cbcvebase.

Microsoft Office vulnerabilities

1,005 known vulnerabilities affecting microsoft/office.

Total CVEs
1,005
CISA KEV
35
actively exploited
Public exploits
103
Exploited in wild
68
Severity breakdown
CRITICAL277HIGH567MEDIUM155LOW6

Vulnerabilities

Page 8 of 51
CVE-2024-21378P2HIGHCVSS 8.8v20192024-02-13
CVE-2024-21378 [HIGH] CWE-94 CVE-2024-21378: Microsoft Outlook Remote Code Execution Vulnerability Microsoft Outlook Remote Code Execution Vulnerability
nvd
CVE-2008-3015P2CRITICALCVSS 9.3v2003v2007+1 more2008-09-11
CVE-2008-3015 [CRITICAL] CWE-189 CVE-2008-3015: Integer overflow in gdiplus.dll in GDI+ in Microsoft Office XP SP3, Office 2003 SP2 and SP3, 2007 Mi Integer overflow in gdiplus.dll in GDI+ in Microsoft Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remot
nvd
CVE-2023-36041P3HIGHCVSS 7.8v20192023-11-14
CVE-2023-36041 [HIGH] CWE-416 CVE-2023-36041: Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2010-1263P2CRITICALCVSS 9.3v2003v2007+1 more2010-06-08
CVE-2010-1263 [CRITICAL] CWE-94 CVE-2010-1263: Windows Shell and WordPad in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vist Windows Shell and WordPad in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7; Microsoft Office XP SP3; Office 2003 SP3; and Office System 2007 SP1 and SP2 do not properly validate COM objects during instantiation, which allows remote attackers to execute arbitr
nvd
CVE-2023-33146P3HIGHCVSS 7.8PoCv20192023-06-14
CVE-2023-33146 [HIGH] CWE-122 CVE-2023-33146: Microsoft Office Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability
nvd
CVE-2023-32029P3HIGHCVSS 7.8v20192023-06-14
CVE-2023-32029 [HIGH] CWE-125 CVE-2023-32029: Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2013-1324P2CRITICALCVSS 9.3v2003v2007+2 more2013-11-13
CVE-2013-1324 [CRITICAL] CWE-119 CVE-2013-1324: Stack-based buffer overflow in Microsoft Office 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 Stack-based buffer overflow in Microsoft Office 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT allows remote attackers to execute arbitrary code via a crafted WordPerfect document (.wpd) file, aka "Word Stack Buffer Overwrite Vulnerability."
nvd
CVE-2012-0165P2CRITICALCVSS 9.3v2003v2007+1 more2012-05-09
CVE-2012-0165 [CRITICAL] CWE-20 CVE-2012-0165: GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2 and Office 2003 SP3, 2007 SP2 and SP3, and 2 GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2 and Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1 does not properly validate record types in EMF images, which allows remote attackers to execute arbitrary code via a crafted image, aka "GDI+ Record Type Vulnerability."
nvd
CVE-2011-0098P2CRITICALCVSS 9.3v2004v20082011-04-13
CVE-2011-0098 [CRITICAL] CWE-189 CVE-2011-0098: Integer signedness error in Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004 and Integer signedness error in Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 allows remote attackers to execute arbitrary code via an XLS file with a large record size, aka
nvd
CVE-2008-3006P2CRITICALCVSS 9.3v2000v2003+4 more2008-08-12
CVE-2008-3006 [CRITICAL] CWE-399 CVE-2008-3006: Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1; Office Excel Vie Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1; Office Excel Viewer 2003 Gold and SP3; Office Excel Viewer; Office Compatibility Pack 2007 Gold and SP1; Office SharePoint Server 2007 Gold and SP1; and Office 2004 and 2008 for Mac do not properly parse Country record values when loading Excel files, which allows re
nvd
CVE-2012-1885P2CRITICALCVSS 9.3v2008v20112012-11-14
CVE-2012-1885 [CRITICAL] CWE-119 CVE-2012-1885: Heap-based buffer overflow in Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Office 2008 Heap-based buffer overflow in Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Office 2008 and 2011 for Mac; and Office Compatibility Pack SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel SerAuxErrBar Heap Overflow Vulnerability."
nvd
CVE-2009-1533P2CRITICALCVSS 9.3v2000v20032009-06-10
CVE-2009-1533 [CRITICAL] CWE-119 CVE-2009-1533: Buffer overflow in the Works for Windows document converters in Microsoft Office 2000 SP3, Office XP Buffer overflow in the Works for Windows document converters in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, Office 2007 SP1, and Works 8.5 and 9 allows remote attackers to execute arbitrary code via a crafted Works .wps file that triggers memory corruption, aka "File Converter Buffer Overflow Vulnerability."
nvd
CVE-2012-0167P2CRITICALCVSS 9.3v2003v20072012-05-09
CVE-2012-0167 [CRITICAL] CWE-20 CVE-2012-0167: Heap-based buffer overflow in the Office GDI+ library in Microsoft Office 2003 SP3 and 2007 SP2 and Heap-based buffer overflow in the Office GDI+ library in Microsoft Office 2003 SP3 and 2007 SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted EMF image in an Office document, aka "GDI+ Heap Overflow Vulnerability."
nvd
CVE-2008-4019P2CRITICALCVSS 9.3v2004v20082008-10-15
CVE-2008-4019 [CRITICAL] CWE-190 CVE-2008-4019: Integer overflow in the REPT function in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2 Integer overflow in the REPT function in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1; Office Excel Viewer 2003 SP3; Office Excel Viewer; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; Office SharePoint Server 2007 Gold and SP1; Office 2004 and 2008 for Mac; and Open XML File
nvd
CVE-2015-2435P2CRITICALCVSS 9.3v2007v20102015-08-15
CVE-2015-2435 [CRITICAL] CWE-20 CVE-2015-2435: Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8 Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10, Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, Lync Basic 2013 SP1, and Silverlight before 5.1.40728 allow remote attacker
nvd
CVE-2015-6093P2CRITICALCVSS 9.3v2007v2010+2 more2015-11-11
CVE-2015-6093 [CRITICAL] CWE-119 CVE-2015-6093: Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Word A Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, Office Web Apps 2010 SP2, and Office Web Apps Server 2013 SP1 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulner
nvd
CVE-2021-34478P3HIGHCVSS 7.8v20192021-08-12
CVE-2021-34478 [HIGH] CVE-2021-34478: Microsoft Office Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability
nvd
CVE-2015-1650P2CRITICALCVSS 9.3v20102015-04-14
CVE-2015-1650 [CRITICAL] CVE-2015-1650: Use-after-free vulnerability in Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 S Use-after-free vulnerability in Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, and Office Web Apps Server 2010 SP2 and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted Office docu
nvd
CVE-2008-4028P3CRITICALCVSS 9.3v2004v20082008-12-10
CVE-2008-4028 [CRITICAL] CWE-119 CVE-2008-4028: Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Outlook 2007 Gold and SP1 Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Outlook 2007 Gold and SP1; Word Viewer 2003 Gold and SP3; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; Office 2004 and 2008 for Mac; and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via cr
nvd
CVE-2013-0007P3CRITICALCVSS 9.3v2003v20072013-01-09
CVE-2013-0007 [CRITICAL] CWE-94 CVE-2013-0007: Microsoft XML Core Services (aka MSXML) 4.0, 5.0, and 6.0 does not properly parse XML content, which Microsoft XML Core Services (aka MSXML) 4.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML XSLT Vulnerability."
nvd
Microsoft Office vulnerabilities | cvebase