Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
Docs
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
apache poi vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2014-3574
Apache POI prior to 3.10.1 and 3.11.x prior to 3.11-beta2 allows remote malicious users to cause a denial of service (CPU consumption and crash) via a crafted OOXML file, aka an XML Entity Expansion (XEE) attack.
Apache Poi
Apache Poi 0.1
Apache Poi 0.2
Apache Poi 0.3
Apache Poi 0.4
Apache Poi 0.5
Apache Poi 0.6
Apache Poi 0.7
Apache Poi 0.10.0
Apache Poi 0.11.0
Apache Poi 0.12.0
Apache Poi 0.13.0
5
CVSSv2
CVE-2012-0213
The UnhandledDataStructure function in hwpf/model/UnhandledDataStructure.java in Apache POI 3.8 and previous versions allows remote malicious users to cause a denial of service (OutOfMemoryError exception and possibly JVM destabilization) via a crafted length value in a Channel D...
Apache Poi
Apache Poi 0.1
Apache Poi 0.2
Apache Poi 0.3
Apache Poi 0.4
Apache Poi 0.5
Apache Poi 0.6
Apache Poi 0.7
Apache Poi 0.10.0
Apache Poi 0.11.0
Apache Poi 0.12.0
Apache Poi 0.13.0
4.3
CVSSv2
CVE-2014-3529
The OPC SAX setup in Apache POI prior to 3.10.1 allows remote malicious users to read arbitrary files via an OpenXML file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Apache Poi
Apache Poi 0.1
Apache Poi 0.2
Apache Poi 0.3
Apache Poi 0.4
Apache Poi 0.5
Apache Poi 0.6
Apache Poi 0.7
Apache Poi 0.10.0
Apache Poi 0.11.0
Apache Poi 0.12.0
Apache Poi 0.13.0
5.5
CVSSv3
CVE-2017-5644
Apache POI in versions prior to release 3.15 allows remote malicious users to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack.
Apache Software Foundation Apache Poi
Apache Poi
5.5
CVSSv3
CVE-2016-5000
The XLSX2CSV example in Apache POI prior to 3.14 allows remote malicious users to read arbitrary files via a crafted OpenXML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Apache Poi
5.5
CVSSv3
CVE-2022-26336
A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an malicious user to cause an Out of Memory exception. This package is used to read TNEF files (Microsoft Outlook and Microsoft Exchange Server). If an application uses poi-scratchpad to parse TNEF files and ...
Apache Software Foundation Poi-scratchpad
Apache Poi
Netapp Active Iq Unified Manager -
5
CVSSv2
CVE-2014-9527
HSLFSlideShow in Apache POI prior to 3.11 allows remote malicious users to cause a denial of service (infinite loop and deadlock) via a crafted PPT file.
Fedoraproject Fedora 20
Apache Poi
5.3
CVSSv3
CVE-2025-31672
Improper Input Validation vulnerability in Apache POI. The issue affects the parsing of OOXML format files like xlsx, docx and pptx. These file formats are basically zip files and it is possible for malicious users to add zip entries with duplicate names (including the path) in t...
Apache Software Foundation Apache Poi
5.5
CVSSv3
CVE-2019-12415
In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an malicious user to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Pro...
* Apache Poi
Apache Poi
Oracle Application Testing Suite 12.5.0.3
Oracle Application Testing Suite 13.1.0.1
Oracle Application Testing Suite 13.2.0.1
Oracle Application Testing Suite 13.3.0.1
Oracle Banking Enterprise Originations 2.7.0
Oracle Banking Enterprise Originations 2.8.0
Oracle Banking Enterprise Product Manufacturing 2.7.0
Oracle Banking Enterprise Product Manufacturing 2.8.0
Oracle Banking Payments 14.0.0
Oracle Banking Payments 14.1.0
9.8
CVSSv3
CVE-2022-23640
Excel-Streaming-Reader is an easy-to-use implementation of a streaming Excel reader using Apache POI. Prior to xlsx-streamer 2.1.0, the XML parser that was used did apply all the necessary settings to prevent XML Entity Expansion issues. Upgrade to version 2.1.0 to receive a patc...
Monitorjbl Excel-streaming-reader
Excel Streaming Reader Project Excel Streaming Reader
Preferred Score:
CVSSv3
CVSSv2
CVSSv3
CVSSv4
EPSS
VMScore
Recommendations:
adp application developer platform 应用开发者平台
type confusion
flir
CVE-2025-6268
overflow
dir-825
CVE-2025-6018
CVE-2025-2783
CVE-2025-6292
webassembly
authentication bypass
CVE-2025-4479
CVE-2025-6306
Home
/
Search Results
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started