Metrics | 
        
        
        threat_severity
         
  | 
    
        
        
        threat_severity
         
  | 
Fri, 22 Nov 2024 18:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Php Group
         Php Group php  | 
|
| CPEs | cpe:2.3:a:php_group:php:*:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Php Group
         Php Group php  | 
|
| Metrics | 
        
        ssvc
         
  | 
Fri, 22 Nov 2024 06:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of its heap containing data from other SQL requests and possible other data belonging to different users of the same server. | |
| Title | Leak partial content of the heap through heap buffer over-read in mysqlnd | |
| Weaknesses | CWE-125 CWE-200  | 
|
| References | 
         | |
| Metrics | 
        
        cvssV3_1
         
  | 
Status: PUBLISHED
Assigner: php
Published:
Updated: 2025-11-03T22:33:10.858Z
Reserved: 2024-09-17T04:17:06.982Z
Link: CVE-2024-8929
Updated: 2025-01-10T13:06:50.914Z
Status : Modified
Published: 2024-11-22T07:15:03.447
Modified: 2025-11-03T23:17:33.117
Link: CVE-2024-8929
                        OpenCVE Enrichment
                    No data.
 Debian DLA
 Debian DSA
 EUVD
 Ubuntu USN