CVE-2025-24792
Snowflake PHP PDO Driver is a driver that uses the PHP Data Objects (PDO) extension to connect to the Snowflake database. Snowflake discovered and remediated a vulnerability in the Snowflake PHP PDO Driver where executing unsupported queries like PUT or GET on stages causes a signed-to-unsigned conversion error that crashes the application using the Driver. This vulnerability affects versions 0.2.0 through 3.0.3. Snowflake fixed the issue in version 3.1.0.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.4
- CVSS vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H
- EPSS probability
- 0.13%
- CWE
- CWE-195
- Published
- 2025-01-29
- Last modified
- 2026-03-12
Affected products
- snowflakedb pdo_snowflake
Weakness type
Related vulnerabilities
- CVE-2026-85441 — MOOS core-moos through 10.4.0 MOOSDB Denial of Service via Negative Serialized String Length
- CVE-2026-18444 — Integer Conversion Vulnerability Resulting in an Out of Bounds Read in NI LabVIEW
- CVE-2026-62959 — Coturn: Pre-authentication heap memory disclosure in ACME redirect (`try_acme_redirect`)
- CVE-2026-55737 — Heap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decoding in erts external term format decoder
- CVE-2026-55991 — Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2
- CVE-2026-49840 — FreeSWITCH: Pre-authentication heap buffer overflow in libesl `Content-Length` parsing
- CVE-2026-41682 — pupnp: Port truncation via atoi() cast in parse_uri() allows SSRF port confusion
- CVE-2026-26981 — OpenEXR has heap-buffer-overflow via signed integer underflow in ImfContextInit.cpp