cbcvebase.

Microsoft Office vulnerabilities

1,005 known vulnerabilities affecting microsoft/office.

Total CVEs
1,005
CISA KEV
35
actively exploited
Public exploits
103
Exploited in wild
68
Severity breakdown
CRITICAL277HIGH567MEDIUM155LOW6

Vulnerabilities

Page 18 of 51
CVE-2015-2376P3CRITICALCVSS 9.3v20112015-07-14
CVE-2015-2376 [CRITICAL] CWE-119 CVE-2015-2376: Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Office for Mac 2011, Ex Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Office for Mac 2011, Excel Viewer 2007 SP3, Office Compatibility Pack SP3, Excel Services on SharePoint Server 2007 SP3, Excel Services on SharePoint Server 2010 SP2, and Excel Services on SharePoint Server 2013 SP1 allow remote attackers to execute arbitrary code or cause
nvd
CVE-2010-3241P3CRITICALCVSS 9.3v2004v20082010-10-13
CVE-2010-3241 [CRITICAL] CWE-20 CVE-2010-3241: Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac d Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate binary file-format information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Out-of-Bounds Memory Write in Parsing Vulnerability."
nvd
CVE-2010-3231P3CRITICALCVSS 9.3v2004v20082010-10-13
CVE-2010-3231 [CRITICAL] CWE-20 CVE-2010-3231: Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac d Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Excel Record Parsing Memory Corruption Vulnerability."
nvd
CVE-2009-2528P3CRITICALCVSS 9.3v2003v2007+1 more2009-10-14
CVE-2009-2528 [CRITICAL] CWE-94 CVE-2009-2528: GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Ta GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "Memory Corruption Vulnerability."
nvd
CVE-2007-1756P3CRITICALCVSS 9.3v2000v2003+2 more2007-07-10
CVE-2007-1756 [CRITICAL] CVE-2007-1756: Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, and Office Excel 2007 does not properly v Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, and Office Excel 2007 does not properly validate version information, which allows user-assisted remote attackers to execute arbitrary code via a crafted Excel file, aka "Calculation Error Vulnerability".
nvd
CVE-2015-6124P3CRITICALCVSS 9.3v2010v20132015-12-09
CVE-2015-6124 [CRITICAL] CWE-119 CVE-2015-6124: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, and Office Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2020-1483P3HIGHCVSS 8.8v20192020-08-17
CVE-2020-1483 [HIGH] CWE-787 CVE-2020-1483: A remote code execution vulnerability exists in Microsoft Outlook when the software fails to properl A remote code execution vulnerability exists in Microsoft Outlook when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affec
nvd
CVE-2016-0198P3HIGHCVSS 7.8v20102016-05-11
CVE-2016-0198 [HIGH] CWE-119 CVE-2016-0198: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2015-6118P3CRITICALCVSS 9.3v2007v20102015-12-09
CVE-2015-6118 [CRITICAL] CWE-119 CVE-2015-6118: Microsoft Office 2007 SP3 and Office 2010 SP2 allow remote attackers to execute arbitrary code via a Microsoft Office 2007 SP3 and Office 2010 SP2 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2008-1434P3CRITICALCVSS 9.3v2000v2003+5 more2008-05-13
CVE-2008-1434 [CRITICAL] CWE-399 CVE-2008-1434: Use-after-free vulnerability in Microsoft Word in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 Use-after-free vulnerability in Microsoft Word in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 Office System SP1 and earlier allows remote attackers to execute arbitrary code via an HTML document with a large number of Cascading Style Sheets (CSS) selectors, related to a "memory handling error" that triggers memory corruption.
nvd
CVE-2007-0034P3CRITICALCVSS 9.3v2000vxp+1 more2007-01-09
CVE-2007-0034 [CRITICAL] CWE-119 CVE-2007-0034: Buffer overflow in the Advanced Search (Finder.exe) feature of Microsoft Outlook 2000, 2002, and 200 Buffer overflow in the Advanced Search (Finder.exe) feature of Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted Outlook Saved Searches (OSS) file that triggers memory corruption, aka "Microsoft Outlook Advanced Find Vulnerability."
nvd
CVE-2006-3650P3CRITICALCVSS 9.3v2000v2001+3 more2006-10-10
CVE-2006-3650 [CRITICAL] CVE-2006-3650: Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac do not properly parse the length of a Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac do not properly parse the length of a chart record, which allows remote user-assisted attackers to execute arbitrary code via a Word document with an embedded malformed chart record that triggers an overwrite of pointer values with values from the document, a different vulnerability than CVE-200
nvd
CVE-2008-4265P3CRITICALCVSS 9.3v2004v20082008-12-10
CVE-2008-4265 [CRITICAL] CWE-399 CVE-2008-4265: Microsoft Office Excel 2000 SP3 allows remote attackers to execute arbitrary code via a crafted Exce Microsoft Office Excel 2000 SP3 allows remote attackers to execute arbitrary code via a crafted Excel spreadsheet that contains a malformed object, which triggers memory corruption during the loading of records from this spreadsheet, aka "File Format Parsing Vulnerability."
nvd
CVE-2008-4031P3CRITICALCVSS 9.3v2004v20082008-12-10
CVE-2008-4031 [CRITICAL] CWE-399 CVE-2008-4031: Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Outlook 2007 Gold and SP1 Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Outlook 2007 Gold and SP1; Word Viewer 2003 Gold and SP3; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; Office 2004 and 2008 for Mac; and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a
nvd
CVE-2016-7234P3HIGHCVSS 7.8v20102016-11-10
CVE-2016-7234 [HIGH] CWE-119 CVE-2016-7234: Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2 Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Excel for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, and Office Web Apps Server 2013 SP1 allow
nvd
CVE-2016-0134P3HIGHCVSS 7.8v20102016-03-09
CVE-2016-0134 [HIGH] CWE-119 CVE-2016-0134: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, Office Web Apps 2010 SP2, and Web Apps Server 2013 SP1 allow remote attackers to execute arbitrary code
nvd
CVE-2020-0906P3HIGHCVSS 8.8v2010v2013+2 more2020-04-15
CVE-2020-0906 [HIGH] CVE-2020-0906: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0979.
nvd
CVE-2020-1447P3HIGHCVSS 8.8v2010v2016+1 more2020-07-14
CVE-2020-1447 [HIGH] CVE-2020-1447: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1448.
nvd
CVE-2010-3216P3CRITICALCVSS 9.3v20042010-10-13
CVE-2010-3216 [CRITICAL] CWE-94 CVE-2010-3216: Microsoft Word 2002 SP3 and Office 2004 for Mac allow remote attackers to execute arbitrary code via Microsoft Word 2002 SP3 and Office 2004 for Mac allow remote attackers to execute arbitrary code via a crafted Word document containing bookmarks that trigger use of an invalid pointer and memory corruption, aka "Word Bookmarks Vulnerability."
nvd
CVE-2020-1448P3HIGHCVSS 8.8v20192020-07-14
CVE-2020-1448 [HIGH] CVE-2020-1448: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1447.
nvd
Microsoft Office vulnerabilities | cvebase