5
CVSSv2

CVE-2012-0213

Published: 07/08/2012 Updated: 11/02/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The UnhandledDataStructure function in hwpf/model/UnhandledDataStructure.java in Apache POI 3.8 and previous versions allows remote malicious users to cause a denial of service (OutOfMemoryError exception and possibly JVM destabilization) via a crafted length value in a Channel Definition Format (CDF) or Compound File Binary Format (CFBF) document.

Vulnerable Product Search on Vulmon Subscribe to Product

apache poi 3.8

apache poi 3.5

apache poi 3.1

apache poi 3.0.2

apache poi 3.0

apache poi 2.5.1

apache poi 2.5

apache poi 1.10

apache poi 1.8

apache poi 1.0.1

apache poi 1.0.0

apache poi 0.5

apache poi 0.4

apache poi

apache poi 3.7

apache poi 3.6

apache poi 3.2

apache poi 3.0.1

apache poi 2.0

apache poi 1.5

apache poi 1.2.0

apache poi 0.12.0

apache poi 0.11.0

apache poi 0.1

apache poi 1.1.0

apache poi 1.0.2

apache poi 0.10.0

apache poi 0.7

apache poi 0.6

apache poi 1.7

apache poi 1.5.1

apache poi 0.14.0

apache poi 0.13.0

apache poi 0.3

apache poi 0.2

Vendor Advisories

It was discovered that Apache POI, a Java implementation of the Microsoft Office file formats, would allocate arbitrary amounts of memory when processing crafted documents This could impact the stability of the Java virtual machine For the stable distribution (squeeze), this problem has been fixed in version 36+dfsg-1+squeeze1 We recommend that ...