cbcvebase.

Microsoft Office Web Apps vulnerabilities

105 known vulnerabilities affecting microsoft/office_web_apps.

Total CVEs
105
CISA KEV
3
actively exploited
Public exploits
4
Exploited in wild
6
Severity breakdown
CRITICAL14HIGH66MEDIUM23LOW2

Vulnerabilities

Page 4 of 6
CVE-2020-16931P3HIGHCVSS 7.8v20132020-10-16
CVE-2020-16931 [HIGH] CWE-908 CVE-2020-16931: <p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of t
nvd
CVE-2020-16929P3HIGHCVSS 7.8v2010v20132020-10-16
CVE-2020-16929 [HIGH] CWE-416 CVE-2020-16929: <p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of t
nvd
CVE-2020-17128P3HIGHCVSS 7.8v20132020-12-10
CVE-2020-17128 [HIGH] CVE-2020-17128: Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2016-7233P3MEDIUMCVSS 6.5v20102016-11-10
CVE-2016-7233 [MEDIUM] CWE-200 CVE-2016-7233: Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Excel for Mac 2011, Word Vie Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Excel for Mac 2011, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2013 SP1, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a c
nvd
CVE-2021-28453P3HIGHCVSS 7.8v20102021-04-13
CVE-2021-28453 [HIGH] CVE-2021-28453: Microsoft Word Remote Code Execution Vulnerability Microsoft Word Remote Code Execution Vulnerability
nvd
CVE-2021-27053P3HIGHCVSS 7.8v20132021-03-11
CVE-2021-27053 [HIGH] CVE-2021-27053: Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2013-5059P3MEDIUMCVSS 6.8v20132013-12-11
CVE-2013-5059 [MEDIUM] CWE-94 CVE-2013-5059: Microsoft SharePoint Server 2010 SP1 and SP2 and 2013, and Office Web Apps 2013, allows remote attac Microsoft SharePoint Server 2010 SP1 and SP2 and 2013, and Office Web Apps 2013, allows remote attackers to execute arbitrary code via crafted page content, aka "SharePoint Page Content Vulnerabilities."
nvd
CVE-2019-1034P3HIGHCVSS 7.8v20102019-06-12
CVE-2019-1034 [HIGH] CVE-2019-1034: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with
nvd
CVE-2019-1201P3HIGHCVSS 7.8v20102019-08-14
CVE-2019-1201 [HIGH] CVE-2019-1201: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. The file could then take actions on behalf of the logged-on user with the same perm
nvd
CVE-2020-17065P3HIGHCVSS 7.8v20132020-11-11
CVE-2020-17065 [HIGH] CVE-2020-17065: Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2021-1716P3HIGHCVSS 7.8v20102021-01-12
CVE-2021-1716 [HIGH] CVE-2021-1716: Microsoft Word Remote Code Execution Vulnerability Microsoft Word Remote Code Execution Vulnerability
nvd
CVE-2021-1715P3HIGHCVSS 7.8v20102021-01-12
CVE-2021-1715 [HIGH] CWE-787 CVE-2021-1715: Microsoft Word Remote Code Execution Vulnerability Microsoft Word Remote Code Execution Vulnerability
nvd
CVE-2020-17123P3HIGHCVSS 7.8v20132020-12-10
CVE-2020-17123 [HIGH] CVE-2020-17123: Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2020-17122P3HIGHCVSS 7.8v20102020-12-10
CVE-2020-17122 [HIGH] CVE-2020-17122: Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2020-17129P3HIGHCVSS 7.8v20132020-12-10
CVE-2020-17129 [HIGH] CVE-2020-17129: Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2020-17125P3HIGHCVSS 7.8v20132020-12-10
CVE-2020-17125 [HIGH] CVE-2020-17125: Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2020-17064P3HIGHCVSS 7.8v20132020-11-11
CVE-2020-17064 [HIGH] CVE-2020-17064: Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2021-27054P3HIGHCVSS 7.8v20132021-03-11
CVE-2021-27054 [HIGH] CVE-2021-27054: Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2016-7291P3HIGHCVSS 7.1v20102016-12-20
CVE-2016-7291 [HIGH] CVE-2016-7291: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word for Mac Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word for Mac 2011, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted document, aka "Microsoft Office
nvd
CVE-2016-7290P3HIGHCVSS 7.1v20102016-12-20
CVE-2016-7290 [HIGH] CWE-125 CVE-2016-7290: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word for Mac Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word for Mac 2011, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted document, aka "Microsoft
nvd
Microsoft Office Web Apps vulnerabilities | cvebase