cbcvebase.

Microsoft Excel vulnerabilities

400 known vulnerabilities affecting microsoft/excel.

Total CVEs
400
CISA KEV
6
actively exploited
Public exploits
34
Exploited in wild
9
Severity breakdown
CRITICAL128HIGH220MEDIUM52

Vulnerabilities

Page 15 of 20
CVE-2011-1987CRITICALCVSS 9.3v2003v2007+1 more2011-09-15
CVE-2011-1987 [CRITICAL] CWE-119 CVE-2011-1987: Array index error in Microsoft Excel 2003 SP3 and 2007 SP2; Excel in Office 2007 SP2; Excel 2010 Gol Array index error in Microsoft Excel 2003 SP3 and 2007 SP2; Excel in Office 2007 SP2; Excel 2010 Gold and SP1; Excel in Office 2010 Gold and SP1; Office 2004, 2008, and 2011 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 allows remote attackers to
nvd
CVE-2011-1986CRITICALCVSS 9.3v20032011-09-15
CVE-2011-1986 [CRITICAL] CWE-399 CVE-2011-1986: Use-after-free vulnerability in Microsoft Excel 2003 SP3 allows remote attackers to execute arbitrar Use-after-free vulnerability in Microsoft Excel 2003 SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Use after Free WriteAV Vulnerability."
nvd
CVE-2011-1990CRITICALCVSS 9.3v20072011-09-15
CVE-2011-1990 [CRITICAL] CWE-119 CVE-2011-1990: Microsoft Excel 2007 SP2; Excel in Office 2007 SP2; Excel Viewer SP2; Office Compatibility Pack for Microsoft Excel 2007 SP2; Excel in Office 2007 SP2; Excel Viewer SP2; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; and Excel Services on Office SharePoint Server 2007 SP2 do not properly validate the sign of an unspecified array index, which allows remote attackers to execute arbitrary code via a crafted spreadshee
nvd
CVE-2011-1274CRITICALCVSS 9.3v2002v2003+1 more2011-06-16
CVE-2011-1274 [CRITICAL] CWE-119 CVE-2011-1274: Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 and 2008 for Mac; Open XML File Format Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitr
nvd
CVE-2011-1273CRITICALCVSS 9.3v2002v2003+2 more2011-06-16
CVE-2011-1273 [CRITICAL] CWE-119 CVE-2011-1273: Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004, 2008, and 2011 for Mac; Open XM Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004, 2008, and 2011 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to e
nvd
CVE-2011-1276CRITICALCVSS 9.3PoCv2002v2003+1 more2011-06-16
CVE-2011-1276 [CRITICAL] CWE-119 CVE-2011-1276: Buffer overflow in Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 and 2008 for Mac; O Buffer overflow in Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craft
nvd
CVE-2011-1272CRITICALCVSS 9.3v2002v2003+1 more2011-06-16
CVE-2011-1272 [CRITICAL] CWE-20 CVE-2011-1272: Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 and 2008 for Mac; Open XML File Format Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 do not properly validate record structures during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrar
nvd
CVE-2011-1277CRITICALCVSS 9.3v20022011-06-16
CVE-2011-1277 [CRITICAL] CWE-119 CVE-2011-1277: Microsoft Excel 2002 SP3, Office 2008 for Mac, and Open XML File Format Converter for Mac do not pro Microsoft Excel 2002 SP3, Office 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel Memory Corruption Vulnerability."
nvd
CVE-2011-1279CRITICALCVSS 9.3v2002v20032011-06-16
CVE-2011-1279 [CRITICAL] CWE-119 CVE-2011-1279: Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Conver Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel Out of Bounds
nvd
CVE-2011-1278CRITICALCVSS 9.3v20022011-06-16
CVE-2011-1278 [CRITICAL] CWE-119 CVE-2011-1278: Microsoft Excel 2002 SP3 and Office 2004 for Mac do not properly validate record information during Microsoft Excel 2002 SP3 and Office 2004 for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel WriteAV Vulnerability."
nvd
CVE-2011-1275CRITICALCVSS 9.3v20022011-06-16
