cbcvebase.

Microsoft Office vulnerabilities

1,005 known vulnerabilities affecting microsoft/office.

Total CVEs
1,005
CISA KEV
35
actively exploited
Public exploits
103
Exploited in wild
68
Severity breakdown
CRITICAL277HIGH567MEDIUM155LOW6

Vulnerabilities

Page 3 of 51
CVE-2005-2127P2HIGHCVSS 7.5ExploitedPoCv2000vxp2005-08-19
CVE-2005-2127 [HIGH] CWE-119 CVE-2005-2127: Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (a Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the (1) DDS Library Shape Control (Msdds.
nvd
CVE-2008-1898P2CRITICALCVSS 9.3ExploitedPoCv2003v20072008-04-21
CVE-2008-1898 [CRITICAL] CWE-20 CVE-2008-1898: A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Micro A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and 2007, allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via an invalid WksPictureInterface property value, which triggers an improper function call.
nvd
CVE-2006-6561P2CRITICALCVSS 9.3ExploitedPoCv2000v2003+2 more2006-12-14
CVE-2006-6561 [CRITICAL] CVE-2006-6561: Unspecified vulnerability in Microsoft Word 2000, 2002, and Word Viewer 2003 allows user-assisted re Unspecified vulnerability in Microsoft Word 2000, 2002, and Word Viewer 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted DOC file that triggers memory corruption, as demonstrated via the 12122006-djtest.doc file, a different issue than CVE-2006-5994 and CVE-2006-6456.
nvd
CVE-2007-6026P2CRITICALCVSS 9.3ExploitedPoCv20032007-11-20
CVE-2007-6026 [CRITICAL] CWE-119 CVE-2007-6026: Stack-based buffer overflow in Microsoft msjet40.dll 4.0.8618.0 (aka Microsoft Jet Engine), as used Stack-based buffer overflow in Microsoft msjet40.dll 4.0.8618.0 (aka Microsoft Jet Engine), as used by Access 2003 in Microsoft Office 2003 SP3, allows user-assisted attackers to execute arbitrary code via a crafted MDB file database file containing a column structure with a modified column count. NOTE: this might be the same issue as CVE-2005-0944.
nvd
CVE-2007-0515P2CRITICALCVSS 9.3ExploitedPoCv2000v2003+2 more2007-01-26
CVE-2007-0515 [CRITICAL] CVE-2007-0515: Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitra Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of service on Word 2003, via unknown attack vectors that trigger memory corruption, as exploited by Trojan.Mdropper.W and later by Trojan.Mdropper.X, a different issue than CVE-2006-6456, CVE-2006-5994, and CVE-2006-65
nvd
CVE-2006-1540P2CRITICALCVSS 9.3ExploitedPoCv2000v2003+3 more2006-03-30
CVE-2006-1540 [CRITICAL] CWE-94 CVE-2006-1540: MSO.DLL in Microsoft Office 2000, Office XP (2002), and Office 2003 allows user-assisted attackers t MSO.DLL in Microsoft Office 2000, Office XP (2002), and Office 2003 allows user-assisted attackers to cause a denial of service and execute arbitrary code via multiple attack vectors, as originally demonstrated using a crafted document record with a malformed string, as demonstrated by replacing a certain "01 00 00 00" byte sequence with an "FF FF FF
nvd
CVE-2012-0159P1CRITICALCVSS 9.3Exploitedv2003v2007+1 more2012-05-09
CVE-2012-0159 [CRITICAL] CWE-399 CVE-2012-0159: Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview; Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Silverlight 4 before 4.1.10329; and Silverlight 5 before 5.1.10411 allow remote attackers to execute arbitrary code vi
nvd
CVE-2009-0561P2CRITICALCVSS 9.3Exploitedv2004v2008+1 more2009-06-10
CVE-2009-0561 [CRITICAL] CWE-189 CVE-2009-0561: Integer overflow in Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2 Integer overflow in Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel Viewer; Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint
nvd
CVE-2009-1134P2CRITICALCVSS 9.3Exploitedv2004v2008+1 more2009-06-10
CVE-2009-1134 [CRITICAL] CWE-94 CVE-2009-1134: Excel in 2007 Microsoft Office System SP1 and SP2; Microsoft Office Excel Viewer; and Microsoft Offi Excel in 2007 Microsoft Office System SP1 and SP2; Microsoft Office Excel Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a BIFF file with a malformed Qsir (0x806) record object, aka "Record Pointer Corruption Vulnerability."
nvd
CVE-2024-38021P1HIGHCVSS 8.8Exploitedv2016v20192024-07-09
