Microsoft Office vulnerabilities
1,005 known vulnerabilities affecting microsoft/office.
Total CVEs
1,005
CISA KEV
35
actively exploited
Public exploits
103
Exploited in wild
68
Severity breakdown
CRITICAL277HIGH567MEDIUM155LOW6
Vulnerabilities
Page 15 of 51
CVE-2010-2573P3CRITICALCVSS 9.3v20042010-11-10
CVE-2010-2573 [CRITICAL] CWE-189 CVE-2010-2573: Integer underflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3, PowerPoint Viewer SP2, and Office 2
Integer underflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3, PowerPoint Viewer SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint Integer Underflow Causes Heap Corruption Vulnerability."
nvd
CVE-2016-3396P3HIGHCVSS 7.8v2007v20102016-10-14
CVE-2016-3396 [HIGH] CWE-264 CVE-2016-3396: Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2
Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live Meeting
nvd
CVE-2010-0823P3CRITICALCVSS 9.3v2004v20082010-06-08
CVE-2010-0823 [CRITICAL] CWE-94 CVE-2010-0823: Unspecified vulnerability in Microsoft Office Excel 2002 SP3, 2003 SP3, 2007 SP1 and SP2; Office 200
Unspecified vulnerability in Microsoft Office Excel 2002 SP3, 2003 SP3, 2007 SP1 and SP2; Office 2004 for mac; Office 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2; allows remote attackers to execute arbitrary code via
nvd
CVE-2008-0110P3CRITICALCVSS 9.3v2000v2003+2 more2008-03-11
CVE-2008-0110 [CRITICAL] CWE-94 CVE-2008-0110: Unspecified vulnerability in Microsoft Outlook in Office 2000 SP3, XP SP3, 2003 SP2 and Sp3, and Off
Unspecified vulnerability in Microsoft Outlook in Office 2000 SP3, XP SP3, 2003 SP2 and Sp3, and Office System allows user-assisted remote attackers to execute arbitrary code via a crafted mailto URI.
nvd
CVE-2010-3221P3CRITICALCVSS 9.3v20042010-10-13
CVE-2010-3221 [CRITICAL] CWE-94 CVE-2010-3221: Microsoft Word 2002 SP3 and 2003 SP3, Office 2004 for Mac, and Word Viewer do not properly handle a
Microsoft Word 2002 SP3 and 2003 SP3, Office 2004 for Mac, and Word Viewer do not properly handle a malformed record during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Parsing Vulnerability."
nvd
CVE-2010-3220P3CRITICALCVSS 9.3v20042010-10-13
CVE-2010-3220 [CRITICAL] CWE-94 CVE-2010-3220: Unspecified vulnerability in Microsoft Word 2002 SP3 and Office 2004 for Mac allows remote attackers
Unspecified vulnerability in Microsoft Word 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Word document that triggers memory corruption, aka "Word Parsing Vulnerability."
nvd
CVE-2008-4264P3CRITICALCVSS 9.3v2004v20082008-12-10
CVE-2008-4264 [CRITICAL] CWE-399 CVE-2008-4264: Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Excel Viewer 2003 Gold a
Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; Office 2004 and 2008 for Mac; and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a crafted Exc
nvd
CVE-2006-1311P3CRITICALCVSS 9.3v2000v2003+1 more2007-02-13
CVE-2006-1311 [CRITICAL] CVE-2006-1311: The RichEdit component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1; Office 2000 SP3, XP SP3,
The RichEdit component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1; Office 2000 SP3, XP SP3, 2003 SP2, and Office 2004 for Mac; and Learning Essentials for Microsoft Office 1.0, 1.1, and 1.5 allows user-assisted remote attackers to execute arbitrary code via a malformed OLE object in an RTF file, which triggers memory corruption.
nvd
CVE-2009-0558P3CRITICALCVSS 9.3v2004v2008+1 more2009-06-10
CVE-2009-0558 [CRITICAL] CWE-94 CVE-2009-0558: Array index error in Excel in Microsoft Office 2000 SP3 and Office 2004 and 2008 for Mac, and Open X
Array index error in Excel in Microsoft Office 2000 SP3 and Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac, allows remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Array Indexing Memory Corruption Vulnerability."
