Microsoft Office vulnerabilities
1,005 known vulnerabilities affecting microsoft/office.
Total CVEs
1,005
CISA KEV
35
actively exploited
Public exploits
103
Exploited in wild
68
Severity breakdown
CRITICAL277HIGH567MEDIUM155LOW6
Vulnerabilities
Page 47 of 51
CVE-2018-8429P4MEDIUMCVSS 5.5v20162018-09-13
CVE-2018-8429 [MEDIUM] CWE-200 CVE-2018-8429: An information disclosure vulnerability exists when Microsoft Excel improperly discloses the content
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel.
nvd
CVE-2018-8382P4MEDIUMCVSS 5.5v20162018-08-15
CVE-2018-8382 [MEDIUM] CWE-200 CVE-2018-8382: An information disclosure vulnerability exists when Microsoft Excel improperly discloses the content
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel.
nvd
CVE-2022-26934P4MEDIUMCVSS 6.5v20192022-05-10
CVE-2022-26934 [MEDIUM] CVE-2022-26934: Windows Graphics Component Information Disclosure Vulnerability
Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2016-7244P4MEDIUMCVSS 5.5v20072016-11-10
CVE-2016-7244 [MEDIUM] CWE-284 CVE-2016-7244: Microsoft Office 2007 SP3 allows remote attackers to cause a denial of service (application hang) vi
Microsoft Office 2007 SP3 allows remote attackers to cause a denial of service (application hang) via a crafted Office document, aka "Microsoft Office Denial of Service Vulnerability."
nvd
CVE-2014-2730P4MEDIUMCVSS 5.0v2007v2010+2 more2014-04-05
CVE-2014-2730 [MEDIUM] CVE-2014-2730: The XML parser in Microsoft Office 2007 SP3, 2010 SP1 and SP2, and 2013, and Office for Mac 2011, do
The XML parser in Microsoft Office 2007 SP3, 2010 SP1 and SP2, and 2013, and Office for Mac 2011, does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory consumption and persistent application hang) via a crafted XML document containing a large number of nested entity references, as demons
nvd
CVE-2023-36897P4MEDIUMCVSS 6.5v20192023-08-08
CVE-2023-36897 [MEDIUM] CWE-20 CVE-2023-36897: Visual Studio Tools for Office Runtime Spoofing Vulnerability
Visual Studio Tools for Office Runtime Spoofing Vulnerability
nvd
CVE-2019-0560P4MEDIUMCVSS 5.5v2019v365 ProPlus for 32-bit Systems+1 more2019-01-08
CVE-2019-0560 [MEDIUM] CVE-2019-0560: An information disclosure vulnerability exists when Microsoft Office improperly discloses the conten
An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory, aka "Microsoft Office Information Disclosure Vulnerability." This affects Office 365 ProPlus, Microsoft Office.
nvd
CVE-2019-0561P4MEDIUMCVSS 5.5v2010-sp2v2016+3 more2019-01-08
CVE-2019-0561 [MEDIUM] CVE-2019-0561: An information disclosure vulnerability exists when Microsoft Word macro buttons are used improperly
An information disclosure vulnerability exists when Microsoft Word macro buttons are used improperly, aka "Microsoft Word Information Disclosure Vulnerability." This affects Microsoft Word, Office 365 ProPlus, Microsoft Office, Word.
nvd
CVE-2018-8546P4MEDIUMCVSS 5.9v2019v365 ProPlus for 32-bit Systems+1 more2018-11-14
CVE-2018-8546 [MEDIUM] CVE-2018-8546: A denial of service vulnerability exists in Skype for Business, aka "Microsoft Skype for Business De
A denial of service vulnerability exists in Skype for Business, aka "Microsoft Skype for Business Denial of Service Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Lync, Skype.
nvd
CVE-2020-1342P4MEDIUMCVSS 5.5v2010v2016+1 more2020-07-14
CVE-2020-1342 [MEDIUM] CWE-125 CVE-2020-1342: An information disclosure vulnerability exists when Microsoft Office software reads out of bound mem
An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory, aka 'Microsoft Office Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1445.
