cbcvebase.

Microsoft Office Web Apps vulnerabilities

105 known vulnerabilities affecting microsoft/office_web_apps.

Total CVEs
105
CISA KEV
3
actively exploited
Public exploits
4
Exploited in wild
6
Severity breakdown
CRITICAL14HIGH66MEDIUM23LOW2

Vulnerabilities

Page 3 of 6
CVE-2017-8742P3HIGHCVSS 7.8v20102017-09-13
CVE-2017-8742 [HIGH] CWE-119 CVE-2017-8742: A remote code execution vulnerability exists in Microsoft PowerPoint 2007 Service Pack 3, Microsoft A remote code execution vulnerability exists in Microsoft PowerPoint 2007 Service Pack 3, Microsoft PowerPoint 2010 Service Pack 2, Microsoft PowerPoint 2013 Service Pack 1, Microsoft PowerPoint 2013 RT Service Pack 1, Microsoft PowerPoint 2016, Microsoft PowerPoint Viewer 2007, Microsoft SharePoint Server 2013 Service Pack 1, Microsoft SharePoint Enterp
nvd
CVE-2016-7230P3HIGHCVSS 7.8v20102016-11-10
CVE-2016-7230 [HIGH] CWE-119 CVE-2016-7230: Microsoft PowerPoint 2010 SP2, PowerPoint Viewer, and Office Web Apps 2010 SP2 allow remote attacker Microsoft PowerPoint 2010 SP2, PowerPoint Viewer, and Office Web Apps 2010 SP2 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2020-1335P3HIGHCVSS 8.8v20132020-09-11
CVE-2020-1335 [HIGH] CVE-2020-1335: <p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affecte
nvd
CVE-2022-21840P3HIGHCVSS 8.8v20132022-01-11
CVE-2022-21840 [HIGH] CVE-2022-21840: Microsoft Office Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability
nvd
CVE-2018-8628P3HIGHCVSS 7.8v2010-sp2v2013-sp12018-12-12
CVE-2018-8628 [HIGH] CVE-2018-8628: A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fail A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Microsoft Office, Office 365 ProPlus, Microsoft PowerPoint, Microsoft SharePoint, Microsoft PowerPoint Viewer, Office Online Server, Microsoft Sha
nvd
CVE-2016-0054P3HIGHCVSS 7.8v20102016-02-10
CVE-2016-0054 [HIGH] CWE-119 CVE-2016-0054: Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for M Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, Office Compatibility Pack SP3, Excel Viewer, Excel Services on SharePoint Server 2007 SP3, Excel Services on SharePoint Server 2010 SP2, Excel Services on SharePoint Server 2013 SP1, and Office Web Apps 2010 SP2 allow remote a
nvd
CVE-2018-8539P3HIGHCVSS 7.8v2010-sp22018-11-14
CVE-2018-8539 [HIGH] CVE-2018-8539: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka "Microsoft Word Remote Code Execution Vulnerability." This affects Microsoft SharePoint Server, Microsoft Office. This CVE ID is unique from CVE-2018-8573.
nvd
CVE-2020-1218P3HIGHCVSS 8.8v2010v20132020-09-11
CVE-2020-1218 [HIGH] CVE-2020-1218: <p>A remote code execution vulnerability exists in Microsoft Word software when it fails to properly A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with
nvd
CVE-2017-0020P3HIGHCVSS 7.8v20132017-03-17
CVE-2017-0020 [HIGH] CVE-2017-0020: Microsoft Excel 2016, Excel 2010 SP2, Excel 2013 RT SP1, and Office Web Apps Server 2013 SP1 allow r Microsoft Excel 2016, Excel 2010 SP2, Excel 2013 RT SP1, and Office Web Apps Server 2013 SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0006, CVE-2017-0019, CVE-20
nvd
CVE-2017-0281P3HIGHCVSS 7.8v2010v20132017-05-12
