{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-02T09:08:09.704","vulnerabilities":[{"cve":{"id":"CVE-2024-8929","sourceIdentifier":"security@php.net","published":"2024-11-22T07:15:03.447","lastModified":"2026-06-17T08:23:34.797","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of its heap containing data from other SQL requests and possible other data belonging to different users of the same server."},{"lang":"es","value":"En las versiones de PHP 8.1.* anteriores a 8.1.31, 8.2.* anteriores a 8.2.26, 8.3.* anteriores a 8.3.14, un servidor MySQL hostil puede hacer que el cliente revele el contenido de su montón que contiene datos de otras solicitudes SQL y otros posibles datos que pertenecen a diferentes usuarios del mismo servidor."}],"affected":[{"source":"security@php.net","affectedData":[{"vendor":"PHP Group","product":"PHP","defaultStatus":"affected","modules":["mysqlnd"],"versions":[{"version":"8.1.*","lessThan":"8.1.31","versionType":"semver","status":"affected"},{"version":"8.2.*","lessThan":"8.2.24","versionType":"semver","status":"affected"},{"version":"8.3.*","lessThan":"8.3.14","versionType":"semver","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"php_group","product":"php","defaultStatus":"unknown","cpes":["cpe:2.3:a:php_group:php:*:*:*:*:*:*:*:*"],"versions":[{"version":"8.1.0","lessThan":"8.1.31","versionType":"custom","status":"affected"},{"version":"8.2.0","lessThan":"8.2.24","versionType":"custom","status":"affected"},{"version":"8.3.0","lessThan":"8.3.14","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@php.net","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N","baseScore":5.8,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":4.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-11-22T17:37:12.386428Z","id":"CVE-2024-8929","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@php.net","type":"Secondary","description":[{"lang":"en","value":"CWE-125"},{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:php:php:*:*:*:*:*:*:*:*","versionStartIncluding":"8.1.0","versionEndExcluding":"8.1.31","matchCriteriaId":"CE6E1B68-3EB9-4C67-97A6-226EA02CC2EA"},{"vulnerable":true,"criteria":"cpe:2.3:a:php:php:*:*:*:*:*:*:*:*","versionStartIncluding":"8.2.0","versionEndExcluding":"8.2.26","matchCriteriaId":"C160D91A-CF97-4DD1-A34F-8B8C852B3CEC"},{"vulnerable":true,"criteria":"cpe:2.3:a:php:php:*:*:*:*:*:*:*:*","versionStartIncluding":"8.3.0","versionEndExcluding":"8.3.14","matchCriteriaId":"35B1BA7F-0EAE-4F40-ACA4-EBC5D63F609A"}]}]}],"references":[{"url":"https://github.com/php/php-src/security/advisories/GHSA-h35g-vwh6-m678","source":"security@php.net","tags":["Exploit","Vendor Advisory"]},{"url":"https://lists.debian.org/debian-lts-announce/2024/12/msg00007.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20250110-0008/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}}]}