cbcvebase.

Microsoft Office vulnerabilities

1,005 known vulnerabilities affecting microsoft/office.

Total CVEs
1,005
CISA KEV
35
actively exploited
Public exploits
103
Exploited in wild
68
Severity breakdown
CRITICAL277HIGH567MEDIUM155LOW6

Vulnerabilities

Page 2 of 51
CVE-2009-0563P1HIGHCVSS 7.8KEVv2000v2003+4 more2009-06-10
CVE-2009-0563 [HIGH] CWE-787 CVE-2009-0563: Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Micro Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File Format Converter for Mac; Microsoft Office Word Viewer 2003 SP3; Microsoft Office Word Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows re
nvd
CVE-2015-1770P1HIGHCVSS 8.8KEVv20132015-06-10
CVE-2015-1770 [HIGH] CWE-824 CVE-2015-1770: Microsoft Office 2013 SP1 and 2013 RT SP1 allows remote attackers to execute arbitrary code via a cr Microsoft Office 2013 SP1 and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Uninitialized Memory Use Vulnerability."
nvd
CVE-2015-1642P1HIGHCVSS 7.8KEVv2007v2010+1 more2015-08-15
CVE-2015-1642 [HIGH] CWE-787 CVE-2015-1642: Microsoft Office 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code Microsoft Office 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2015-2424P1HIGHCVSS 8.8KEVv2007v2010+2 more2015-07-14
CVE-2015-2424 [HIGH] CWE-787 CVE-2015-2424: Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2009-0557P1HIGHCVSS 7.8KEVv2000v2003+4 more2009-06-10
CVE-2009-0557 [HIGH] CWE-94 CVE-2009-0557: Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP
nvd
CVE-2009-0238P1HIGHCVSS 8.8KEVv2004v20082009-02-25
CVE-2009-0238 [HIGH] CWE-94 CVE-2009-0238: Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; E Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office 2004 and 2008 for Mac allow remote attackers to execute arbitrary code via a crafted Excel document that triggers an access attempt on an i
nvd
CVE-2019-1297P1HIGHCVSS 8.8KEVv2016v20192019-09-11
CVE-2019-1297 [HIGH] CVE-2019-1297: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.
nvd
CVE-2006-2492P2HIGHCVSS 8.8KEVv2000v2003+1 more2006-05-20
CVE-2006-2492 [HIGH] CWE-120 CVE-2006-2492: Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Mi Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 20060519 for a zero-day attack.
nvd
CVE-2021-42292P1HIGHCVSS 7.8KEVv2013v2016+1 more2021-11-10
CVE-2021-42292 [HIGH] CVE-2021-42292: Microsoft Excel Security Feature Bypass Vulnerability Microsoft Excel Security Feature Bypass Vulnerability
nvd
CVE-2021-38646P1HIGHCVSS 7.8KEVRansomwarev2013v2016+1 more2021-09-15
CVE-2021-38646 [HIGH] CVE-2021-38646: Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
nvd
CVE-2007-0671P2HIGHCVSS 8.8KEVv2000v2003+2 more2007-02-03
CVE-2007-0671 [HIGH] CVE-2007-0671: Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Of Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.
nvd
CVE-2023-35311P1HIGHCVSS 7.5KEVv20192023-07-11
CVE-2023-35311 [HIGH] CWE-367 CVE-2023-35311: Microsoft Outlook Security Feature Bypass Vulnerability Microsoft Outlook Security Feature Bypass Vulnerability
nvd
CVE-2023-36761P2MEDIUMCVSS 6.5KEVv20192023-09-12
CVE-2023-36761 [MEDIUM] CWE-20 CVE-2023-36761: Microsoft Word Information Disclosure Vulnerability Microsoft Word Information Disclosure Vulnerability
nvd
CVE-2012-1854P2HIGHCVSS 7.8KEVv2003v2007+1 more2012-07-10
CVE-2012-1854 [HIGH] CWE-426 CVE-2012-1854: Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for Applications (VBA); and Summit Microsoft Visual Basic for Applications SDK allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that cont
nvd
CVE-2021-27059P2MEDIUMCVSS 6.5KEVv2010v2013+1 more2021-03-11
CVE-2021-27059 [MEDIUM] CVE-2021-27059: Microsoft Office Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability
nvd
CVE-2023-21716P1CRITICALCVSS 9.8ExploitedPoCv20192023-02-14
CVE-2023-21716 [CRITICAL] CWE-190 CVE-2023-21716: Microsoft Word Remote Code Execution Vulnerability Microsoft Word Remote Code Execution Vulnerability
nvd
CVE-2011-0105P2CRITICALCVSS 9.3ExploitedPoCv2004v20082011-04-13
CVE-2011-0105 [CRITICAL] CWE-119 CVE-2011-0105: Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac o Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac obtain a certain length value from an uninitialized memory location, which allows remote attackers to trigger a buffer overflow and execute arbitrary code via a crafted Excel file, aka "Excel Data Initialization Vulnerability."
nvd
CVE-2009-1136P2CRITICALCVSS 9.3ExploitedPoCv20032009-07-15
CVE-2009-1136 [CRITICAL] CWE-94 CVE-2009-1136: The Microsoft Office Web Components Spreadsheet ActiveX control (aka OWC10 or OWC11), as distributed The Microsoft Office Web Components Spreadsheet ActiveX control (aka OWC10 or OWC11), as distributed in Office XP SP3 and Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 Gold and SP1, an
nvd
CVE-2008-0081P2CRITICALCVSS 9.8ExploitedPoCv20042008-01-16
CVE-2008-0081 [CRITICAL] CVE-2008-0081: Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted macros, aka "Macro Validation Vulnerability," a different vulnerability than CVE-2007-3490.
nvd
CVE-2025-47165P1HIGHCVSS 7.8ExploitedPoCv20192025-06-10
CVE-2025-47165 [HIGH] CWE-416 CVE-2025-47165: Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
Microsoft Office vulnerabilities | cvebase