cbcvebase.

Microsoft Excel vulnerabilities

438 known vulnerabilities affecting microsoft/excel.

Total CVEs
438
CISA KEV
6
actively exploited
Public exploits
34
Exploited in wild
21
Severity breakdown
CRITICAL128HIGH250MEDIUM59LOW1

Vulnerabilities

Page 9 of 22
CVE-2016-7229P3HIGHCVSS 7.8v2007v2010+2 more2016-11-10
CVE-2016-7229 [HIGH] CWE-119 CVE-2016-7229: Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for M Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2020-1496P3HIGHCVSS 8.8v2010v2013+1 more2020-08-17
CVE-2020-1496 [HIGH] CVE-2020-1496: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affecte
nvd
CVE-2020-1494P3HIGHCVSS 8.8v2010v2013+1 more2020-08-17
CVE-2020-1494 [HIGH] CVE-2020-1494: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affecte
nvd
CVE-2020-1495P3HIGHCVSS 8.8v2010v2013+1 more2020-08-17
CVE-2020-1495 [HIGH] CVE-2020-1495: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affecte
nvd
CVE-2020-1504P3HIGHCVSS 8.8v20102020-08-17
CVE-2020-1504 [HIGH] CVE-2020-1504: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affecte
nvd
CVE-2018-8147P3HIGHCVSS 7.8v2010-sp2v2013-sp1+1 more2018-05-09
CVE-2018-8147 [HIGH] CVE-2018-8147: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Excel. This CVE ID is unique from CVE-2018-8148, CVE-2018-8162.
nvd
CVE-2018-8148P3HIGHCVSS 7.8v2010-sp2v2013-sp1+1 more2018-05-09
CVE-2018-8148 [HIGH] CVE-2018-8148: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Excel. This CVE ID is unique from CVE-2018-8147, CVE-2018-8162.
nvd
CVE-2018-8162P3HIGHCVSS 7.8v2010-sp2v2013-sp1+1 more2018-05-09
CVE-2018-8162 [HIGH] CVE-2018-8162: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Excel. This CVE ID is unique from CVE-2018-8147, CVE-2018-8148.
nvd
CVE-2020-1498P3HIGHCVSS 8.8v2010v2013+1 more2020-08-17
CVE-2020-1498 [HIGH] CVE-2020-1498: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affecte
nvd
CVE-2011-0103P3CRITICALCVSS 9.3v2002v20032011-04-13
CVE-2011-0103 [CRITICAL] CWE-119 CVE-2011-0103: Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Conver Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted record information in an Excel file, aka "Excel Memory Corruption Vulnerability."
nvd
CVE-2018-1029P3HIGHCVSS 7.8v2007v2010+2 more2018-04-12
CVE-2018-1029 [HIGH] CVE-2018-1029: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel. This CVE ID is unique from CVE-2018-0920, CVE-2018-1011, CVE-2018-1027.
nvd
CVE-2011-1273P3CRITICALCVSS 9.3v2002v2003+2 more2011-06-16
CVE-2011-1273 [CRITICAL] CWE-119 CVE-2011-1273: Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004, 2008, and 2011 for Mac; Open XM Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004, 2008, and 2011 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to e
nvd
CVE-2011-1279P3CRITICALCVSS 9.3v2002v20032011-06-16
CVE-2011-1279 [CRITICAL] CWE-119 CVE-2011-1279: Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Conver Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel Out of Bounds
nvd
CVE-2007-0028P3CRITICALCVSS 9.3v2000v2002+1 more2007-01-09
CVE-2007-0028 [CRITICAL] CVE-2007-0028: Microsoft Excel 2000, 2002, 2003, Viewer 2003, Office 2004 for Mac, and Office v.X for Mac does not Microsoft Excel 2000, 2002, 2003, Viewer 2003, Office 2004 for Mac, and Office v.X for Mac does not properly handle certain opcodes, which allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file, which results in an "Improper Memory Access Vulnerability." NOTE: an early disclosure of this issue used CVE-2006-3432, but only CVE-
nvd
CVE-2016-7231P3HIGHCVSS 7.8v20072016-11-10
CVE-2016-7231 [HIGH] CWE-119 CVE-2016-7231: Microsoft Excel 2007 SP3, Excel for Mac 2011, Office Compatibility Pack SP3, and Excel Viewer allow Microsoft Excel 2007 SP3, Excel for Mac 2011, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2020-1335P3HIGHCVSS 8.8v2010v2013+1 more2020-09-11
CVE-2020-1335 [HIGH] CVE-2020-1335: <p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affecte
nvd
CVE-2020-1594P3HIGHCVSS 8.8v2010v2013+1 more2020-09-11
CVE-2020-1594 [HIGH] CVE-2020-1594: <p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affecte
nvd
CVE-2020-1332P3HIGHCVSS 8.8v2010v2013+1 more2020-09-11
CVE-2020-1332 [HIGH] CVE-2020-1332: <p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affecte
nvd
CVE-2016-3361P3HIGHCVSS 7.8v20102016-09-14
CVE-2016-3361 [HIGH] CWE-119 CVE-2016-3361: Microsoft Excel 2010 SP2 allows remote attackers to execute arbitrary code via a crafted document, a Microsoft Excel 2010 SP2 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2015-2415P3CRITICALCVSS 9.3v2007v2010+1 more2015-07-14
CVE-2015-2415 [CRITICAL] CWE-119 CVE-2015-2415: Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, and Office Compatibilit Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
Microsoft Excel vulnerabilities | cvebase