Microsoft Excel vulnerabilities
438 known vulnerabilities affecting microsoft/excel.
Total CVEs
438
CISA KEV
6
actively exploited
Public exploits
34
Exploited in wild
21
Severity breakdown
CRITICAL128HIGH250MEDIUM59LOW1
Vulnerabilities
Page 6 of 22
CVE-2010-0821P3CRITICALCVSS 9.3v2002v2003+1 more2010-06-08
CVE-2010-0821 [CRITICAL] CWE-94 CVE-2010-0821: Unspecified vulnerability in Microsoft Office Excel 2002 SP3, 2003 SP3, 2007 SP1 and SP2; Office 200
Unspecified vulnerability in Microsoft Office Excel 2002 SP3, 2003 SP3, 2007 SP1 and SP2; Office 2004 for mac; Office 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2; allows remote attackers to execute arbitrary code via
nvd
CVE-2010-1250P3CRITICALCVSS 9.3v20022010-06-08
CVE-2010-1250 [CRITICAL] CWE-94 CVE-2010-1250: Heap-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for
Heap-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with malformed (1) EDG (0x88) and (2) Publisher (0x89) records, aka "Excel EDG Memory Corruption Vulnerability."
nvd
CVE-2009-3130P3CRITICALCVSS 9.3v2002v2003+1 more2009-11-11
CVE-2009-3130 [CRITICAL] CWE-119 CVE-2009-3130: Heap-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Ope
Heap-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via a spreadsheet containing a malformed Binary File Format (aka BIFF) record that triggers memory corruption, aka "Excel Document Parsing Heap Overflow Vulnerabilit
nvd
CVE-2015-0063P3CRITICALCVSS 9.3v2007v2010+1 more2015-02-11
CVE-2015-0063 [CRITICAL] CWE-399 CVE-2015-0063: Microsoft Excel 2007 SP3; the proofing tools in Office 2010 SP2; Excel 2010 SP2; Excel 2013 Gold, SP
Microsoft Excel 2007 SP3; the proofing tools in Office 2010 SP2; Excel 2010 SP2; Excel 2013 Gold, SP1, and RT; Excel Viewer; and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Excel Remote Code Execution Vulnerability."
nvd
CVE-2010-3236P3CRITICALCVSS 9.3v2002v20032010-10-13
CVE-2010-3236 [CRITICAL] CWE-20 CVE-2010-3236: Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Conver
Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Out Of Bounds Array Vulnerability."
nvd
CVE-2010-3237P3CRITICALCVSS 9.3v20022010-10-13
CVE-2010-3237 [CRITICAL] CWE-20 CVE-2010-3237: Microsoft Excel 2002 SP3 and Office 2004 for Mac do not properly validate record information, which
Microsoft Excel 2002 SP3 and Office 2004 for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Merge Cell Record Pointer Vulnerability."
nvd
CVE-2010-3238P3CRITICALCVSS 9.3v2002v20032010-10-13
CVE-2010-3238 [CRITICAL] CWE-20 CVE-2010-3238: Microsoft Excel 2002 SP3 and 2003 SP3, and Office 2004 for Mac, does not properly validate binary fi
Microsoft Excel 2002 SP3 and 2003 SP3, and Office 2004 for Mac, does not properly validate binary file-format information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Negative Future Function Vulnerability."
nvd
CVE-2010-1252P3CRITICALCVSS 9.3v20022010-06-08
CVE-2010-1252 [CRITICAL] CWE-94 CVE-2010-1252: Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote a
Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Excel file, aka "Excel String Variable Vulnerability."
nvd
CVE-2010-1251P3CRITICALCVSS 9.3v20022010-06-08
CVE-2010-1251 [CRITICAL] CWE-94 CVE-2010-1251: Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote a
Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Excel file, aka "Excel Record Stack Corruption Vulnerability."
nvd
CVE-2010-0264P3CRITICALCVSS 9.3v2002v2003+1 more2010-03-10
CVE-2010-0264 [CRITICAL] CWE-94 CVE-2010-0264: Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter fo
Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Microsoft Office Excel DbOrParamQry Record Parsing Vulnerability."