nvd
CVE-2006-0004P4MEDIUMCVSS 5.0v20002006-02-14
CVE-2006-0004 [MEDIUM] CVE-2006-0004: Microsoft PowerPoint 2000 in Office 2000 SP3 has an interaction with Internet Explorer that allows r
Microsoft PowerPoint 2000 in Office 2000 SP3 has an interaction with Internet Explorer that allows remote attackers to obtain sensitive information via a PowerPoint presentation that attempts to access objects in the Temporary Internet Files Folder (TIFF).
nvd
CVE-2020-16855P4MEDIUMCVSS 5.5v2016v20192020-09-11
CVE-2020-16855 [MEDIUM] CWE-125 CVE-2020-16855: <p>An information disclosure vulnerability exists when Microsoft Office software reads out of bound
An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory. An attacker who successfully exploited the vulnerability could view out of bound memory.
Exploitation of the vulnerability requires that a user open a specially crafted
nvd
CVE-2017-0029P4MEDIUMCVSS 5.5v20102017-03-17
CVE-2017-0029 [MEDIUM] CVE-2017-0029: Microsoft Office 2010 SP2, Word 2010 SP2, Word 2013 RT SP1, and Word 2016 allow remote attackers to
Microsoft Office 2010 SP2, Word 2010 SP2, Word 2013 RT SP1, and Word 2016 allow remote attackers to cause a denial of service (application hang) via a crafted Office document, aka "Microsoft Office Denial of Service Vulnerability."
nvd
CVE-2008-4020P4MEDIUMCVSS 4.3vxp2008-10-15
CVE-2008-4020 [MEDIUM] CWE-79 CVE-2008-4020: Cross-site scripting (XSS) vulnerability in Microsoft Office XP SP3 allows remote attackers to injec
Cross-site scripting (XSS) vulnerability in Microsoft Office XP SP3 allows remote attackers to inject arbitrary web script or HTML via a document that contains a "Content-Disposition: attachment" header and is accessed through a cdo: URL, which renders the content instead of raising a File Download dialog box, aka "Vulnerability in Content-Disposition
nvd
CVE-2019-1112P4MEDIUMCVSS 5.5v20192019-07-15
CVE-2019-1112 [MEDIUM] CWE-200 CVE-2019-1112: An information disclosure vulnerability exists when Microsoft Excel improperly discloses the content
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information Disclosure Vulnerability'.
nvd
CVE-2019-1446P4MEDIUMCVSS 5.5v2010v2013+2 more2019-11-12
CVE-2019-1446 [MEDIUM] CWE-200 CVE-2019-1446: An information disclosure vulnerability exists when Microsoft Excel improperly discloses the content
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information Disclosure Vulnerability'.
nvd
CVE-2019-1464P4MEDIUMCVSS 5.5v2010v2013+2 more2019-12-10
CVE-2019-1464 [MEDIUM] CWE-200 CVE-2019-1464: An information disclosure vulnerability exists when Microsoft Excel improperly discloses the content
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information Disclosure Vulnerability'.
nvd
CVE-2016-0012P4MEDIUMCVSS 4.3v2007v2010+2 more2016-01-13
CVE-2016-0012 [MEDIUM] CWE-200 CVE-2016-0012: Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Offic
Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Visio 2010 SP2, Word 2010 SP2, Office 2013 SP1, Excel 2013 SP1, PowerPoint 2013 SP1, Visio 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Office 2016, Excel 2016, Po
nvd
CVE-2019-1263P4MEDIUMCVSS 5.5v2016v20192019-09-11
CVE-2019-1263 [MEDIUM] CWE-200 CVE-2019-1263: An information disclosure vulnerability exists when Microsoft Excel improperly discloses the content
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information Disclosure Vulnerability'.
nvd
CVE-2026-21258P4MEDIUMCVSS 5.5v20192026-02-10
CVE-2026-21258 [MEDIUM] CWE-20 CVE-2026-21258: Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose info
Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd