cbcvebase.

Microsoft Office vulnerabilities

1,005 known vulnerabilities affecting microsoft/office.

Total CVEs
1,005
CISA KEV
35
actively exploited
Public exploits
103
Exploited in wild
68
Severity breakdown
CRITICAL277HIGH567MEDIUM155LOW6

Vulnerabilities

Page 11 of 51
CVE-2013-0006P3HIGHCVSS 8.8v2003v20072013-01-09
CVE-2013-0006 [HIGH] CWE-189 CVE-2013-0006: Microsoft XML Core Services (aka MSXML) 3.0, 5.0, and 6.0 does not properly parse XML content, which Microsoft XML Core Services (aka MSXML) 3.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML Integer Truncation Vulnerability."
nvd
CVE-2024-30103P2HIGHCVSS 8.8v20192024-06-11
CVE-2024-30103 [HIGH] CWE-184 CVE-2024-30103: Microsoft Outlook Remote Code Execution Vulnerability Microsoft Outlook Remote Code Execution Vulnerability
nvd
CVE-2008-3007P3CRITICALCVSS 9.3v2003v2007+1 more2008-09-11
CVE-2008-3007 [CRITICAL] CWE-20 CVE-2008-3007: Argument injection vulnerability in a URI handler in Microsoft Office XP SP3, 2003 SP2 and SP3, 2007 Argument injection vulnerability in a URI handler in Microsoft Office XP SP3, 2003 SP2 and SP3, 2007 Office System Gold and SP1, and Office OneNote 2007 Gold and SP1 allow remote attackers to execute arbitrary code via a crafted onenote:// URL, aka "Uniform Resource Locator Validation Error Vulnerability."
nvd
CVE-2018-0848P3HIGHCVSS 8.8v2007v2010+2 more2018-01-22
CVE-2018-0848 [HIGH] CVE-2018-0848: Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Of Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0805, CVE-2018-0806, and CVE-2018-0807.
nvd
CVE-2010-3945P3CRITICALCVSS 9.3v2003vxp2010-12-16
CVE-2010-3945 [CRITICAL] CWE-119 CVE-2010-3945: Buffer overflow in the CGM image converter in the graphics filters in Microsoft Office XP SP3, Offic Buffer overflow in the CGM image converter in the graphics filters in Microsoft Office XP SP3, Office 2003 SP3, and Office Converter Pack allows remote attackers to execute arbitrary code via a crafted CGM image in an Office document, aka "CGM Image Converter Buffer Overrun Vulnerability."
nvd
CVE-2018-0794P3HIGHCVSS 8.8v2010v20162018-01-10
CVE-2018-0794 [HIGH] CVE-2018-0794: Microsoft Word in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Microsoft Word in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0792.
nvd
CVE-2017-8528P3HIGHCVSS 8.8v2007v20102017-06-15
CVE-2017-8528 [HIGH] CVE-2017-8528: Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gol Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, Windows Server 2016, Microsoft Office 2007 SP3, and Microsoft Office 2010 SP2 allows a remote code execution vulnerability due to the way it handles objects in memory, aka "Windows Uniscribe Remote Code Execu
nvd
CVE-2018-1028P3HIGHCVSS 8.8v2013v2013_rt+1 more2018-04-12
CVE-2018-1028 [HIGH] CWE-94 CVE-2018-1028: A remote code execution vulnerability exists when the Office graphics component improperly handles s A remote code execution vulnerability exists when the Office graphics component improperly handles specially crafted embedded fonts, aka "Microsoft Office Graphics Remote Code Execution Vulnerability." This affects Word, Microsoft Office, Microsoft SharePoint, Excel, Microsoft SharePoint Server.
nvd
CVE-2008-3020P3CRITICALCVSS 9.3v2000v2003+1 more2008-08-12
CVE-2008-3020 [CRITICAL] CWE-399 CVE-2008-3020: Microsoft Office 2000 SP3 and XP SP3; Office Converter Pack; and Works 8 do not properly parse the l Microsoft Office 2000 SP3 and XP SP3; Office Converter Pack; and Works 8 do not properly parse the length of a BMP file, which allows remote attackers to execute arbitrary code via a crafted BMP file, aka the "Malformed BMP Filter Vulnerability."
nvd
CVE-2012-0184P3CRITICALCVSS 9.3v2008v20112012-05-09
