Lucene search

K
osvGoogleOSV:GHSA-JQX5-H2HW-5Q4F
HistoryMay 04, 2022 - 12:28 a.m.

Denial of Service in Apache POI

2022-05-0400:28:50
Google
osv.dev
16

0.01 Low

EPSS

Percentile

83.5%

The UnhandledDataStructure function in hwpf/model/UnhandledDataStructure.java in Apache POI 3.8 and earlier allows remote attackers to cause a denial of service (OutOfMemoryError exception and possibly JVM destabilization) via a crafted length value in a Channel Definition Format (CDF) or Compound File Binary Format (CFBF) document.

0.01 Low

EPSS

Percentile

83.5%