CVE detail
CVE-2020-7065 — CVE-2020-7065
Published 2020-04-01 · Modified 2026-06-17 · Vendor php · Product php · Source nvd
HIGH
severity
CVSS-derived band
0.0476
EPSS probability
exploitation probability, 30d
91.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, certain invalid strings could cause PHP to overwrite stack-allocated buffer. This could lead to memory corruption, crashes and potentially code execution.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References