Microsoft Powerpoint vulnerabilities
74 known vulnerabilities affecting microsoft/powerpoint.
Total CVEs
74
CISA KEV
4
actively exploited
Public exploits
10
Exploited in wild
6
Severity breakdown
CRITICAL24HIGH40MEDIUM9LOW1
Vulnerabilities
Page 1 of 4
CVE-2009-0556P1HIGHCVSS 8.8KEVv2000v2002+1 more2009-04-03
CVE-2009-0556 [HIGH] CWE-94 CVE-2009-0556: Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 200
Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an an invalid index value that triggers memory corruption, as exploited in the wild in April 2009 by Exploit:Win32/Apptom.gen, aka "Mem
nvd
CVE-2015-2424P1HIGHCVSS 8.8KEVv2007v20102015-07-14
CVE-2015-2424 [HIGH] CWE-787 CVE-2015-2424: Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP
Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2010-2572P2HIGHCVSS 7.8KEVv2002v20032010-11-10
CVE-2010-2572 [HIGH] CWE-120 CVE-2010-2572: Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arb
Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95 document, aka "PowerPoint Parsing Buffer Overflow Vulnerability."
nvd
CVE-2007-0671P2HIGHCVSS 8.8KEVv2000v2002+1 more2007-02-03
CVE-2007-0671 [HIGH] CVE-2007-0671: Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Of
Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.
nvd
CVE-2011-1269P2CRITICALCVSS 9.3Exploitedv2002v2003+1 more2011-05-13
CVE-2011-1269 [CRITICAL] CWE-20 CVE-2011-1269: Microsoft PowerPoint 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 and 2008 for Mac; Open XML File F
Microsoft PowerPoint 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 make unspecified function calls during file parsing without proper handling of memory, which allows remote attackers to execute arbitrary code
nvd
CVE-2006-3590P2MEDIUMCVSS 5.1Exploitedv2000v2002+1 more2006-07-14
CVE-2006-3590 [MEDIUM] CWE-94 CVE-2006-3590: mso.dll, as used by Microsoft PowerPoint 2000 through 2003, allows user-assisted attackers to execut
mso.dll, as used by Microsoft PowerPoint 2000 through 2003, allows user-assisted attackers to execute arbitrary commands via a malformed shape container in a PPT file that leads to memory corruption, as exploited by Trojan.PPDropper.B, a different issue than CVE-2006-1540 and CVE-2006-3493.
nvd
CVE-2015-0097P2CRITICALCVSS 9.3PoCv2007v20102015-03-11
CVE-2015-0097 [CRITICAL] CWE-19 CVE-2015-0097: Microsoft Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Excel 2010 SP2, PowerPoint 2010 SP2, a
Microsoft Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Excel 2010 SP2, PowerPoint 2010 SP2, and Word 2010 SP2 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Word Local Zone Remote Code Execution Vulnerability."
nvd
CVE-2010-0033P2CRITICALCVSS 9.3PoCv20032010-02-10
CVE-2010-0033 [CRITICAL] CWE-119 CVE-2010-0033: Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execu
Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint Viewer TextBytesAtom Record Stack Overflow Vulnerability."
nvd
CVE-2004-0200P3CRITICALCVSS 9.3PoCv2002v20032004-09-28
CVE-2004-0200 [CRITICAL] CVE-2004-0200: Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.
nvd
CVE-2010-3142P3CRITICALCVSS 9.3PoCv20072010-08-27
CVE-2010-3142 [CRITICAL] CVE-2010-3142: Untrusted search path vulnerability in Microsoft Office PowerPoint 2007 allows local users, and poss
Untrusted search path vulnerability in Microsoft Office PowerPoint 2007 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse rpawinet.dll that is located in the same folder as a .odp, .pothtml, .potm, .potx, .ppa, .ppam, .pps, .ppt, .ppthtml, .pptm, .pptxml, .pwz, .sldm, .sldx, and
nvd
CVE-2025-47175P3HIGHCVSS 7.8PoCv20162025-06-10
CVE-2025-47175 [HIGH] CWE-416 CVE-2025-47175: Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locall
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
nvd
CVE-2010-3141P3CRITICALCVSS 9.3PoCv20102010-08-27
CVE-2010-3141 [CRITICAL] CVE-2010-3141: Untrusted search path vulnerability in Microsoft PowerPoint 2010 allows local users, and possibly re
Untrusted search path vulnerability in Microsoft PowerPoint 2010 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse pptimpconv.dll that is located in the same folder as a .odp, .pot, .potm, .potx, .ppa, .pps, .ppsm, .ppsx, .ppt, .pptm, .pptx, .pwz, .sldm, or .sldx file.