nvd
CVE-2009-2502P3HIGHCVSS 8.1v2003v2007+1 more2009-10-14
CVE-2009-2502 [HIGH] CWE-119 CVE-2009-2502: Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3,
Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, an
nvd
CVE-2009-3128P3CRITICALCVSS 9.3v2004v20082009-11-11
CVE-2009-3128 [CRITICAL] CWE-94 CVE-2009-3128: Microsoft Office Excel 2002 SP3 and 2003 SP3, and Office Excel Viewer 2003 SP3, does not properly pa
Microsoft Office Excel 2002 SP3 and 2003 SP3, and Office Excel Viewer 2003 SP3, does not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a spreadsheet with a malformed record object, aka "Excel SxView Memory Corruption Vulnerability."
nvd
CVE-2009-3131P3CRITICALCVSS 9.3v2004v20082009-11-11
CVE-2009-3131 [CRITICAL] CWE-94 CVE-2009-3131: Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open
Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a spreadsh
nvd
CVE-2008-0109P3CRITICALCVSS 9.3v2000v2003+1 more2008-02-12
CVE-2008-0109 [CRITICAL] CWE-399 CVE-2008-0109: Word in Microsoft Office 2000 SP3, XP SP3, Office 2003 SP2, and Office Word Viewer 2003 allows remot
Word in Microsoft Office 2000 SP3, XP SP3, Office 2003 SP2, and Office Word Viewer 2003 allows remote attackers to execute arbitrary code via crafted fields within the File Information Block (FIB) of a Word file, which triggers length calculation errors and memory corruption.
nvd
CVE-2013-0082P3CRITICALCVSS 9.3v2003v20072013-11-13
CVE-2013-0082 [CRITICAL] CWE-119 CVE-2013-0082: Microsoft Office 2003 SP3 and 2007 SP3 allows remote attackers to execute arbitrary code via a craft
Microsoft Office 2003 SP3 and 2007 SP3 allows remote attackers to execute arbitrary code via a crafted WordPerfect document (.wpd) file, aka "WPD File Format Memory Corruption Vulnerability."
nvd
CVE-2010-0243P3CRITICALCVSS 9.3v2004vxp2010-02-10
CVE-2010-0243 [CRITICAL] CWE-119 CVE-2010-0243: Buffer overflow in MSO.DLL in Microsoft Office XP SP3 and Office 2004 for Mac allows remote attacker
Buffer overflow in MSO.DLL in Microsoft Office XP SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Office document, aka "MSO.DLL Buffer Overflow."
nvd
CVE-2011-0656P3CRITICALCVSS 9.3v2004v2008+1 more2011-04-13
CVE-2011-0656 [CRITICAL] CWE-20 CVE-2011-0656: Microsoft PowerPoint 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004, 2008, and 2011 for Mac; Op
Microsoft PowerPoint 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004, 2008, and 2011 for Mac; Open XML File Format Converter for Mac; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; PowerPoint Viewer; PowerPoint Viewer 2007 SP2; and PowerPoint Web App do not properly validate PersistDirectoryEntry records in Power
nvd
CVE-2009-0559P3CRITICALCVSS 9.3v2004v2008+1 more2009-06-10
CVE-2009-0559 [CRITICAL] CWE-94 CVE-2009-0559: Stack-based buffer overflow in Excel in Microsoft Office 2000 SP3 and Office XP SP3 allows remote at
Stack-based buffer overflow in Excel in Microsoft Office 2000 SP3 and Office XP SP3 allows remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "String Copy Stack-Based Overrun Vulnerability."
nvd
CVE-2008-4030P3CRITICALCVSS 9.3v2004v20082008-12-10
CVE-2008-4030 [CRITICAL] CVE-2008-4030: Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Outlook 2007 Gold and SP1
Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Outlook 2007 Gold and SP1; Word Viewer 2003 Gold and SP3; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1 allow remote attackers to execute arbitrary code via crafted control words in (1) an RTF file or (2) a rich text e-mail message, whic
nvd
CVE-2008-0104P3CRITICALCVSS 9.3v2000v2003+1 more2008-02-12
CVE-2008-0104 [CRITICAL] CWE-94 CVE-2008-0104: Unspecified vulnerability in Microsoft Office Publisher 2000, 2002, and 2003 SP2 allows remote attac
Unspecified vulnerability in Microsoft Office Publisher 2000, 2002, and 2003 SP2 allows remote attackers to execute arbitrary code via a crafted .pub file, aka "Publisher Memory Corruption Vulnerability."
nvd
CVE-2017-8509P3HIGHCVSS 8.8v2007v2010+2 more2017-06-15
CVE-2017-8509 [HIGH] CVE-2017-8509: A remote code execution vulnerability exists in Microsoft Office when the software fails to properly
A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8510, CVE-2017-8511, CVE-2017-8512, CVE-2017-0260, and CVE-2017-8506.
nvd