nvd
CVE-2010-3230P3CRITICALCVSS 9.3v20022010-10-13
CVE-2010-3230 [CRITICAL] CWE-189 CVE-2010-3230: Integer overflow in Microsoft Excel 2002 SP3 allows remote attackers to execute arbitrary code via a
Integer overflow in Microsoft Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel document with crafted record information, aka "Excel Record Parsing Integer Overflow Vulnerability."
nvd
CVE-2010-0823P3CRITICALCVSS 9.3v2002v2003+1 more2010-06-08
CVE-2010-0823 [CRITICAL] CWE-94 CVE-2010-0823: Unspecified vulnerability in Microsoft Office Excel 2002 SP3, 2003 SP3, 2007 SP1 and SP2; Office 200
Unspecified vulnerability in Microsoft Office Excel 2002 SP3, 2003 SP3, 2007 SP1 and SP2; Office 2004 for mac; Office 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2; allows remote attackers to execute arbitrary code via
nvd
CVE-2009-3128P3CRITICALCVSS 9.3v2002v2003+1 more2009-11-11
CVE-2009-3128 [CRITICAL] CWE-94 CVE-2009-3128: Microsoft Office Excel 2002 SP3 and 2003 SP3, and Office Excel Viewer 2003 SP3, does not properly pa
Microsoft Office Excel 2002 SP3 and 2003 SP3, and Office Excel Viewer 2003 SP3, does not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a spreadsheet with a malformed record object, aka "Excel SxView Memory Corruption Vulnerability."
nvd
CVE-2009-3131P3CRITICALCVSS 9.3v2002v2003+1 more2009-11-11
CVE-2009-3131 [CRITICAL] CWE-94 CVE-2009-3131: Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open
Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a spreadsh
nvd
CVE-2008-4266P3CRITICALCVSS 9.3v2000v2002+1 more2008-12-10
CVE-2008-4266 [CRITICAL] CWE-399 CVE-2008-4266: Array index vulnerability in Microsoft Office Excel 2000 SP3, 2002 SP3, and 2003 SP3; Excel Viewer 2
Array index vulnerability in Microsoft Office Excel 2000 SP3, 2002 SP3, and 2003 SP3; Excel Viewer 2003 Gold and SP3; Office 2004 and 2008 for Mac; and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via an Excel spreadsheet with a NAME record that contains an invalid index value, which triggers stack corrupti
nvd
CVE-2010-3242P3CRITICALCVSS 9.3v20022010-10-13
CVE-2010-3242 [CRITICAL] CWE-20 CVE-2010-3242: Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac d
Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Ghost Record Type Parsing Vulnerability."
nvd
CVE-2011-3403P3CRITICALCVSS 9.3v20032011-12-14
CVE-2011-3403 [CRITICAL] CWE-94 CVE-2011-3403: Microsoft Excel 2003 SP3 and Office 2004 for Mac do not properly handle objects in memory, which all
Microsoft Excel 2003 SP3 and Office 2004 for Mac do not properly handle objects in memory, which allows remote attackers to execute arbitrary code via a crafted Excel spreadsheet, aka "Record Memory Corruption Vulnerability."
nvd
CVE-2010-3234P3CRITICALCVSS 9.3v20022010-10-13
CVE-2010-3234 [CRITICAL] CWE-20 CVE-2010-3234: Microsoft Excel 2002 SP3 does not properly validate formula information, which allows remote attacke
Microsoft Excel 2002 SP3 does not properly validate formula information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Formula Substream Memory Corruption Vulnerability."
nvd
CVE-2020-0759P3HIGHCVSS 8.8v2010v2013+2 more2020-02-11
CVE-2020-0759 [HIGH] CVE-2020-0759: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.
nvd
CVE-2012-1887P3CRITICALCVSS 9.3v2003v2007+1 more2012-11-14
CVE-2012-1887 [CRITICAL] CWE-399 CVE-2012-1887: Use-after-free vulnerability in Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 SP1, and Office
Use-after-free vulnerability in Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 SP1, and Office 2008 and 2011 for Mac, allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel SST Invalid Length Use After Free Vulnerability."
nvd