Microsoft Office vulnerabilities
1,005 known vulnerabilities affecting microsoft/office.
Total CVEs
1,005
CISA KEV
35
actively exploited
Public exploits
103
Exploited in wild
68
Severity breakdown
CRITICAL277HIGH567MEDIUM155LOW6
Vulnerabilities
Page 16 of 51
CVE-2008-4266P3CRITICALCVSS 9.3v2004v20082008-12-10
CVE-2008-4266 [CRITICAL] CWE-399 CVE-2008-4266: Array index vulnerability in Microsoft Office Excel 2000 SP3, 2002 SP3, and 2003 SP3; Excel Viewer 2
Array index vulnerability in Microsoft Office Excel 2000 SP3, 2002 SP3, and 2003 SP3; Excel Viewer 2003 Gold and SP3; Office 2004 and 2008 for Mac; and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via an Excel spreadsheet with a NAME record that contains an invalid index value, which triggers stack corrupti
nvd
CVE-2010-3242P3CRITICALCVSS 9.3v2004v20082010-10-13
CVE-2010-3242 [CRITICAL] CWE-20 CVE-2010-3242: Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac d
Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Ghost Record Type Parsing Vulnerability."
nvd
CVE-2010-2747P3CRITICALCVSS 9.3v20042010-10-13
CVE-2010-2747 [CRITICAL] CWE-94 CVE-2010-2747: Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly handle an uninitialized pointer duri
Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly handle an uninitialized pointer during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Uninitialized Pointer Vulnerability."
nvd
CVE-2011-3403P3CRITICALCVSS 9.3v20042011-12-14
CVE-2011-3403 [CRITICAL] CWE-94 CVE-2011-3403: Microsoft Excel 2003 SP3 and Office 2004 for Mac do not properly handle objects in memory, which all
Microsoft Excel 2003 SP3 and Office 2004 for Mac do not properly handle objects in memory, which allows remote attackers to execute arbitrary code via a crafted Excel spreadsheet, aka "Record Memory Corruption Vulnerability."
nvd
CVE-2015-6092P3CRITICALCVSS 9.3v20102015-11-11
CVE-2015-6092 [CRITICAL] CWE-119 CVE-2015-6092: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016,
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2010-2748P3CRITICALCVSS 9.3v20042010-10-13
CVE-2010-2748 [CRITICAL] CWE-94 CVE-2010-2748: Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly check an unspecified boundary during
Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly check an unspecified boundary during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Boundary Check Vulnerability."
nvd
CVE-2015-1683P3CRITICALCVSS 9.3v20072015-05-13
CVE-2015-1683 [CRITICAL] CWE-119 CVE-2015-1683: Microsoft Office 2007 SP3 allows remote attackers to execute arbitrary code via a crafted document,
Microsoft Office 2007 SP3 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2012-1887P3CRITICALCVSS 9.3v2008v20112012-11-14
CVE-2012-1887 [CRITICAL] CWE-399 CVE-2012-1887: Use-after-free vulnerability in Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 SP1, and Office
Use-after-free vulnerability in Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 SP1, and Office 2008 and 2011 for Mac, allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel SST Invalid Length Use After Free Vulnerability."
nvd
CVE-2017-0014P3HIGHCVSS 7.5v20102017-03-17
CVE-2017-0014 [HIGH] CVE-2017-0014: The Windows Graphics Component in Microsoft Office 2010 SP2; Windows Server 2008 R2 SP1; Windows 7 S
The Windows Graphics Component in Microsoft Office 2010 SP2; Windows Server 2008 R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Graphics Component Remote Code Execution Vulnerabilit
nvd
CVE-2009-3127P3CRITICALCVSS 9.3v2004v20082009-11-11
CVE-2009-3127 [CRITICAL] CWE-94 CVE-2009-3127: Microsoft Office Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, Open XML File Format Con
Microsoft Office Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, Open XML File Format Converter for Mac, and Office Excel Viewer 2003 SP3 do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Cache Memory Corruption Vulnerability."
