Buffer overflow in PHP before 5.2.0 allows remote attackers to execute arbitrary code via crafted UTF-8 inputs to the (1) htmlentities or (2) htmlspecialchars functions.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.235
EPSS Ranking 95.7%