Apache Software Foundation Apache Poi vulnerabilities
3 known vulnerabilities affecting apache_software_foundation/apache_poi.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2025-31672MEDIUMCVSS 5.3fixed in 5.4.02025-04-09
CVE-2025-31672 [MEDIUM] CWE-20 CVE-2025-31672: Improper Input Validation vulnerability in Apache POI. The issue affects the parsing of OOXML format
Improper Input Validation vulnerability in Apache POI. The issue affects the parsing of OOXML format files like xlsx, docx and pptx. These file formats are basically zip files and it is possible for malicious users to add zip entries with duplicate names (including the path) in the zip. In this case, products reading the affected file could read diff
cvelistv5nvd
CVE-2017-12626HIGHCVSS 7.5fixed in 3.172018-01-29
CVE-2017-12626 [HIGH] CWE-835 CVE-2017-12626: Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks: 1) Infinit
Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks: 1) Infinite Loops while parsing crafted WMF, EMF, MSG and macros (POI bugs 61338 and 61294), and 2) Out of Memory Exceptions while parsing crafted DOC, PPT and XLS (POI bugs 52372 and 61295).
cvelistv5nvd
CVE-2017-5644MEDIUMCVSS 5.5vbefore 3.152017-03-24
CVE-2017-5644 [MEDIUM] CWE-776 CVE-2017-5644: Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (C
Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack.
cvelistv5nvd