5
CVSSv2

CVE-2017-12626

Published: 29/01/2018 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks: 1) Infinite Loops while parsing crafted WMF, EMF, MSG and macros (POI bugs 61338 and 61294), and 2) Out of Memory Exceptions while parsing crafted DOC, PPT and XLS (POI bugs 52372 and 61295).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache poi

Vendor Advisories

Synopsis Moderate: Red Hat JBoss Fuse/A-MQ 63 R7 security and bug fix update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat JBoss Fuse and Red Hat JBoss A-MQRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerabilit ...
Debian Bug report logs - #888651 libapache-poi-java: CVE-2017-12626: Denial of Service Vulnerabilities Package: src:libapache-poi-java; Maintainer for src:libapache-poi-java is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 28 Ja ...
Debian Bug report logs - #858301 libapache-poi-java: CVE-2017-5644 Package: src:libapache-poi-java; Maintainer for src:libapache-poi-java is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 20 Mar 2017 20:36:01 UTC Severity: impor ...
Apache POI in versions prior to release 317 are vulnerable to Denial of Service Attacks: 1) Infinite Loops while parsing crafted WMF, EMF, MSG and macros (POI bugs 61338 and 61294), and 2) Out of Memory Exceptions while parsing crafted DOC, PPT and XLS (POI bugs 52372 and 61295) ...