cbcvebase.

Microsoft Excel vulnerabilities

438 known vulnerabilities affecting microsoft/excel.

Total CVEs
438
CISA KEV
6
actively exploited
Public exploits
34
Exploited in wild
21
Severity breakdown
CRITICAL128HIGH250MEDIUM59LOW1

Vulnerabilities

Page 5 of 22
CVE-2010-3239P3CRITICALCVSS 9.3v20022010-10-13
CVE-2010-3239 [CRITICAL] CWE-20 CVE-2010-3239: Microsoft Excel 2002 SP3 does not properly validate record information, which allows remote attacker Microsoft Excel 2002 SP3 does not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Extra Out of Boundary Record Parsing Vulnerability."
nvd
CVE-2010-3240P3CRITICALCVSS 9.3v2002v20072010-10-13
CVE-2010-3240 [CRITICAL] CWE-20 CVE-2010-3240: Microsoft Excel 2002 SP3 and 2007 SP2; Excel Viewer SP2; and Office Compatibility Pack for Word, Exc Microsoft Excel 2002 SP3 and 2007 SP2; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Real Time Data Array Record Vulnerability."
nvd
CVE-2017-8510P3HIGHCVSS 8.8v20132017-06-15
CVE-2017-8510 [HIGH] CVE-2017-8510: A remote code execution vulnerability exists in Microsoft Office when the software fails to properly A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8509, CVE-2017-8511, CVE-2017-8512, CVE-2017-0260, and CVE-2017-8506.
nvd
CVE-2011-1987P3CRITICALCVSS 9.3v2003v2007+1 more2011-09-15
CVE-2011-1987 [CRITICAL] CWE-119 CVE-2011-1987: Array index error in Microsoft Excel 2003 SP3 and 2007 SP2; Excel in Office 2007 SP2; Excel 2010 Gol Array index error in Microsoft Excel 2003 SP3 and 2007 SP2; Excel in Office 2007 SP2; Excel 2010 Gold and SP1; Excel in Office 2010 Gold and SP1; Office 2004, 2008, and 2011 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 allows remote attackers to
nvd
CVE-2011-0980P3CRITICALCVSS 9.3v2002v20032011-02-10
CVE-2011-0980 [CRITICAL] CWE-264 CVE-2011-0980: Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Conver Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse Office Art objects, which allows remote attackers to execute arbitrary code via vectors related to a function pointer, aka "Excel Dangling Pointer Vulnerability."
nvd
CVE-2015-2555P3CRITICALCVSS 9.3v2010v20132015-10-14
CVE-2015-2555 [CRITICAL] CVE-2015-2555: Use-after-free vulnerability in Microsoft Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2 Use-after-free vulnerability in Microsoft Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, and Excel Services on SharePoint Server 2010 SP2 and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted calculatedColumnFormula object in an Office document, aka "Microsoft Office Memory Corru
nvd
CVE-2015-2558P3CRITICALCVSS 9.3v2007v2010+2 more2015-10-14
CVE-2015-2558 [CRITICAL] CVE-2015-2558: Use-after-free vulnerability in Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 Use-after-free vulnerability in Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, Excel Viewer, Office Compatibility Pack SP3, and Excel Services on SharePoint Server 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a long fileVersion element
nvd
CVE-2009-3134P3CRITICALCVSS 9.3v2002v2003+1 more2009-11-11
CVE-2009-3134 [CRITICAL] CWE-94 CVE-2009-3134: Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 do not properly parse the Excel file format, which allows remot
nvd
CVE-2010-1253P3CRITICALCVSS 9.3v2002v20072010-06-08
CVE-2010-1253 [CRITICAL] CWE-94 CVE-2010-1253: Microsoft Office Excel 2002 SP3, 2007 SP1, and SP2; Office 2004 for mac; Office 2008 for Mac; Open X Microsoft Office Excel 2002 SP3, 2007 SP1, and SP2; Office 2004 for mac; Office 2008 for Mac; Open XML File Format Converter for Mac; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2; allows remote attackers to execute arbitrary code via an Excel file with crafted DBQueryExt records that allow a function cal
nvd
CVE-2010-0263P3CRITICALCVSS 9.3v2002v2003+1 more2010-03-10
