cbcvebase.

Microsoft Office vulnerabilities

1,005 known vulnerabilities affecting microsoft/office.

Total CVEs
1,005
CISA KEV
35
actively exploited
Public exploits
103
Exploited in wild
68
Severity breakdown
CRITICAL277HIGH567MEDIUM155LOW6

Vulnerabilities

Page 19 of 51
CVE-2011-3413P3CRITICALCVSS 9.3v20082011-12-14
CVE-2011-3413 [CRITICAL] CWE-94 CVE-2011-3413: Microsoft PowerPoint 2007 SP2; Office 2008 for Mac; Office Compatibility Pack for Word, Excel, and P Microsoft PowerPoint 2007 SP2; Office 2008 for Mac; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; and PowerPoint Viewer 2007 SP2 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via an invalid OfficeArt record in a PowerPoint document, aka "OfficeArt Shape RCE Vulnera
nvd
CVE-2007-0033P3CRITICALCVSS 9.3v2000vxp+1 more2007-01-09
CVE-2007-0033 [CRITICAL] CVE-2007-0033: Microsoft Outlook 2002 and 2003 allows user-assisted remote attackers to execute arbitrary code via Microsoft Outlook 2002 and 2003 allows user-assisted remote attackers to execute arbitrary code via a malformed VEVENT record in an .iCal meeting request or ICS file.
nvd
CVE-2015-2477P3CRITICALCVSS 9.3v2007v2011+1 more2015-08-15
CVE-2015-2477 [CRITICAL] CWE-119 CVE-2015-2477: Microsoft Office 2007 SP3, Office for Mac 2011, Office for Mac 2016, and Word Viewer allow remote at Microsoft Office 2007 SP3, Office for Mac 2011, Office for Mac 2016, and Word Viewer allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2018-8587P3HIGHCVSS 7.8v2010-sp2v2013-sp1+4 more2018-12-12
CVE-2018-8587 [HIGH] CVE-2018-8587: A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook.
nvd
CVE-2006-3651P3CRITICALCVSS 9.3v20032006-10-10
CVE-2006-3651 [CRITICAL] CVE-2006-3651: Unspecified vulnerability in Microsoft Word 2000, 2002, and Office 2003 allows remote user-assisted Unspecified vulnerability in Microsoft Word 2000, 2002, and Office 2003 allows remote user-assisted attackers to execute arbitrary code via a crafted mail merge file, a different vulnerability than CVE-2006-3647 and CVE-2006-4693.
nvd
CVE-2019-1448P3HIGHCVSS 7.8v2016v20192019-11-12
CVE-2019-1448 [HIGH] CVE-2019-1448: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.
nvd
CVE-2006-3435P3CRITICALCVSS 9.3v2000v2003+3 more2006-10-10
CVE-2006-3435 [CRITICAL] CWE-94 CVE-2006-3435: PowerPoint in Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac does not properly parse PowerPoint in Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac does not properly parse the slide notes field in a document, which allows remote user-assisted attackers to execute arbitrary code via crafted data in this field, which triggers an erroneous object pointer calculation that uses data from within the document. NOTE: this issue
nvd
CVE-2007-0029P3CRITICALCVSS 9.3v2000vxp+3 more2007-01-09
CVE-2007-0029 [CRITICAL] CVE-2007-0029: Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted rem Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via a malformed string, aka "Excel Malformed String Vulnerability."
nvd
CVE-2016-0010P3HIGHCVSS 7.8v2007v2010+2 more2016-01-13
CVE-2016-0010 [HIGH] CWE-119 CVE-2016-0010: Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Excel Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Excel for Mac 2011, PowerPoint for Mac 2011, Word for Mac 2011, Excel 2016 for Mac, PowerPoint 2016 for Mac, Word 2016 for Mac, and Word Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruptio
nvd
CVE-2016-3281P3HIGHCVSS 7.8v20102016-07-13
CVE-2016-3281 [HIGH] CWE-119 CVE-2016-3281: Microsoft Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2 Microsoft Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2017-0031P3HIGHCVSS 7.8v20102017-03-17