CVE-2012-0184 [CRITICAL] CWE-264 CVE-2012-0184: Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2008 and 2011 for Mac; Exc Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2008 and 2011 for Mac; Excel Viewer; and Office Compatibility Pack SP2 and SP3 do not properly handle memory during the opening of files, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel SXLI Record Memory Corruption Vulnerability."
nvd
CVE-2008-3019P3CRITICALCVSS 9.3v2000v2003+1 more2008-08-12
CVE-2008-3019 [CRITICAL] CWE-399 CVE-2008-3019: Microsoft Office 2000 SP3, XP SP3, and 2003 SP2; Office Converter Pack; and Works 8 do not properly Microsoft Office 2000 SP3, XP SP3, and 2003 SP2; Office Converter Pack; and Works 8 do not properly parse the length of an Encapsulated PostScript (EPS) file, which allows remote attackers to execute arbitrary code via a crafted EPS file, aka the "Malformed EPS Filter Vulnerability."
nvd
CVE-2012-0177P3CRITICALCVSS 9.3v20072012-04-10
CVE-2012-0177 [CRITICAL] CWE-119 CVE-2012-0177: Heap-based buffer overflow in the Office Works File Converter in Microsoft Office 2007 SP2, Works 9, Heap-based buffer overflow in the Office Works File Converter in Microsoft Office 2007 SP2, Works 9, and Works 6-9 File Converter allows remote attackers to execute arbitrary code via a crafted Works (aka .wps) file, aka "Office WPS Converter Heap Overflow Vulnerability."
nvd
CVE-2025-47171P3MEDIUMCVSS 6.7PoCv20192025-06-10
CVE-2025-47171 [MEDIUM] CWE-20 CVE-2025-47171: Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally.
nvd
CVE-2018-8332P3HIGHCVSS 8.8v20162018-09-13
CVE-2018-8332 [HIGH] CVE-2018-8332: A remote code execution vulnerability exists when the Windows font library improperly handles specia A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Win32k Graphics Remote Code Execution Vulnerability." This affects Windows 7, Microsoft Office, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2008 R2, Windows Server 2012, Windows Server 2016, Windows
nvd
CVE-2017-8527P3HIGHCVSS 8.8v2007v20102017-06-15
CVE-2017-8527 [HIGH] CWE-119 CVE-2017-8527: Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to the way it handles objects in memory, aka "Windows Graphics Remote Code Execution Vulnerability".
nvd
CVE-2011-1272P2CRITICALCVSS 9.3v2004v20082011-06-16
CVE-2011-1272 [CRITICAL] CWE-20 CVE-2011-1272: Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 and 2008 for Mac; Open XML File Format Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 do not properly validate record structures during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrar
nvd
CVE-2014-4117P3CRITICALCVSS 9.3v2007v2010+1 more2014-10-15
CVE-2014-4117 [CRITICAL] CWE-20 CVE-2014-4117: Microsoft Office 2007 SP3, Word 2007 SP3, Office 2010 SP1 and SP2, Word 2010 SP1 and SP2, Office for Microsoft Office 2007 SP3, Word 2007 SP3, Office 2010 SP1 and SP2, Word 2010 SP1 and SP2, Office for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP1 and SP2, and Word Web Apps 2010 Gold, SP1, and SP2 allow remote attackers to execute arbitrary code via crafted properties in a Word document, aka "Microso
nvd
CVE-2010-1902P3CRITICALCVSS 9.3v2004v20082010-08-11
CVE-2010-1902 [CRITICAL] CWE-119 CVE-2010-1902: Buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2; Microsoft Office 2004 and Buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2; Microsoft Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Word Viewer; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 allows remote attackers to execute arbitrary code via unspecified properties in the data in
nvd
CVE-2018-0849P2HIGHCVSS 8.8v2007v2010+2 more2018-01-22
CVE-2018-0849 [HIGH] CVE-2018-0849: Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Of Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0805, CVE-2018-0806, and CVE-2018-0807.
nvd
CVE-2018-0862P2HIGHCVSS 8.8v2007v2010+2 more2018-01-22
CVE-2018-0862 [HIGH] CVE-2018-0862: Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Of Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0805, CVE-2018-0806, and CVE-2018-0807.
nvd
Microsoft Office vulnerabilities | cvebase