CVE-2011-1275 [CRITICAL] CWE-119 CVE-2011-1275: Microsoft Excel 2002 SP3; Office 2004, 2008, and 2011 for Mac; and Open XML File Format Converter fo Microsoft Excel 2002 SP3; Office 2004, 2008, and 2011 for Mac; and Open XML File Format Converter for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel Memory Heap Overwrit
nvd
CVE-2011-0105CRITICALCVSS 9.3PoCv20022011-04-13
CVE-2011-0105 [CRITICAL] CWE-119 CVE-2011-0105: Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac o Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac obtain a certain length value from an uninitialized memory location, which allows remote attackers to trigger a buffer overflow and execute arbitrary code via a crafted Excel file, aka "Excel Data Initialization Vulnerability."
nvd
CVE-2011-0104CRITICALCVSS 9.3PoCv2002v20032011-04-13
CVE-2011-0104 [CRITICAL] CWE-119 CVE-2011-0104: Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Conver Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HLink record in an Excel file, aka "Excel Buffer Overwrite Vulnerability."
nvd
CVE-2011-0097CRITICALCVSS 9.3v2002v2003+2 more2011-04-13
CVE-2011-0097 [CRITICAL] CWE-189 CVE-2011-0097: Integer underflow in Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004 and 2008 fo Integer underflow in Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 allows remote attackers to execute arbitrary code via a crafted 400h substream in an Excel file, which
nvd
CVE-2011-0103CRITICALCVSS 9.3v2002v20032011-04-13
CVE-2011-0103 [CRITICAL] CWE-119 CVE-2011-0103: Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Conver Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted record information in an Excel file, aka "Excel Memory Corruption Vulnerability."
nvd
CVE-2011-0098CRITICALCVSS 9.3v2002v2003+2 more2011-04-13
CVE-2011-0098 [CRITICAL] CWE-189 CVE-2011-0098: Integer signedness error in Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004 and Integer signedness error in Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 allows remote attackers to execute arbitrary code via an XLS file with a large record size, aka
nvd
CVE-2011-0101CRITICALCVSS 9.3v20022011-04-13
CVE-2011-0101 [CRITICAL] CWE-119 CVE-2011-0101: Microsoft Excel 2002 SP3 allows remote attackers to execute arbitrary code or cause a denial of serv Microsoft Excel 2002 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted RealTimeData record, related to a stTopic field, double-byte characters, and an incorrect pointer calculation, aka "Excel Record Parsing WriteAV Vulnerability."
nvd
CVE-2011-0977CRITICALCVSS 9.3v20072011-02-10
CVE-2011-0977 [CRITICAL] CWE-399 CVE-2011-0977: Use-after-free vulnerability in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 20 Use-after-free vulnerability in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via malformed shape data in the Office drawing file format, aka "Microsoft Office Graphic Object Dereferencing Vulnerability."
nvd
CVE-2011-0979CRITICALCVSS 9.3v2002v2003+2 more2011-02-10
CVE-2011-0979 [CRITICAL] CWE-20 CVE-2011-0979: Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004, 2008, and 2011 for Mac; Open XM Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004, 2008, and 2011 for Mac; Open XML File Format Converter for Mac; and Excel Viewer SP2 do not properly handle errors during the parsing of Office Art records in Excel spreadsheets, which allows remote attackers to execute arbitrary code via a malformed object record, related to a "str
nvd
CVE-2011-0978CRITICALCVSS 9.3PoCv2002v2003+1 more2011-02-10
CVE-2011-0978 [CRITICAL] CWE-119 CVE-2011-0978: Stack-based buffer overflow in Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 for Mac Stack-based buffer overflow in Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 allows remote attackers to execute arbitrary code via vectors related to an axis properties record, and improper incrementing of an array index, ak
nvd