CVE-2017-0031 [HIGH] CVE-2017-0031: Microsoft Office 2010 SP2, Office Compatibility Pack SP3, Word 2007 SP3, and Word 2010 SP2 allow rem Microsoft Office 2010 SP2, Office Compatibility Pack SP3, Word 2007 SP3, and Word 2010 SP2 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0006, CVE-2017-0019, CVE-2017
nvd
CVE-2017-0030P3HIGHCVSS 7.8v20102017-03-17
CVE-2017-0030 [HIGH] CVE-2017-0030: Microsoft Office 2010 SP2, Office Compatibility Pack SP3, Office Web Apps Server 2010 SP2, Word 2007 Microsoft Office 2010 SP2, Office Compatibility Pack SP3, Office Web Apps Server 2010 SP2, Word 2007 SP3, Word 2010 SP2, and Word Automation Services on SharePoint Server 2010 SP2 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." This
nvd
CVE-2016-0127P3HIGHCVSS 7.8v20102016-04-12
CVE-2016-0127 [HIGH] CWE-119 CVE-2016-0127: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Office Com Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, and Office Web Apps Server 2013 SP1 allow remote attackers to execute arbitrary cod
nvd
CVE-2016-0052P3HIGHCVSS 7.8v20102016-02-10
CVE-2016-0052 [HIGH] CVE-2016-0052: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps Server 2013 SP1, and SharePoint Server 2013 SP1 allow remote attackers to execute arbitrary code via a craft
nvd
CVE-2016-0053P3HIGHCVSS 7.8v20102016-02-10
CVE-2016-0053 [HIGH] CWE-119 CVE-2016-0053: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps Server 2013 SP1, and SharePoint Server 2013 SP1 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Micro
nvd
CVE-2016-7232P3HIGHCVSS 7.8v20102016-11-10
CVE-2016-7232 [HIGH] CWE-119 CVE-2016-7232: Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, and Office Compatibility Pac Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2010-3950P3CRITICALCVSS 9.3vxp2010-12-16
CVE-2010-3950 [CRITICAL] CWE-119 CVE-2010-3950: The TIFF image converter in the graphics filters in Microsoft Office XP SP3, Office Converter Pack, The TIFF image converter in the graphics filters in Microsoft Office XP SP3, Office Converter Pack, and Works 9 does not properly convert data, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted TIFF image in an Office document, aka "TIFF Image Converter Memory Corruption Vulnerabili
nvd
CVE-2010-3952P3CRITICALCVSS 9.3vxp2010-12-16
CVE-2010-3952 [CRITICAL] CWE-119 CVE-2010-3952: The FlashPix image converter in the graphics filters in Microsoft Office XP SP3 and Office Converter The FlashPix image converter in the graphics filters in Microsoft Office XP SP3 and Office Converter Pack allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted FlashPix image in an Office document, aka "FlashPix Image Converter Heap Corruption Vulnerability."
nvd
CVE-2018-0922P3HIGHCVSS 7.8v2010v2013+1 more2018-03-14
CVE-2018-0922 [HIGH] CWE-787 CVE-2018-0922: Microsoft Office 2010 SP2, 2013 SP1, and 2016, Microsoft Office 2016 Click-to-Run Microsoft Office 2 Microsoft Office 2010 SP2, 2013 SP1, and 2016, Microsoft Office 2016 Click-to-Run Microsoft Office 2016 for Mac, Microsoft Office Compatibility Pack SP2, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps 2013 SP1, Microsoft Office Word Viewer, Microsoft SharePoint Enterprise Server 2013 SP1, Microsoft SharePoint Enterprise Server 2016, Micro
nvd
CVE-2013-3854P3CRITICALCVSS 9.3v20072013-09-11
CVE-2013-3854 [CRITICAL] CVE-2013-3854: Microsoft Office 2007 SP3 and Word 2007 SP3 allow remote attackers to execute arbitrary code or caus Microsoft Office 2007 SP3 and Word 2007 SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3853.
nvd
Microsoft Office vulnerabilities | cvebase