cbcvebase.

Microsoft Office vulnerabilities

1,005 known vulnerabilities affecting microsoft/office.

Total CVEs
1,005
CISA KEV
35
actively exploited
Public exploits
103
Exploited in wild
68
Severity breakdown
CRITICAL277HIGH567MEDIUM155LOW6

Vulnerabilities

Page 14 of 51
CVE-2009-3132P3CRITICALCVSS 9.3v2004v20082009-11-11
CVE-2009-3132 [CRITICAL] CWE-94 CVE-2009-3132: Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a spreadsh
nvd
CVE-2008-0119P3CRITICALCVSS 9.3v2000v2003+3 more2008-05-13
CVE-2008-0119 [CRITICAL] CWE-94 CVE-2008-0119: Unspecified vulnerability in Microsoft Publisher in Office 2000 and XP SP3, 2003 SP2 and SP3, and 20 Unspecified vulnerability in Microsoft Publisher in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 SP1 and earlier allows remote attackers to execute arbitrary code via a Publisher file with crafted object header data that triggers memory corruption, aka "Publisher Object Handler Validation Vulnerability."
nvd
CVE-2010-1249P3CRITICALCVSS 9.3v2004v20082010-06-08
CVE-2010-1249 [CRITICAL] CVE-2010-1249: Buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Op Buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed ExternName (0x23) record, aka "Excel Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0823 and CVE-2010-1247.
nvd
CVE-2010-0821P3CRITICALCVSS 9.3v2004v20082010-06-08
CVE-2010-0821 [CRITICAL] CWE-94 CVE-2010-0821: Unspecified vulnerability in Microsoft Office Excel 2002 SP3, 2003 SP3, 2007 SP1 and SP2; Office 200 Unspecified vulnerability in Microsoft Office Excel 2002 SP3, 2003 SP3, 2007 SP1 and SP2; Office 2004 for mac; Office 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2; allows remote attackers to execute arbitrary code via
nvd
CVE-2018-0795P3HIGHCVSS 8.8v2010v20162018-01-10
CVE-2018-0795 [HIGH] CVE-2018-0795: Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code executio Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Remote Code Execution Vulnerability".
nvd
CVE-2010-3335P3CRITICALCVSS 9.3v2003v2004+5 more2010-11-10
CVE-2010-3335 [CRITICAL] CWE-119 CVE-2010-3335: Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "Drawing Exception Handling Vulnerability."
nvd
CVE-2010-1250P3CRITICALCVSS 9.3v2004v20082010-06-08
CVE-2010-1250 [CRITICAL] CWE-94 CVE-2010-1250: Heap-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Heap-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with malformed (1) EDG (0x88) and (2) Publisher (0x89) records, aka "Excel EDG Memory Corruption Vulnerability."
nvd
CVE-2009-3130P3CRITICALCVSS 9.3v2004v20082009-11-11
CVE-2009-3130 [CRITICAL] CWE-119 CVE-2009-3130: Heap-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Ope Heap-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via a spreadsheet containing a malformed Binary File Format (aka BIFF) record that triggers memory corruption, aka "Excel Document Parsing Heap Overflow Vulnerabilit
nvd
CVE-2013-3129P3HIGHCVSS 7.8v2003v2007+1 more2013-07-10
CVE-2013-3129 [HIGH] CWE-94 CVE-2013-3129: Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 before 5.1.20513.0; win32k.s Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 before 5.1.20513.0; win32k.sys in the kernel-mode drivers, and GDI+, DirectWrite, and Journal, in Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT; GDI+ in Office 2003
nvd
CVE-2015-1760P3CRITICALCVSS 9.3v2010v20132015-06-10
CVE-2015-1760 [CRITICAL] CWE-19 CVE-2015-1760: Microsoft Office Compatibility Pack SP3, Office 2010 SP2, Office 2013 SP1, and Office 2013 RT SP1 al Microsoft Office Compatibility Pack SP3, Office 2010 SP2, Office 2013 SP1, and Office 2013 RT SP1 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2015-0063P3CRITICALCVSS 9.3v20102015-02-11
CVE-2015-0063 [CRITICAL] CWE-399 CVE-2015-0063: Microsoft Excel 2007 SP3; the proofing tools in Office 2010 SP2; Excel 2010 SP2; Excel 2013 Gold, SP Microsoft Excel 2007 SP3; the proofing tools in Office 2010 SP2; Excel 2010 SP2; Excel 2013 Gold, SP1, and RT; Excel Viewer; and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Excel Remote Code Execution Vulnerability."
nvd
CVE-2010-3236P3CRITICALCVSS 9.3v2004v20082010-10-13
CVE-2010-3236 [CRITICAL] CWE-20 CVE-2010-3236: Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Conver Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Out Of Bounds Array Vulnerability."
nvd
CVE-2010-3237P3CRITICALCVSS 9.3v20042010-10-13
CVE-2010-3237 [CRITICAL] CWE-20 CVE-2010-3237: Microsoft Excel 2002 SP3 and Office 2004 for Mac do not properly validate record information, which Microsoft Excel 2002 SP3 and Office 2004 for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Merge Cell Record Pointer Vulnerability."
nvd
CVE-2010-3238P3CRITICALCVSS 9.3v20042010-10-13
CVE-2010-3238 [CRITICAL] CWE-20 CVE-2010-3238: Microsoft Excel 2002 SP3 and 2003 SP3, and Office 2004 for Mac, does not properly validate binary fi Microsoft Excel 2002 SP3 and 2003 SP3, and Office 2004 for Mac, does not properly validate binary file-format information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Negative Future Function Vulnerability."
nvd
CVE-2010-1252P3CRITICALCVSS 9.3v20042010-06-08
CVE-2010-1252 [CRITICAL] CWE-94 CVE-2010-1252: Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote a Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Excel file, aka "Excel String Variable Vulnerability."
nvd
CVE-2010-1251P3CRITICALCVSS 9.3v20042010-06-08
CVE-2010-1251 [CRITICAL] CWE-94 CVE-2010-1251: Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote a Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Excel file, aka "Excel Record Stack Corruption Vulnerability."
nvd
CVE-2010-0264P3CRITICALCVSS 9.3v2004v20082010-03-10
CVE-2010-0264 [CRITICAL] CWE-94 CVE-2010-0264: Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter fo Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Microsoft Office Excel DbOrParamQry Record Parsing Vulnerability."
nvd
CVE-2010-0031P3CRITICALCVSS 9.3v20042010-02-10
CVE-2010-0031 [CRITICAL] CWE-94 CVE-2010-0031: Array index error in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3, and PowerPoint in Office 200 Array index error in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3, and PowerPoint in Office 2004 for Mac, allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint OEPlaceholderAtom 'placementId' Invalid Array Indexing Vulnerability."
nvd
CVE-2010-3215P3CRITICALCVSS 9.3v20042010-10-13
CVE-2010-3215 [CRITICAL] CWE-94 CVE-2010-3215: Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly handle unspecified return values dur Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly handle unspecified return values during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Return Value Vulnerability."
nvd
CVE-2010-2750P3CRITICALCVSS 9.3v20042010-10-13
CVE-2010-2750 [CRITICAL] CWE-94 CVE-2010-2750: Array index error in Microsoft Word 2002 SP3 and Office 2004 for Mac allows remote attackers to exec Array index error in Microsoft Word 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Word document that triggers memory corruption, aka "Word Index Vulnerability."
nvd
Microsoft Office vulnerabilities | cvebase