4.3

CVE-2014-3574

Apache POI before 3.10.1 and 3.11.x before 3.11-beta2 allows remote attackers to cause a denial of service (CPU consumption and crash) via a crafted OOXML file, aka an XML Entity Expansion (XEE) attack.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Poi Version <= 3.10
Apache ≫ Poi Version 0.1
Apache ≫ Poi Version 0.2
Apache ≫ Poi Version 0.3
Apache ≫ Poi Version 0.4
Apache ≫ Poi Version 0.5
Apache ≫ Poi Version 0.6
Apache ≫ Poi Version 0.7
Apache ≫ Poi Version 0.10.0
Apache ≫ Poi Version 0.11.0
Apache ≫ Poi Version 0.12.0
Apache ≫ Poi Version 0.13.0
Apache ≫ Poi Version 0.14.0
Apache ≫ Poi Version 1.0.0
Apache ≫ Poi Version 1.0.1
Apache ≫ Poi Version 1.0.2
Apache ≫ Poi Version 1.1.0
Apache ≫ Poi Version 1.2.0
Apache ≫ Poi Version 1.5
Apache ≫ Poi Version 1.5.1
Apache ≫ Poi Version 1.7 Update dev
Apache ≫ Poi Version 1.8 Update dev
Apache ≫ Poi Version 1.10 Update dev
Apache ≫ Poi Version 2.0
Apache ≫ Poi Version 2.0 Update pre1
Apache ≫ Poi Version 2.0 Update pre2
Apache ≫ Poi Version 2.0 Update pre3
Apache ≫ Poi Version 2.0 Update rc1
Apache ≫ Poi Version 2.0 Update rc2
Apache ≫ Poi Version 2.5
Apache ≫ Poi Version 2.5.1
Apache ≫ Poi Version 3.0
Apache ≫ Poi Version 3.0 Update alpha1
Apache ≫ Poi Version 3.0 Update alpha2
Apache ≫ Poi Version 3.0 Update alpha3
Apache ≫ Poi Version 3.0.1
Apache ≫ Poi Version 3.0.2
Apache ≫ Poi Version 3.0.2 Update beta1
Apache ≫ Poi Version 3.0.2 Update beta2
Apache ≫ Poi Version 3.1
Apache ≫ Poi Version 3.1 Update beta1
Apache ≫ Poi Version 3.1 Update beta2
Apache ≫ Poi Version 3.2
Apache ≫ Poi Version 3.5
Apache ≫ Poi Version 3.5 Update beta1
Apache ≫ Poi Version 3.5 Update beta2
Apache ≫ Poi Version 3.5 Update beta3
Apache ≫ Poi Version 3.5 Update beta4
Apache ≫ Poi Version 3.5 Update beta5
Apache ≫ Poi Version 3.5 Update beta6
Apache ≫ Poi Version 3.6
Apache ≫ Poi Version 3.7
Apache ≫ Poi Version 3.7 Update beta1
Apache ≫ Poi Version 3.7 Update beta2
Apache ≫ Poi Version 3.7 Update beta3
Apache ≫ Poi Version 3.8
Apache ≫ Poi Version 3.8 Update beta1
Apache ≫ Poi Version 3.8 Update beta2
Apache ≫ Poi Version 3.8 Update beta3
Apache ≫ Poi Version 3.8 Update beta4
Apache ≫ Poi Version 3.8 Update beta5
Apache ≫ Poi Version 3.9
Apache ≫ Poi Version 3.10 Update beta1
Apache ≫ Poi Version 3.10 Update beta2
Apache ≫ Poi Version 3.11 Update beta1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.4% 0.936
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www-01.ibm.com/support/docview.wss?uid=swg21996759
http://poi.apache.org/changes.html
http://rhn.redhat.com/errata/RHSA-2014-1370.html
http://rhn.redhat.com/errata/RHSA-2014-1398.html
http://rhn.redhat.com/errata/RHSA-2014-1399.html
http://rhn.redhat.com/errata/RHSA-2014-1400.html
http://secunia.com/advisories/59943
http://secunia.com/advisories/60419
http://secunia.com/advisories/61766
http://www.apache.org/dist/poi/release/RELEASE-NOTES.txt
Vendor Advisory
https://lucene.apache.org/solr/solrnews.html#18-august-2014-recommendation-to-update-apache-poi-in-apache-solr-480-481-and-490-installations
Patch
Vendor Advisory
http://www.securityfocus.com/bid/69648
https://exchange.xforce.ibmcloud.com/vulnerabilities/95768