Apache / Poi
10 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-31672 | Apache POI: parsing OOXML based files (xlsx, docx, etc.), poi-ooxml could read unexpected data if underlying zip has duplicate zip entry names | MEDIUM | 6.9 | Apr 9, 2025 |
| CVE-2022-26336 | A carefully crafted TNEF file can cause an out of memory exception | MEDIUM | 5.5 | Mar 4, 2022 |
| CVE-2019-12415 | poi: a specially crafted Microsoft Excel document allows attacker to read files from the local filesystem | MEDIUM | 5.5 | Oct 23, 2019 |
| CVE-2017-12626 | poi: Parsing of multiple file types can cause a denial of service via infinite loop or out of memory exception | HIGH | 7.5 | Jan 29, 2018 |
| CVE-2017-5644 | Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an… | MEDIUM | 5.5 | Mar 24, 2017 |
| CVE-2016-5000 | poi: XML External Entity (XXE) Vulnerability in Apache POI's XLSX2CSV Example | HIGH | 7.5 | Aug 5, 2016 |
| CVE-2014-9527 | apache-poi: denial of service in HSLFSlideShow via corrupted PPT file | MEDIUM | 5.0 | Jan 6, 2015 |
| CVE-2014-3574 | apache-poi: entity expansion (billion laughs) flaw | MEDIUM | 4.3 | Sep 4, 2014 |
| CVE-2014-3529 | apache-poi: XML eXternal Entity (XXE) flaw | MEDIUM | 4.3 | Sep 4, 2014 |
| CVE-2012-0213 | jakarta: JVM destabilization due to memory exhaustion when processing CDF/CFBF files | MEDIUM | 5.0 | Aug 7, 2012 |
Showing 1 to 10 of 10 CVEs