Microsoft Office vulnerabilities
1,005 known vulnerabilities affecting microsoft/office.
Total CVEs
1,005
CISA KEV
35
actively exploited
Public exploits
103
Exploited in wild
68
Severity breakdown
CRITICAL277HIGH567MEDIUM155LOW6
Vulnerabilities
Page 17 of 51
CVE-2015-6091P3CRITICALCVSS 9.3v20102015-11-11
CVE-2015-6091 [CRITICAL] CWE-119 CVE-2015-6091: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016,
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, and Word Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2014-6357P3CRITICALCVSS 9.3v2010v2011+1 more2014-12-11
CVE-2014-6357 [CRITICAL] CVE-2014-6357: Use-after-free vulnerability in Microsoft Office 2010 SP2, Office 2013 Gold and SP1, Office 2013 RT
Use-after-free vulnerability in Microsoft Office 2010 SP2, Office 2013 Gold and SP1, Office 2013 RT Gold and SP1, Office for Mac 2011, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 Gold and SP1, and Office Web Apps 2010 SP2 and 2013 Gold and SP1 allows remote attackers to execute arbitrary code vi
nvd
CVE-2026-40364P3HIGHCVSS 8.4v20192026-05-12
CVE-2026-40364 [HIGH] CWE-122 CVE-2026-40364: Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an una
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2008-1090P3CRITICALCVSS 9.3v2003v2007+2 more2008-04-08
CVE-2008-1090 [CRITICAL] CWE-399 CVE-2008-1090: Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows u
Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows user-assisted remote attackers to execute arbitrary code via a crafted .DXF file, aka "Visio Memory Validation Vulnerability."
nvd
CVE-2008-1089P3CRITICALCVSS 9.3v2003v2007+2 more2008-04-08
CVE-2008-1089 [CRITICAL] CWE-94 CVE-2008-1089: Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows u
Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows user-assisted remote attackers to execute arbitrary code via a Visio file containing crafted object header data, aka "Visio Object Header Vulnerability."
nvd
CVE-2019-1449P3CRITICALCVSS 9.8v20192019-11-12
CVE-2019-1449 [CRITICAL] CVE-2019-1449: A security feature bypass vulnerability exists in the way that Office Click-to-Run (C2R) components
A security feature bypass vulnerability exists in the way that Office Click-to-Run (C2R) components handle a specially crafted file, which could lead to a standard user, any AppContainer sandbox, and Office LPAC Protected View to escalate privileges to SYSTEM.To exploit this bug, an attacker would have to run a specially crafted file, aka 'Microsoft Office C
nvd
CVE-2007-0027P3CRITICALCVSS 9.3v2000vxp+3 more2007-01-09
CVE-2007-0027 [CRITICAL] CVE-2007-0027: Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows remote attackers
Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via malformed IMDATA records that trigger memory corruption.
nvd
CVE-2009-3133P3CRITICALCVSS 9.3v2004v20082009-11-11
CVE-2009-3133 [CRITICAL] CWE-94 CVE-2009-3133: Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter fo
Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a spreadsheet containing a malformed object that triggers memory corruption, related to "loading Excel records," aka "Excel Document Parsing Memory Corruption Vulnerability."
nvd
CVE-2021-28455P3HIGHCVSS 8.8v2013v2016+1 more2021-05-11
CVE-2021-28455 [HIGH] CVE-2021-28455: Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability
nvd
CVE-2016-7277P3CRITICALCVSS 9.6v20162016-12-20
CVE-2016-7277 [CRITICAL] CWE-119 CVE-2016-7277: Microsoft Office 2016 allows remote attackers to execute arbitrary code or cause a denial of service
Microsoft Office 2016 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2007-0208P3CRITICALCVSS 9.3v2000v2003+2 more2007-02-13
CVE-2007-0208 [CRITICAL] CWE-20 CVE-2007-0208: Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 200
Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac does not correctly check the properties of certain documents and warn the user of macro content, which allows user-assisted remote attackers to execute arbitrary code.
nvd
CVE-2008-0103P3CRITICALCVSS 9.3v2000v2003+2 more2008-02-13
CVE-2008-0103 [CRITICAL] CWE-399 CVE-2008-0103: Unspecified vulnerability in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP2, and Office 2
Unspecified vulnerability in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Office document that contains a malformed object, related to a "memory handling error," aka "Microsoft Office Execution Jump Vulnerability."
nvd
CVE-2019-1111P3HIGHCVSS 8.8v2010v2013+2 more2019-07-15
CVE-2019-1111 [HIGH] CVE-2019-1111: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1110.
nvd
CVE-2019-1110P3HIGHCVSS 8.8v2016v20192019-07-15
CVE-2019-1110 [HIGH] CVE-2019-1110: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1111.
nvd
CVE-2008-4026P3CRITICALCVSS 9.3v2004v20082008-12-10
CVE-2008-4026 [CRITICAL] CWE-399 CVE-2008-4026: Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Word Viewer 2003 Gold and
Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Word Viewer 2003 Gold and SP3; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; Office 2004 and 2008 for Mac; and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a crafted Word document that
nvd
CVE-2007-3890P3CRITICALCVSS 9.3v2000v2003+2 more2007-08-14
CVE-2007-3890 [CRITICAL] CVE-2007-3890: Microsoft Excel in Office 2000 SP3, Office XP SP3, Office 2003 SP2, and Office 2004 for Mac allows r
Microsoft Excel in Office 2000 SP3, Office XP SP3, Office 2003 SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via a Workspace with a certain index value that triggers memory corruption.
nvd
CVE-2008-4024P3CRITICALCVSS 9.3v2004v20082008-12-10
CVE-2008-4024 [CRITICAL] CWE-94 CVE-2008-4024: Microsoft Office Word 2000 SP3 and 2002 SP3 and Office 2004 for Mac allow remote attackers to execut
Microsoft Office Word 2000 SP3 and 2002 SP3 and Office 2004 for Mac allow remote attackers to execute arbitrary code via a Word document with a crafted lcbPlcfBkfSdt field in the File Information Block (FIB), which bypasses an initialization step and triggers an "arbitrary free," aka "Word Memory Corruption Vulnerability."
nvd
CVE-2007-1201P3CRITICALCVSS 9.3v2000vxp2008-03-11
CVE-2007-1201 [CRITICAL] CWE-94 CVE-2007-1201: Unspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user
Unspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user-assisted remote attackers to execute arbitrary code via vectors related to DataSource that trigger memory corruption, aka "Office Web Components DataSource Vulnerability."
nvd
CVE-2011-1983P3CRITICALCVSS 9.3v2007v2010+1 more2011-12-14
CVE-2011-1983 [CRITICAL] CWE-399 CVE-2011-1983: Use-after-free vulnerability in Microsoft Office 2007 SP2 and SP3, Office 2010 Gold and SP1, and Off
Use-after-free vulnerability in Microsoft Office 2007 SP2 and SP3, Office 2010 Gold and SP1, and Office for Mac 2011 allows remote attackers to execute arbitrary code via a crafted Word document, aka "Word Use After Free Vulnerability."
nvd
CVE-2020-1446P3HIGHCVSS 8.8v2010v2016+1 more2020-07-14
CVE-2020-1446 [HIGH] CVE-2020-1446: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1447, CVE-2020-1448.
nvd