Microsoft Office vulnerabilities

987 known vulnerabilities affecting microsoft/office.

Total CVEs
987
CISA KEV
35
actively exploited
Public exploits
98
Exploited in wild
42
Severity breakdown
CRITICAL279HIGH549MEDIUM153LOW6

Vulnerabilities

Page 41 of 50
CVE-2010-1263CRITICALCVSS 9.3v2003v2007+1 more2010-06-08
CVE-2010-1263 [CRITICAL] CWE-94 CVE-2010-1263: Windows Shell and WordPad in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vist Windows Shell and WordPad in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7; Microsoft Office XP SP3; Office 2003 SP3; and Office System 2007 SP1 and SP2 do not properly validate COM objects during instantiation, which allows remote attackers to execute arbitr
nvd
CVE-2010-1252CRITICALCVSS 9.3v20042010-06-08
CVE-2010-1252 [CRITICAL] CWE-94 CVE-2010-1252: Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote a Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Excel file, aka "Excel String Variable Vulnerability."
nvd
CVE-2010-1253CRITICALCVSS 9.3v2004v20082010-06-08
CVE-2010-1253 [CRITICAL] CWE-94 CVE-2010-1253: Microsoft Office Excel 2002 SP3, 2007 SP1, and SP2; Office 2004 for mac; Office 2008 for Mac; Open X Microsoft Office Excel 2002 SP3, 2007 SP1, and SP2; Office 2004 for mac; Office 2008 for Mac; Open XML File Format Converter for Mac; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2; allows remote attackers to execute arbitrary code via an Excel file with crafted DBQueryExt records that allow a function cal
nvd
CVE-2010-1245CRITICALCVSS 9.3PoCv2004v20082010-06-08
CVE-2010-1245 [CRITICAL] CVE-2010-1245: Unspecified vulnerability in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for M Unspecified vulnerability in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed SxView (0xB0) record, aka "Excel Record Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0824 and CVE-
nvd
CVE-2010-0824CRITICALCVSS 9.3PoCv20042010-06-08
CVE-2010-0824 [CRITICAL] CVE-2010-0824: Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote a Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed WOPT (0x80B) record, aka "Excel Record Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0821 and CVE-2010-1245.
nvd
CVE-2010-1251CRITICALCVSS 9.3v20042010-06-08
CVE-2010-1251 [CRITICAL] CWE-94 CVE-2010-1251: Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote a Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Excel file, aka "Excel Record Stack Corruption Vulnerability."
nvd
CVE-2010-0822CRITICALCVSS 9.3PoCv2004v20082010-06-08
CVE-2010-0822 [CRITICAL] CWE-94 CVE-2010-0822: Stack-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Stack-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a crafted OBJ (0x5D) record, aka "Excel Object Stack Overflow Vulnerability."
nvd
CVE-2010-1248CRITICALCVSS 9.3PoCv20042010-06-08
CVE-2010-1248 [CRITICAL] CWE-94 CVE-2010-1248: Buffer overflow in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers t Buffer overflow in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed HFPicture (0x866) record, aka "Excel HFPicture Memory Corruption Vulnerability."
nvd
CVE-2010-0823CRITICALCVSS 9.3v2004v20082010-06-08
CVE-2010-0823 [CRITICAL] CWE-94 CVE-2010-0823: Unspecified vulnerability in Microsoft Office Excel 2002 SP3, 2003 SP3, 2007 SP1 and SP2; Office 200 Unspecified vulnerability in Microsoft Office Excel 2002 SP3, 2003 SP3, 2007 SP1 and SP2; Office 2004 for mac; Office 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2; allows remote attackers to execute arbitrary code via
nvd
CVE-2010-0815CRITICALCVSS 9.3v2003v2007+1 more2010-05-12
