cbcvebase.

Microsoft Office vulnerabilities

1,005 known vulnerabilities affecting microsoft/office.

Total CVEs
1,005
CISA KEV
35
actively exploited
Public exploits
103
Exploited in wild
68
Severity breakdown
CRITICAL277HIGH567MEDIUM155LOW6

Vulnerabilities

Page 20 of 51
CVE-2013-3853P3CRITICALCVSS 9.3v20072013-09-11
CVE-2013-3853 [CRITICAL] CWE-119 CVE-2013-3853: Microsoft Office 2007 SP3 and Word 2007 SP3 allow remote attackers to execute arbitrary code or caus Microsoft Office 2007 SP3 and Word 2007 SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3854.
nvd
CVE-2007-0030P3CRITICALCVSS 9.3v2000vxp+3 more2007-01-09
CVE-2007-0030 [CRITICAL] CVE-2007-0030: Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted rem Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via an Excel file with an out-of-range Column field in certain BIFF8 record types, which references arbitrary memory.
nvd
CVE-2004-0573P3HIGHCVSS 7.5v2000v2003+1 more2004-09-28
CVE-2004-0573 [HIGH] CVE-2004-0573: Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 200 Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website.
nvd
CVE-2007-1747P3CRITICALCVSS 9.3v2000v2003+3 more2007-05-08
CVE-2007-1747 [CRITICAL] CWE-399 CVE-2007-1747: Unspecified vulnerability in MSO.dll in Microsoft Office 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, Unspecified vulnerability in MSO.dll in Microsoft Office 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and 2007 allows user-assisted remote attackers to execute arbitrary code via a malformed drawing object, which triggers memory corruption.
nvd
CVE-2015-0086P3CRITICALCVSS 9.3v20102015-03-11
CVE-2015-0086 [CRITICAL] CWE-399 CVE-2015-0086: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 Gold and SP1, Word 2013 RT Gold a Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 Gold and SP1, Word 2013 RT Gold and SP1, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 Gold and SP1, Web Applications 2010 SP2, and Web Apps Server 2013 Gold and SP1 allow remote
nvd
CVE-2010-1901P3CRITICALCVSS 9.3v2004v20082010-08-11
CVE-2010-1901 [CRITICAL] CWE-94 CVE-2010-1901: Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2; Microsoft Office 2004 and 2008 for Mac; Open Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2; Microsoft Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Word Viewer; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 do not properly handle unspecified properties in rich text data, which allows remote attackers to execute arbitr
nvd
CVE-2020-0760P3HIGHCVSS 8.8v2010v2013+2 more2020-04-15
CVE-2020-0760 [HIGH] CVE-2020-0760: A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type l A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries, aka 'Microsoft Office Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0991.
nvd
CVE-2018-8430P3HIGHCVSS 7.8v2013-sp1v20162018-09-13
CVE-2018-8430 [HIGH] CVE-2018-8430: A remote code execution vulnerability exists in Microsoft Word if a user opens a specially crafted P A remote code execution vulnerability exists in Microsoft Word if a user opens a specially crafted PDF file, aka "Word PDF Remote Code Execution Vulnerability." This affects Microsoft Word, Microsoft Office.
nvd
CVE-2007-3029P3CRITICALCVSS 9.3v2003vxp2007-07-10
CVE-2007-3029 [CRITICAL] CVE-2007-3029: Unspecified vulnerability in Microsoft Excel 2002 SP3 and 2003 SP2 allows user-assisted remote attac Unspecified vulnerability in Microsoft Excel 2002 SP3 and 2003 SP2 allows user-assisted remote attackers to execute arbitrary code via a malformed Excel file containing multiple active worksheets, which results in memory corruption.
nvd
CVE-2020-1349P3HIGHCVSS 7.8v20192020-07-14
CVE-2020-1349 [HIGH] CVE-2020-1349: A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka 'Microsoft Outlook Remote Code Execution Vulnerability'.
nvd
CVE-2016-3317P3HIGHCVSS 7.8v20102016-08-09
CVE-2016-3317 [HIGH] CWE-119 CVE-2016-3317: Microsoft Office 2010 SP2, Word 2007 SP3, Word 2010 SP2, Word for Mac 2011, Word 2016 for Mac, and W Microsoft Office 2010 SP2, Word 2007 SP3, Word 2010 SP2, Word for Mac 2011, Word 2016 for Mac, and Word Viewer allow remote attackers to execute arbitrary code via a crafted file, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2016-3318P3HIGHCVSS 7.8v2007v2010+1 more2016-08-09
CVE-2016-3318 [HIGH] CWE-119 CVE-2016-3318: Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allow remote attackers to execute arb Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allow remote attackers to execute arbitrary code via a crafted file, aka "Graphics Component Memory Corruption Vulnerability."
nvd
CVE-2006-5574P3CRITICALCVSS 9.3v20032006-12-31
CVE-2006-5574 [CRITICAL] CVE-2006-5574: Unspecified vulnerability in the Brazilian Portuguese Grammar Checker in Microsoft Office 2003 and t Unspecified vulnerability in the Brazilian Portuguese Grammar Checker in Microsoft Office 2003 and the Multilingual Interface for Office 2003, Project 2003, and Visio 2003 allows user-assisted remote attackers to execute arbitrary code via crafted text that is not properly parsed.
nvd
CVE-2007-0209P3CRITICALCVSS 9.3v2000v2003+2 more2007-02-13
CVE-2007-0209 [CRITICAL] CWE-94 CVE-2007-0209: Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 200 Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a Word file with a malformed drawing object, which leads to memory corruption.
nvd
CVE-2007-2903P4MEDIUMCVSS 5.0PoCv20002007-05-30
CVE-2007-2903 [MEDIUM] CVE-2007-2903: Buffer overflow in the HelpPopup method in the Microsoft Office 2000 Controllo UA di Microsoft Offic Buffer overflow in the HelpPopup method in the Microsoft Office 2000 Controllo UA di Microsoft Office ActiveX control (OUACTRL.OCX) 1.0.1.9 allows remote attackers to cause a denial of service (probably winhlp32.exe crash) via a long first argument. NOTE: it is not clear whether this issue crosses privilege boundaries.
nvd
CVE-2026-40361P3HIGHCVSS 8.4v20192026-05-12
CVE-2026-40361 [HIGH] CWE-416 CVE-2026-40361: Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-20953P3HIGHCVSS 8.4v2016v20192026-01-13
CVE-2026-20953 [HIGH] CWE-416 CVE-2026-20953: Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2018-8248P3HIGHCVSS 7.8v2010-sp2v2013-sp1+1 more2018-06-14
CVE-2018-8248 [HIGH] CVE-2018-8248: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Office.
nvd
CVE-2026-40363P3HIGHCVSS 8.4v2016v20192026-05-12
CVE-2026-40363 [HIGH] CWE-122 CVE-2026-40363: Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-40358P3HIGHCVSS 8.4v2016v20192026-05-12
CVE-2026-40358 [HIGH] CWE-416 CVE-2026-40358: Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
Microsoft Office vulnerabilities | cvebase