nvd
CVE-2006-3660P3HIGHCVSS 7.6PoCv20032006-07-18
CVE-2006-3660 [HIGH] CVE-2006-3660: Unspecified vulnerability in Microsoft PowerPoint 2003 has unknown impact and user-assisted attack v
Unspecified vulnerability in Microsoft PowerPoint 2003 has unknown impact and user-assisted attack vectors related to powerpnt.exe. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3655, CVE-2006-3656, and CVE-2006-3590, although it is possible that they are all different.
nvd
CVE-2018-8376P2HIGHCVSS 8.8v2010-sp22018-08-15
CVE-2018-8376 [HIGH] CVE-2018-8376: A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fail
A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Microsoft PowerPoint.
nvd
CVE-2015-1682P2CRITICALCVSS 9.3v2010v2011+1 more2015-05-13
CVE-2015-1682 [CRITICAL] CWE-119 CVE-2015-1682: Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Office 2013 SP1, Exce
Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Office 2013 SP1, Excel 2013 SP1, PowerPoint 2013 SP1, Word 2013 SP1, Office 2013 RT SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Office for Mac 2011, Excel for Mac 2011, PowerPoint for Mac 2011, Word for Mac 2011, PowerPoint Viewer, Word Automation Se
nvd
CVE-2018-8501P2HIGHCVSS 8.8v2010-sp2v2013-sp1+1 more2018-10-10
CVE-2018-8501 [HIGH] CVE-2018-8501: A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fail
A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in Protected View, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Office 365 ProPlus, PowerPoint Viewer, Microsoft Office, Microsoft PowerPoint.
nvd
CVE-2009-0224P3CRITICALCVSS 9.3v2004v20082009-05-12
CVE-2009-0224 [CRITICAL] CWE-94 CVE-2009-0224: Microsoft Office PowerPoint 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; PowerPoint Viewer 20
Microsoft Office PowerPoint 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; PowerPoint Viewer 2003 and 2007 SP1 and SP2; PowerPoint in Microsoft Office 2004 for Mac and 2008 for Mac; Open XML File Format Converter for Mac; Microsoft Works 8.5 and 9.0; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 an
nvd
CVE-2015-0085P2CRITICALCVSS 9.3v2007v20102015-03-11
CVE-2015-0085 [CRITICAL] CVE-2015-0085: Use-after-free vulnerability in Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Word
Use-after-free vulnerability in Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Office 2013 Gold and SP1, Word 2013 Gold and SP1, Office 2013 RT Gold and SP1, Word 2013 RT Gold and SP1, Excel Viewer, Office Compatibility Pack SP3, Word Automation Services on
nvd
CVE-2010-0034P3CRITICALCVSS 9.3v20032010-02-10
CVE-2010-0034 [CRITICAL] CWE-119 CVE-2010-0034: Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execu
Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "Office PowerPoint Viewer TextCharsAtom Record Stack Overflow Vulnerability."
nvd
CVE-2010-0031P3CRITICALCVSS 9.3v2002v20032010-02-10
CVE-2010-0031 [CRITICAL] CWE-94 CVE-2010-0031: Array index error in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3, and PowerPoint in Office 200
Array index error in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3, and PowerPoint in Office 2004 for Mac, allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint OEPlaceholderAtom 'placementId' Invalid Array Indexing Vulnerability."
nvd
1 / 4Next →