CVE-2017-0281 [HIGH] CVE-2017-0281: Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2016, Office Online Server 2016, Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2016, Office Online Server 2016, Office Web Apps 2010 SP2,Office Web Apps 2013 SP1, Project Server 2013 SP1, SharePoint Enterprise Server 2013 SP1, SharePoint Enterprise Server 2016, SharePoint Foundation 2013 SP1, Sharepoint Server 2010 SP2, Word 2016, and Skype for Business 2016 allow a remot
nvd
CVE-2016-0025P3HIGHCVSS 7.3v20102016-06-16
CVE-2016-0025 [HIGH] CWE-20 CVE-2016-0025: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Office 201 Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Office 2016, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, Office Web Apps Server 2013 SP1, an
nvd
CVE-2017-8511P3HIGHCVSS 7.8v20102017-06-15
CVE-2017-8511 [HIGH] CVE-2017-8511: A remote code execution vulnerability exists in Microsoft Office when the software fails to properly A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8509, CVE-2017-8510, CVE-2017-8512, CVE-2017-0260, and CVE-2017-8506.
nvd
CVE-2017-8632P3HIGHCVSS 7.8v20132017-09-13
CVE-2017-8632 [HIGH] CVE-2017-8632: A remote code execution vulnerability exists in Microsoft Excel 2010 Service Pack 2, Microsoft Excel A remote code execution vulnerability exists in Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Service Pack 1, Microsoft Excel 2013 RT Service Pack 1, Microsoft Excel 2016, Microsoft Office Web Apps 2013, Microsoft Excel for Mac 2011, Microsoft Excel 2016 for Mac, and Microsoft Office Compatibility Pack Service Pack 3, when they fail to properly hand
nvd
CVE-2017-8631P3HIGHCVSS 7.8v20132017-09-13
CVE-2017-8631 [HIGH] CVE-2017-8631: A remote code execution vulnerability exists in Excel Services, Microsoft Excel 2007 Service Pack 3, A remote code execution vulnerability exists in Excel Services, Microsoft Excel 2007 Service Pack 3, Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Service Pack 1, Microsoft Excel 2013 RT Service Pack 1, Microsoft Excel 2016, Microsoft Office Web Apps 2013, Microsoft Office Compatibility Pack Service Pack 3, Microsoft Excel Web App 2013 Service Pack
nvd
CVE-2020-0980P3HIGHCVSS 7.8v2010v20132020-04-15
CVE-2020-0980 [HIGH] CVE-2020-0980: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'.
nvd
CVE-2020-0892P3HIGHCVSS 7.8v20102020-03-12
CVE-2020-0892 [HIGH] CVE-2020-0892: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0850, CVE-2020-0851, CVE-2020-0852, CVE-2020-0855.
nvd
CVE-2013-3895P3MEDIUMCVSS 6.8v20102013-10-09
CVE-2013-3895 [MEDIUM] CWE-264 CVE-2013-3895: Microsoft SharePoint Server 2007 SP3 and 2010 SP1 and SP2 allows remote attackers to conduct clickja Microsoft SharePoint Server 2007 SP3 and 2010 SP1 and SP2 allows remote attackers to conduct clickjacking attacks via a crafted web page, aka "Parameter Injection Vulnerability."
nvd
CVE-2016-3279P3MEDIUMCVSS 5.5v20102016-07-13
CVE-2016-3279 [MEDIUM] CWE-254 CVE-2016-3279: Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Excel 2013 SP1, Power Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Excel 2013 SP1, PowerPoint 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Excel 2016, Word 2016, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to execute arbitrary code via
nvd
CVE-2021-38655P3HIGHCVSS 7.8v20132021-09-15
CVE-2021-38655 [HIGH] CWE-416 CVE-2021-38655: Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2020-16932P3HIGHCVSS 7.8v20132020-10-16
CVE-2020-16932 [HIGH] CWE-908 CVE-2020-16932: <p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of t
nvd
Microsoft Office Web Apps vulnerabilities | cvebase