nvd
CVE-2022-41106P3HIGHCVSS 8.8v20192022-11-09
CVE-2022-41106 [HIGH] CVE-2022-41106: Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2010-0257P3CRITICALCVSS 9.3v2004v20082010-03-10
CVE-2010-0257 [CRITICAL] CWE-94 CVE-2010-0257: Microsoft Office Excel 2002 SP3 does not properly parse the Excel file format, which allows remote a
Microsoft Office Excel 2002 SP3 does not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Microsoft Office Excel Record Memory Corruption Vulnerability."
nvd
CVE-2019-1205P3CRITICALCVSS 9.8v2016v20192019-08-14
CVE-2019-1205 [CRITICAL] CVE-2019-1205: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. The file could then take actions on behalf of the logged-on user with the same
nvd
CVE-2006-0002P3HIGHCVSS 7.5v2000v2003+1 more2006-01-10
CVE-2006-0002 [HIGH] CVE-2006-0002: Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP
Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.
nvd
CVE-2006-3493P4MEDIUMCVSS 5.1PoCv2000v2003+1 more2006-07-10
CVE-2006-3493 [MEDIUM] CVE-2006-3493: Buffer overflow in LsCreateLine function (mso_203) in mso.dll and mso9.dll, as used by Microsoft Wor
Buffer overflow in LsCreateLine function (mso_203) in mso.dll and mso9.dll, as used by Microsoft Word and possibly other products in Microsoft Office 2003, 2002, and 2000, allows remote user-assisted attackers to cause a denial of service (crash) via a crafted Word DOC or other Office file type. NOTE: this issue was originally reported to allow code execution
nvd
CVE-2009-2518P3CRITICALCVSS 9.3vxp2009-10-14
CVE-2009-2518 [CRITICAL] CWE-189 CVE-2009-2518: Integer overflow in GDI+ in Microsoft Office XP SP3 allows remote attackers to execute arbitrary cod
Integer overflow in GDI+ in Microsoft Office XP SP3 allows remote attackers to execute arbitrary code via an Office document with a bitmap (aka BMP) image that triggers memory corruption, aka "Office BMP Integer Overflow Vulnerability."
nvd
CVE-2011-0655P3CRITICALCVSS 9.3v2004v2008+1 more2011-04-13
CVE-2011-0655 [CRITICAL] CWE-20 CVE-2011-0655: Microsoft PowerPoint 2007 SP2 and 2010; Office 2004, 2008, and 2011 for Mac; Open XML File Format Co
Microsoft PowerPoint 2007 SP2 and 2010; Office 2004, 2008, and 2011 for Mac; Open XML File Format Converter for Mac; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; PowerPoint Viewer; PowerPoint Viewer 2007 SP2; and PowerPoint Web App do not properly validate TimeColorBehaviorContainer Floating Point records in PowerP
nvd
CVE-2016-3282P3HIGHCVSS 7.8v20102016-07-13
CVE-2016-3282 [HIGH] CWE-119 CVE-2016-3282: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016,
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1, SharePoint Server 2016, Office Web Apps 2010 SP2, Office Web
nvd
CVE-2020-1321P3HIGHCVSS 8.8v2016v20192020-06-09
CVE-2020-1321 [HIGH] CVE-2020-1321: A remote code execution vulnerability exists in Microsoft Office software when it fails to properly
A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory, aka 'Microsoft Office Remote Code Execution Vulnerability'.
nvd
CVE-2014-6364P3CRITICALCVSS 9.3v2007v2010+1 more2014-12-11
CVE-2014-6364 [CRITICAL] CVE-2014-6364: Use-after-free vulnerability in Microsoft Office 2007 SP3; 2010 SP2; 2013 Gold, SP1, and SP2; and 20
Use-after-free vulnerability in Microsoft Office 2007 SP3; 2010 SP2; 2013 Gold, SP1, and SP2; and 2013 RT Gold and SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Component Use After Free Vulnerability."
nvd