Back to Database
Status published
Medium
CVE-2014-3574
Apache POI before 3.10.1 and 3.11.x before 3.11-beta2 allows remote...
Vulnerability Description
Apache POI before 3.10.1 and 3.11.x before 3.11-beta2 allows remote attackers to cause a denial of service (CPU consumption and crash) via a crafted OOXML file, aka an XML Entity Expansion (XEE) attack.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-3574
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21996759
- http://www.securityfocus.com/bid/69648
- http://poi.apache.org/changes.html
- http://secunia.com/advisories/61766
- https://lucene.apache.org/solr/solrnews.html#18-august-2014-recommendation-to-update-apache-poi-in-apache-solr-480-481-and-490-installations
- http://rhn.redhat.com/errata/RHSA-2014-1370.html
- http://www.apache.org/dist/poi/release/RELEASE-NOTES.txt
- http://secunia.com/advisories/60419
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95768
- http://rhn.redhat.com/errata/RHSA-2014-1400.html
- http://rhn.redhat.com/errata/RHSA-2014-1398.html
- http://secunia.com/advisories/59943
- http://rhn.redhat.com/errata/RHSA-2014-1399.html
More from apache
View All →CVE-2025-58712
Amq: privilege escalation via excessive /etc/passwd permissions
Medium
6.4
CVE-2021-25958
Generation of Error Message Containing Sensitive Information in Apache OFBiz
Medium
6.5
CVE-2021-24117
In Apache Teaclave Rust SGX SDK 1.1.3, a side-channel vulnerability...
Medium
4.9
CVE-2020-5499
Baidu Rust SGX SDK through 1.0.8 has an enclave ID...
Critical
9.8
CVE-2018-14889
CouchDB in Vectra Networks Cognito Brain and Sensor before 4.3...
High
7.8
Affected Vendor
apache
View all reports →Affected Software
poi
Vulnerable Versions:
0, 0.1, 0.2, 0.3, 0.4, 0.5, 0.6, 0.7, 0.10.0, 0.11.0, 0.12.0, 0.13.0, 0.14.0, 1.0.0, 1.0.1, 1.0.2, 1.1.0, 1.2.0, 1.5, 1.5.1, 1.7, 1.8, 1.10, 2.0, 2.5, 2.5.1, 3.0, 3.0.1, 3.0.2, 3.1, 3.2, 3.5, 3.6, 3.7, 3.8, 3.9, 3.10, 3.11
Timeline
Official Publish:
September 4th, 2014
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.