Microsoft Office Web Apps Server vulnerabilities

61 known vulnerabilities affecting microsoft/office_web_apps_server.

Total CVEs
61
CISA KEV
2
actively exploited
Public exploits
3
Exploited in wild
2
Severity breakdown
CRITICAL6HIGH42MEDIUM12LOW1

Vulnerabilities

Page 2 of 4
CVE-2021-31177HIGHCVSS 7.8v20132021-05-11
CVE-2021-31177 [HIGH] CWE-416 CVE-2021-31177: Microsoft Office Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability
nvd
CVE-2021-31176HIGHCVSS 7.8v20132021-05-11
CVE-2021-31176 [HIGH] CWE-416 CVE-2021-31176: Microsoft Office Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability
nvd
CVE-2021-31178MEDIUMCVSS 5.5v20132021-05-11
CVE-2021-31178 [MEDIUM] CWE-191 CVE-2021-31178: Microsoft Office Information Disclosure Vulnerability Microsoft Office Information Disclosure Vulnerability
nvd
CVE-2021-31174MEDIUMCVSS 5.5v20132021-05-11
CVE-2021-31174 [MEDIUM] CWE-125 CVE-2021-31174: Microsoft Excel Information Disclosure Vulnerability Microsoft Excel Information Disclosure Vulnerability
nvd
CVE-2021-28453HIGHCVSS 7.8v20132021-04-13
CVE-2021-28453 [HIGH] CVE-2021-28453: Microsoft Word Remote Code Execution Vulnerability Microsoft Word Remote Code Execution Vulnerability
nvd
CVE-2021-28451HIGHCVSS 7.8v20132021-04-13
CVE-2021-28451 [HIGH] CVE-2021-28451: Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2021-28454HIGHCVSS 7.8v20132021-04-13
CVE-2021-28454 [HIGH] CWE-416 CVE-2021-28454: Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2021-28456MEDIUMCVSS 5.5v20132021-04-13
CVE-2021-28456 [MEDIUM] CVE-2021-28456: Microsoft Excel Information Disclosure Vulnerability Microsoft Excel Information Disclosure Vulnerability
nvd
CVE-2021-1716HIGHCVSS 7.8v20132021-01-12
CVE-2021-1716 [HIGH] CVE-2021-1716: Microsoft Word Remote Code Execution Vulnerability Microsoft Word Remote Code Execution Vulnerability
nvd
CVE-2021-1713HIGHCVSS 7.8v20132021-01-12
CVE-2021-1713 [HIGH] CWE-119 CVE-2021-1713: Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2021-1714HIGHCVSS 7.8v20132021-01-12
CVE-2021-1714 [HIGH] CVE-2021-1714: Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2021-1715HIGHCVSS 7.8v20132021-01-12
CVE-2021-1715 [HIGH] CWE-787 CVE-2021-1715: Microsoft Word Remote Code Execution Vulnerability Microsoft Word Remote Code Execution Vulnerability
nvd
CVE-2019-1201HIGHCVSS 7.8v20132019-08-14
CVE-2019-1201 [HIGH] CVE-2019-1201: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. The file could then take actions on behalf of the logged-on user with the same perm
nvd
CVE-2019-0585HIGHCVSS 8.8v20102019-01-08
CVE-2019-0585 [HIGH] CVE-2019-0585: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka "Microsoft Word Remote Code Execution Vulnerability." This affects Word, Microsoft Office, Microsoft Office Word Viewer, Office 365 ProPlus, Microsoft SharePoint, Microsoft Office Online Server, Microsoft Word, Microsoft SharePoint Ser
nvd
CVE-2019-0561MEDIUMCVSS 5.5v20102019-01-08
CVE-2019-0561 [MEDIUM] CVE-2019-0561: An information disclosure vulnerability exists when Microsoft Word macro buttons are used improperly An information disclosure vulnerability exists when Microsoft Word macro buttons are used improperly, aka "Microsoft Word Information Disclosure Vulnerability." This affects Microsoft Word, Office 365 ProPlus, Microsoft Office, Word.
nvd
CVE-2018-8577HIGHCVSS 7.8v20132018-11-14
CVE-2018-8577 [HIGH] CVE-2018-8577: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Office, Office 365 ProPlus, Microsoft Excel, Microsoft Excel Viewer, Excel. This CVE ID is unique from CVE-2018-8574.
nvd
CVE-2018-0919LOWCVSS 3.3v20132018-03-14
CVE-2018-0919 [LOW] CWE-125 CVE-2018-0919: Microsoft Office 2010 SP2, 2013 SP1, and 2016, Microsoft Office 2016 Click-to-Run Microsoft Office 2 Microsoft Office 2010 SP2, 2013 SP1, and 2016, Microsoft Office 2016 Click-to-Run Microsoft Office 2016 for Mac, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps 2013 SP1, Microsoft SharePoint Enterprise Server 2013 SP1, Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2010 SP2, Microsoft Word 2010 SP2, Word 2013 SP1
nvd
CVE-2018-0797HIGHCVSS 7.8v20132018-01-10
CVE-2018-0797 [HIGH] CWE-787 CVE-2018-0797: Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code executio Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way RTF content is handled, aka "Microsoft Word Memory Corruption Vulnerability".
nvd
CVE-2017-11826HIGHCVSS 7.8KEVv2010v20132017-10-13
CVE-2017-11826 [HIGH] CWE-119 CVE-2017-11826: Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office Online Server allow remote code execution when the software fails to properly handle objects in memory.
nvd
CVE-2017-8742HIGHCVSS 7.8v20132017-09-13
CVE-2017-8742 [HIGH] CWE-119 CVE-2017-8742: A remote code execution vulnerability exists in Microsoft PowerPoint 2007 Service Pack 3, Microsoft A remote code execution vulnerability exists in Microsoft PowerPoint 2007 Service Pack 3, Microsoft PowerPoint 2010 Service Pack 2, Microsoft PowerPoint 2013 Service Pack 1, Microsoft PowerPoint 2013 RT Service Pack 1, Microsoft PowerPoint 2016, Microsoft PowerPoint Viewer 2007, Microsoft SharePoint Server 2013 Service Pack 1, Microsoft SharePoint Enterp
nvd