Lucene search

K
cve[email protected]CVE-2014-3574
HistorySep 04, 2014 - 5:55 p.m.

CVE-2014-3574

2014-09-0417:55:05
web.nvd.nist.gov
52
apache poi
denial of service
cve-2014-3574
ooxml
xml entity expansion
xee
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

6.7 Medium

AI Score

Confidence

High

0.012 Low

EPSS

Percentile

85.0%

Apache POI before 3.10.1 and 3.11.x before 3.11-beta2 allows remote attackers to cause a denial of service (CPU consumption and crash) via a crafted OOXML file, aka an XML Entity Expansion (XEE) attack.

Affected configurations

NVD
Node
apachepoiRangeโ‰ค3.10
OR
apachepoiMatch0.1
OR
apachepoiMatch0.2
OR
apachepoiMatch0.3
OR
apachepoiMatch0.4
OR
apachepoiMatch0.5
OR
apachepoiMatch0.6
OR
apachepoiMatch0.7
OR
apachepoiMatch0.10.0
OR
apachepoiMatch0.11.0
OR
apachepoiMatch0.12.0
OR
apachepoiMatch0.13.0
OR
apachepoiMatch0.14.0
OR
apachepoiMatch1.0.0
OR
apachepoiMatch1.0.1
OR
apachepoiMatch1.0.2
OR
apachepoiMatch1.1.0
OR
apachepoiMatch1.2.0
OR
apachepoiMatch1.5
OR
apachepoiMatch1.5.1
OR
apachepoiMatch1.7dev
OR
apachepoiMatch1.8dev
OR
apachepoiMatch1.10dev
OR
apachepoiMatch2.0
OR
apachepoiMatch2.0pre1
OR
apachepoiMatch2.0pre2
OR
apachepoiMatch2.0pre3
OR
apachepoiMatch2.0rc1
OR
apachepoiMatch2.0rc2
OR
apachepoiMatch2.5
OR
apachepoiMatch2.5.1
OR
apachepoiMatch3.0
OR
apachepoiMatch3.0alpha1
OR
apachepoiMatch3.0alpha2
OR
apachepoiMatch3.0alpha3
OR
apachepoiMatch3.0.1
OR
apachepoiMatch3.0.2
OR
apachepoiMatch3.0.2beta1
OR
apachepoiMatch3.0.2beta2
OR
apachepoiMatch3.1
OR
apachepoiMatch3.1beta1
OR
apachepoiMatch3.1beta2
OR
apachepoiMatch3.2
OR
apachepoiMatch3.5
OR
apachepoiMatch3.5beta1
OR
apachepoiMatch3.5beta2
OR
apachepoiMatch3.5beta3
OR
apachepoiMatch3.5beta4
OR
apachepoiMatch3.5beta5
OR
apachepoiMatch3.5beta6
OR
apachepoiMatch3.6
OR
apachepoiMatch3.7
OR
apachepoiMatch3.7beta1
OR
apachepoiMatch3.7beta2
OR
apachepoiMatch3.7beta3
OR
apachepoiMatch3.8
OR
apachepoiMatch3.8beta1
OR
apachepoiMatch3.8beta2
OR
apachepoiMatch3.8beta3
OR
apachepoiMatch3.8beta4
OR
apachepoiMatch3.8beta5
OR
apachepoiMatch3.9
OR
apachepoiMatch3.10beta1
OR
apachepoiMatch3.10beta2
OR
apachepoiMatch3.11beta1

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

6.7 Medium

AI Score

Confidence

High

0.012 Low

EPSS

Percentile

85.0%