CVE-2010-0815 [CRITICAL] CWE-94 CVE-2010-0815: VBE6.DLL in Microsoft Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Visu VBE6.DLL in Microsoft Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Visual Basic for Applications (VBA), and VBA SDK 6.3 through 6.5 does not properly search for ActiveX controls that are embedded in documents, which allows remote attackers to execute arbitrary code via a crafted document, aka "VBE6.DLL Stack Memory Corrup
nvd
CVE-2010-0263CRITICALCVSS 9.3v2004v20082010-03-10
CVE-2010-0263 [CRITICAL] CWE-94 CVE-2010-0263: Microsoft Office Excel 2007 SP1 and SP2; Office 2008 for Mac; Open XML File Format Converter for Mac Microsoft Office Excel 2007 SP1 and SP2; Office 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer SP1 and SP2; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2; and Office SharePoint Server 2007 SP1 and SP2 do not validate ZIP headers during decompression of Open XML (.XLSX) documents, wh
nvd
CVE-2010-0261CRITICALCVSS 9.3v2004v20082010-03-10
CVE-2010-0261 [CRITICAL] CWE-119 CVE-2010-0261: Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2 and Office Compatibility Pack Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2 and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted spreadsheet in which "a MDXSET record is broken up into several records," aka "Microsoft Office Excel MDXSET Record Heap Overf
nvd
CVE-2010-0262CRITICALCVSS 9.3v2004v20082010-03-10
CVE-2010-0262 [CRITICAL] CWE-94 CVE-2010-0262: Microsoft Office Excel 2007 SP1 and SP2 and Office 2004 for Mac do not properly parse the Excel file Microsoft Office Excel 2007 SP1 and SP2 and Office 2004 for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet that triggers access of an uninitialized stack variable, aka "Microsoft Office Excel FNGROUPNAME Record Uninitialized Memory Vulnerability."
nvd
CVE-2010-0264CRITICALCVSS 9.3v2004v20082010-03-10
CVE-2010-0264 [CRITICAL] CWE-94 CVE-2010-0264: Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter fo Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Microsoft Office Excel DbOrParamQry Record Parsing Vulnerability."
nvd
CVE-2010-0257CRITICALCVSS 9.3v2004v20082010-03-10
CVE-2010-0257 [CRITICAL] CWE-94 CVE-2010-0257: Microsoft Office Excel 2002 SP3 does not properly parse the Excel file format, which allows remote a Microsoft Office Excel 2002 SP3 does not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Microsoft Office Excel Record Memory Corruption Vulnerability."
nvd
CVE-2010-0260CRITICALCVSS 9.3v2004v20082010-03-10
CVE-2010-0260 [CRITICAL] CWE-94 CVE-2010-0260: Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2; Office Excel Viewer SP1 and S Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted spreadsheet in which "a MDXTUPLE record is broken up into several records," aka "Microsoft O
nvd
CVE-2010-0258HIGHCVSS 7.8v2004v20082010-03-10
CVE-2010-0258 [HIGH] CWE-843 CVE-2010-0258: Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 do not properly parse the Excel file format, which allows remote attackers to execute arbitrary
nvd
CVE-2010-0243CRITICALCVSS 9.3v2004vxp2010-02-10
CVE-2010-0243 [CRITICAL] CWE-119 CVE-2010-0243: Buffer overflow in MSO.DLL in Microsoft Office XP SP3 and Office 2004 for Mac allows remote attacker Buffer overflow in MSO.DLL in Microsoft Office XP SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Office document, aka "MSO.DLL Buffer Overflow."
nvd
CVE-2010-0031CRITICALCVSS 9.3v20042010-02-10
CVE-2010-0031 [CRITICAL] CWE-94 CVE-2010-0031: Array index error in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3, and PowerPoint in Office 200 Array index error in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3, and PowerPoint in Office 2004 for Mac, allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint OEPlaceholderAtom 'placementId' Invalid Array Indexing Vulnerability."
nvd
CVE-2009-3132CRITICALCVSS 9.3v2004v20082009-11-11
CVE-2009-3132 [CRITICAL] CWE-94 CVE-2009-3132: Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a spreadsh
nvd