CVE-2010-0263 [CRITICAL] CWE-94 CVE-2010-0263: Microsoft Office Excel 2007 SP1 and SP2; Office 2008 for Mac; Open XML File Format Converter for Mac Microsoft Office Excel 2007 SP1 and SP2; Office 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer SP1 and SP2; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2; and Office SharePoint Server 2007 SP1 and SP2 do not validate ZIP headers during decompression of Open XML (.XLSX) documents, wh
nvd
CVE-2011-1988P3CRITICALCVSS 9.3v2003v20072011-09-15
CVE-2011-1988 [CRITICAL] CWE-119 CVE-2011-1988: Microsoft Excel 2003 SP3 and 2007 SP2; Excel in Office 2007 SP2; Office 2004 and 2008 for Mac; Open Microsoft Excel 2003 SP3 and 2007 SP2; Excel in Office 2007 SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 do not properly parse records in Excel spreadsheets, which allows remote attackers to execute arbitrary code via a
nvd
CVE-2012-0143P3CRITICALCVSS 9.3v20032012-05-09
CVE-2012-0143 [CRITICAL] CWE-399 CVE-2012-0143: Microsoft Excel 2003 SP3 and Office 2008 for Mac do not properly handle memory during the opening of Microsoft Excel 2003 SP3 and Office 2008 for Mac do not properly handle memory during the opening of files, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Memory Corruption Using Various Modified Bytes Vulnerability."
nvd
CVE-2020-1225P3HIGHCVSS 8.8v2010v2013+1 more2020-06-09
CVE-2020-1225 [HIGH] CWE-416 CVE-2020-1225: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1226.
nvd
CVE-2020-1226P3HIGHCVSS 8.8v2010v2013+1 more2020-06-09
CVE-2020-1226 [HIGH] CVE-2020-1226: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1225.
nvd
CVE-2012-0141P3CRITICALCVSS 9.3v2003v2007+1 more2012-05-09
CVE-2012-0141 [CRITICAL] CWE-119 CVE-2012-0141: Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2011 for Mac; Excel Viewer Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2011 for Mac; Excel Viewer; and Office Compatibility Pack SP2 and SP3 do not properly handle memory during the opening of files, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel File Format Memory Corruption Vulnerability."
nvd
CVE-2010-3233P3CRITICALCVSS 9.3v2002v20032010-10-13
CVE-2010-3233 [CRITICAL] CWE-20 CVE-2010-3233: Microsoft Excel 2002 SP3 and 2003 SP3 does not properly validate record information, which allows re Microsoft Excel 2002 SP3 and 2003 SP3 does not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted .wk3 (aka Lotus 1-2-3 workbook) file, aka "Lotus 1-2-3 Workbook Parsing Vulnerability."
nvd
CVE-2010-0262P3CRITICALCVSS 9.3v2002v2003+1 more2010-03-10
CVE-2010-0262 [CRITICAL] CWE-94 CVE-2010-0262: Microsoft Office Excel 2007 SP1 and SP2 and Office 2004 for Mac do not properly parse the Excel file Microsoft Office Excel 2007 SP1 and SP2 and Office 2004 for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet that triggers access of an uninitialized stack variable, aka "Microsoft Office Excel FNGROUPNAME Record Uninitialized Memory Vulnerability."
nvd
CVE-2013-3890P3CRITICALCVSS 9.3v20072013-10-09
CVE-2013-3890 [CRITICAL] CWE-119 CVE-2013-3890: Microsoft Excel 2007 SP3, Excel Viewer, and Office Compatibility Pack SP3 allow remote attackers to Microsoft Excel 2007 SP3, Excel Viewer, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Excel Memory Corruption Vulnerability."
nvd
CVE-2009-3132P3CRITICALCVSS 9.3v2002v2003+1 more2009-11-11
CVE-2009-3132 [CRITICAL] CWE-94 CVE-2009-3132: Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a spreadsh
nvd
CVE-2010-1249P3CRITICALCVSS 9.3v20022010-06-08
CVE-2010-1249 [CRITICAL] CVE-2010-1249: Buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Op Buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed ExternName (0x23) record, aka "Excel Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0823 and CVE-2010-1247.
nvd
Microsoft Excel vulnerabilities | cvebase