cbcvebase.

Microsoft Office vulnerabilities

1,005 known vulnerabilities affecting microsoft/office.

Total CVEs
1,005
CISA KEV
35
actively exploited
Public exploits
103
Exploited in wild
68
Severity breakdown
CRITICAL277HIGH567MEDIUM155LOW6

Vulnerabilities

Page 23 of 51
CVE-2019-0801P3HIGHCVSS 7.8v2010v2013+2 more2019-04-09
CVE-2019-0801 [HIGH] CWE-19 CVE-2019-0801: A remote code execution vulnerability exists when Microsoft Office fails to properly handle certain A remote code execution vulnerability exists when Microsoft Office fails to properly handle certain files.To exploit the vulnerability, an attacker would have to convince a user to open a specially crafted URL file that points to an Excel or PowerPoint file that was also downloaded.The update addresses the vulnerability by correcting how Office handles th
nvd
CVE-2020-1335P3HIGHCVSS 8.8v2010v2013+2 more2020-09-11
CVE-2020-1335 [HIGH] CVE-2020-1335: <p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affecte
nvd
CVE-2020-1594P3HIGHCVSS 8.8v20192020-09-11
CVE-2020-1594 [HIGH] CVE-2020-1594: <p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affecte
nvd
CVE-2020-1332P3HIGHCVSS 8.8v20192020-09-11
CVE-2020-1332 [HIGH] CVE-2020-1332: <p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affecte
nvd
CVE-2020-1193P3HIGHCVSS 8.8v2010v2013+2 more2020-09-11
CVE-2020-1193 [HIGH] CVE-2020-1193: <p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affecte
nvd
CVE-2018-0812P3HIGHCVSS 7.8v2007v2010+2 more2018-01-10
CVE-2018-0812 [HIGH] CWE-787 CVE-2018-0812: Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Of Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Memory Corruption Vulnerability".
nvd
CVE-2015-2380P3CRITICALCVSS 9.3v20102015-07-14
CVE-2015-2380 [CRITICAL] CWE-119 CVE-2015-2380: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, and Word 2013 RT SP1 allow r Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, and Word 2013 RT SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2015-2379P3CRITICALCVSS 9.3v2010v20112015-07-14
CVE-2015-2379 [CRITICAL] CWE-119 CVE-2015-2379: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Office for Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Office for Mac 2011, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2022-21840P3HIGHCVSS 8.8v2013v2016+1 more2022-01-11
CVE-2022-21840 [HIGH] CVE-2022-21840: Microsoft Office Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability
nvd
CVE-2006-0007P3CRITICALCVSS 9.3v2000v2003+1 more2006-07-11
CVE-2006-0007 [CRITICAL] CWE-119 CVE-2006-0007: Buffer overflow in GIFIMP32.FLT, as used in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office Buffer overflow in GIFIMP32.FLT, as used in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted GIF image that triggers memory corruption when it is parsed.
nvd
CVE-2017-11854P3HIGHCVSS 8.8v20102017-11-15
CVE-2017-11854 [HIGH] CWE-119 CVE-2017-11854: Microsoft Word 2007 Service Pack 3, Microsoft Word 2010 Service Pack 2, Microsoft Office 2010 Servic Microsoft Word 2007 Service Pack 3, Microsoft Word 2010 Service Pack 2, Microsoft Office 2010 Service Pack 2, and Microsoft Office Compatibility Pack Service Pack 3 allow an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memory, aka "Microsoft Word Memory Corruption Vulnerability".
nvd
CVE-2007-0936P3CRITICALCVSS 9.3v20032007-06-12
CVE-2007-0936 [CRITICAL] CVE-2007-0936: Multiple unspecified vulnerabilities in Microsoft Visio 2002 allow remote user-assisted attackers to Multiple unspecified vulnerabilities in Microsoft Visio 2002 allow remote user-assisted attackers to execute arbitrary code via a Visio (.VSD, VSS, .VST) file with a crafted packed object that triggers memory corruption, aka "Visio Document Packaging Vulnerability."
nvd
CVE-2016-0056P3HIGHCVSS 7.8v20102016-02-10
CVE-2016-0056 [HIGH] CWE-119 CVE-2016-0056: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2016-0055P3HIGHCVSS 7.8v20072016-02-10
CVE-2016-0055 [HIGH] CWE-119 CVE-2016-0055: Microsoft Office 2007 SP3 allows remote attackers to execute arbitrary code via a crafted Office doc Microsoft Office 2007 SP3 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2018-0903P3HIGHCVSS 7.8v20162018-03-14
CVE-2018-0903 [HIGH] CVE-2018-0903: Microsoft Access 2010 SP2, Microsoft Access 2013 SP1, Microsoft Access 2016, and Microsoft Office 20 Microsoft Access 2010 SP2, Microsoft Access 2013 SP1, Microsoft Access 2016, and Microsoft Office 2016 Click-to-Run allow a remote code execution vulnerability due to how objects are handled in memory, aka "Microsoft Access Remote Code Execution Vulnerability".
nvd
CVE-2018-8628P3HIGHCVSS 7.8v2016v2019+2 more2018-12-12
CVE-2018-8628 [HIGH] CVE-2018-8628: A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fail A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Microsoft Office, Office 365 ProPlus, Microsoft PowerPoint, Microsoft SharePoint, Microsoft PowerPoint Viewer, Office Online Server, Microsoft Sha
nvd
CVE-2023-33153P3HIGHCVSS 8.8v2013v2016+1 more2023-07-11
CVE-2023-33153 [HIGH] CWE-416 CVE-2023-33153: Microsoft Outlook Remote Code Execution Vulnerability Microsoft Outlook Remote Code Execution Vulnerability
nvd
CVE-2006-3434P3CRITICALCVSS 9.3v2000v2003+2 more2006-10-10
CVE-2006-3434 [CRITICAL] CVE-2006-3434: Unspecified vulnerability in Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac allows r Unspecified vulnerability in Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac allows remote user-assisted attackers to execute arbitrary code via a crafted string that triggers memory corruption.
nvd
CVE-2023-36413P3MEDIUMCVSS 6.5v2016v20192023-11-14
CVE-2023-36413 [MEDIUM] CVE-2023-36413: Microsoft Office Security Feature Bypass Vulnerability Microsoft Office Security Feature Bypass Vulnerability
nvd
CVE-2011-1278P3CRITICALCVSS 9.3v20042011-06-16
CVE-2011-1278 [CRITICAL] CWE-119 CVE-2011-1278: Microsoft Excel 2002 SP3 and Office 2004 for Mac do not properly validate record information during Microsoft Excel 2002 SP3 and Office 2004 for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel WriteAV Vulnerability."
nvd
Microsoft Office vulnerabilities | cvebase