CVE-2024-38021 [HIGH] CWE-20 CVE-2024-38021: Microsoft Outlook Remote Code Execution Vulnerability Microsoft Outlook Remote Code Execution Vulnerability
nvd
CVE-2011-0097P2CRITICALCVSS 9.3Exploitedv2004v20082011-04-13
CVE-2011-0097 [CRITICAL] CWE-189 CVE-2011-0097: Integer underflow in Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004 and 2008 fo Integer underflow in Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 allows remote attackers to execute arbitrary code via a crafted 400h substream in an Excel file, which
nvd
CVE-2009-3126P2CRITICALCVSS 9.3Exploitedv2003v2007+1 more2009-10-14
CVE-2009-3126 [CRITICAL] CWE-189 CVE-2009-3126: Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3 Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP
nvd
CVE-2009-2501P2CRITICALCVSS 9.3Exploitedv2003v2007+1 more2009-10-14
CVE-2009-2501 [CRITICAL] CWE-119 CVE-2009-2501: Heap-based buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Off Heap-based buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 200
nvd
CVE-2006-6456P2CRITICALCVSS 9.3Exploitedv2000v2003+2 more2006-12-11
CVE-2006-6456 [CRITICAL] CVE-2006-6456: Unspecified vulnerability in Microsoft Word 2000, 2002, and 2003 and Word Viewer 2003 allows remote Unspecified vulnerability in Microsoft Word 2000, 2002, and 2003 and Word Viewer 2003 allows remote attackers to execute code via unspecified vectors related to malformed data structures that trigger memory corruption, a different vulnerability than CVE-2006-5994.
nvd
CVE-2006-5994P2CRITICALCVSS 9.3Exploitedv2000v2003+2 more2006-12-06
CVE-2006-5994 [CRITICAL] CVE-2006-5994: Unspecified vulnerability in Microsoft Word 2000 and 2002, Office Word and Word Viewer 2003, Word 20 Unspecified vulnerability in Microsoft Word 2000 and 2002, Office Word and Word Viewer 2003, Word 2004 and 2004 v. X for Mac, and Works 2004, 2005, and 2006 allows remote attackers to execute arbitrary code via a Word document with a malformed string that triggers memory corruption, a different vulnerability than CVE-2006-6456.
nvd
CVE-2010-3336P2CRITICALCVSS 9.3Exploitedv2004v2008+2 more2010-11-10
CVE-2010-3336 [CRITICAL] CWE-119 CVE-2010-3336: Microsoft Office XP SP3, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Microsoft Office XP SP3, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "MSO Large SPID Read AV Vulnerability."
nvd
CVE-2007-3899P2CRITICALCVSS 9.3Exploitedv2000v2004+1 more2007-10-09
CVE-2007-3899 [CRITICAL] CWE-94 CVE-2007-3899: Unspecified vulnerability in Microsoft Word 2000 SP3, Word 2002 SP3, and Office 2004 for Mac allows Unspecified vulnerability in Microsoft Word 2000 SP3, Word 2002 SP3, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a malformed string in a Word file, aka "Word Memory Corruption Vulnerability."
nvd
CVE-2018-8627P2MEDIUMCVSS 5.5Exploitedv2010-sp2v2016+1 more2018-12-12
CVE-2018-8627 [MEDIUM] CVE-2018-8627: An information disclosure vulnerability exists when Microsoft Excel software reads out of bound memo An information disclosure vulnerability exists when Microsoft Excel software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Office, Office 365 ProPlus, Microsoft Excel, Microsoft Excel Viewer, Excel. This CVE ID is uniqu
nvd
CVE-2006-4534P2CRITICALCVSS 9.3Exploitedv2000v2001+1 more2006-09-05
CVE-2006-4534 [CRITICAL] CVE-2006-4534: Unspecified vulnerability in Microsoft Word 2000, 2002, and Office 2003 allows remote user-assisted Unspecified vulnerability in Microsoft Word 2000, 2002, and Office 2003 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors involving a crafted file resulting in a malformed stack, as exploited by malware with names including Trojan.Mdropper.Q, Mofei, and Femo.
nvd
CVE-2013-5054P2MEDIUMCVSS 4.3Exploitedv20132013-12-11
CVE-2013-5054 [MEDIUM] CWE-200 CVE-2013-5054: Microsoft Office 2013 and 2013 RT allows remote attackers to discover authentication tokens via a cr Microsoft Office 2013 and 2013 RT allows remote attackers to discover authentication tokens via a crafted response to a file-open request for an Office file on a web site, as exploited in the wild in 2013, aka "Token Hijacking Vulnerability."
nvd
Microsoft Office vulnerabilities | cvebase