Microsoft Powerpoint vulnerabilities
74 known vulnerabilities affecting microsoft/powerpoint.
Total CVEs
74
CISA KEV
4
actively exploited
Public exploits
10
Exploited in wild
6
Severity breakdown
CRITICAL24HIGH40MEDIUM9LOW1
Vulnerabilities
Page 2 of 4
CVE-2010-2573P3CRITICALCVSS 9.3v2002v20032010-11-10
CVE-2010-2573 [CRITICAL] CWE-189 CVE-2010-2573: Integer underflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3, PowerPoint Viewer SP2, and Office 2
Integer underflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3, PowerPoint Viewer SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint Integer Underflow Causes Heap Corruption Vulnerability."
nvd
CVE-2010-0030P3CRITICALCVSS 9.3v2002v20032010-02-10
CVE-2010-0030 [CRITICAL] CWE-119 CVE-2010-0030: Heap-based buffer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attack
Heap-based buffer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint LinkedSlideAtom Heap Overflow Vulnerability."
nvd
CVE-2011-0656P3CRITICALCVSS 9.3v2002v2003+2 more2011-04-13
CVE-2011-0656 [CRITICAL] CWE-20 CVE-2011-0656: Microsoft PowerPoint 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004, 2008, and 2011 for Mac; Op
Microsoft PowerPoint 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004, 2008, and 2011 for Mac; Open XML File Format Converter for Mac; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; PowerPoint Viewer; PowerPoint Viewer 2007 SP2; and PowerPoint Web App do not properly validate PersistDirectoryEntry records in Power
nvd
CVE-2006-3655P3MEDIUMCVSS 5.1PoCv20032006-07-18
CVE-2006-3655 [MEDIUM] CVE-2006-3655: Unspecified vulnerability in mso.dll in Microsoft PowerPoint 2003 allows user-assisted attackers to
Unspecified vulnerability in mso.dll in Microsoft PowerPoint 2003 allows user-assisted attackers to execute arbitrary code via a crafted PowerPoint file. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3656, CVE-2006-3660, and CVE-2006-3590, although it is possible that they are all different.
nvd
CVE-2011-0976P3CRITICALCVSS 9.3v20072011-02-10
CVE-2011-0976 [CRITICAL] CWE-264 CVE-2011-0976: Microsoft PowerPoint 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 and 2008 for Mac; Open XML File F
Microsoft PowerPoint 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; and PowerPoint Viewer 2007 SP2 do not properly handle Office Art containers that have invalid records, which allows remote attackers to execute a
nvd
CVE-2011-0655P3CRITICALCVSS 9.3v20102011-04-13
CVE-2011-0655 [CRITICAL] CWE-20 CVE-2011-0655: Microsoft PowerPoint 2007 SP2 and 2010; Office 2004, 2008, and 2011 for Mac; Open XML File Format Co
Microsoft PowerPoint 2007 SP2 and 2010; Office 2004, 2008, and 2011 for Mac; Open XML File Format Converter for Mac; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; PowerPoint Viewer; PowerPoint Viewer 2007 SP2; and PowerPoint Web App do not properly validate TimeColorBehaviorContainer Floating Point records in PowerP
nvd
CVE-2011-1270P3CRITICALCVSS 9.3v2002v20032011-05-13
CVE-2011-1270 [CRITICAL] CWE-119 CVE-2011-1270: Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arb
Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "Presentation Buffer Overrun RCE Vulnerability."
nvd
CVE-2011-3413P3CRITICALCVSS 9.3v20072011-12-14
CVE-2011-3413 [CRITICAL] CWE-94 CVE-2011-3413: Microsoft PowerPoint 2007 SP2; Office 2008 for Mac; Office Compatibility Pack for Word, Excel, and P
Microsoft PowerPoint 2007 SP2; Office 2008 for Mac; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; and PowerPoint Viewer 2007 SP2 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via an invalid OfficeArt record in a PowerPoint document, aka "OfficeArt Shape RCE Vulnera
nvd
CVE-2015-2503P3CRITICALCVSS 9.3v2007v2010+2 more2015-11-11
CVE-2015-2503 [CRITICAL] CWE-264 CVE-2015-2503: Microsoft Access 2007 SP3, Excel 2007 SP3, InfoPath 2007 SP3, OneNote 2007 SP3, PowerPoint 2007 SP3,
Microsoft Access 2007 SP3, Excel 2007 SP3, InfoPath 2007 SP3, OneNote 2007 SP3, PowerPoint 2007 SP3, Project 2007 SP3, Publisher 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Office 2007 IME (Japanese) SP3, Access 2010 SP2, Excel 2010 SP2, InfoPath 2010 SP2, OneNote 2010 SP2, PowerPoint 2010 SP2, Project 2010 SP2, Publisher 2010 SP2, Visio 2010 SP2, Word
nvd
CVE-2010-0032P3CRITICALCVSS 9.3v2002v20032010-02-10
CVE-2010-0032 [CRITICAL] CWE-94 CVE-2010-0032: Use-after-free vulnerability in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote atta
Use-after-free vulnerability in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "OEPlaceholderAtom Use After Free Vulnerability."
nvd
CVE-2020-0760P3HIGHCVSS 8.8v2010v2013+1 more2020-04-15
CVE-2020-0760 [HIGH] CVE-2020-0760: A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type l
A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries, aka 'Microsoft Office Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0991.
nvd
CVE-2010-0029P3CRITICALCVSS 9.3v20022010-02-10
CVE-2010-0029 [CRITICAL] CWE-119 CVE-2010-0029: Buffer overflow in Microsoft Office PowerPoint 2002 SP3 allows remote attackers to execute arbitrary
Buffer overflow in Microsoft Office PowerPoint 2002 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint File Path Handling Buffer Overflow Vulnerability."
nvd
CVE-2019-1462P3HIGHCVSS 7.8v2010v2013+1 more2019-12-10
CVE-2019-1462 [HIGH] CWE-908 CVE-2019-1462: A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fail
A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka 'Microsoft PowerPoint Remote Code Execution Vulnerability'.
nvd
CVE-2006-3449P3HIGHCVSS 7.5v2000v2001+2 more2006-08-09
CVE-2006-3449 [HIGH] CVE-2006-3449: Unspecified vulnerability in Microsoft PowerPoint 2000 through 2003, possibly a buffer overflow, all
Unspecified vulnerability in Microsoft PowerPoint 2000 through 2003, possibly a buffer overflow, allows user-assisted remote attackers to execute arbitrary commands via a malformed record in the BIFF file format used in a PPT file, a different issue than CVE-2006-1540, aka "Microsoft PowerPoint Malformed Record Vulnerability."
nvd
CVE-2016-3360P3HIGHCVSS 7.8v2007v2010+1 more2016-09-14
CVE-2016-3360 [HIGH] CWE-119 CVE-2016-3360: Microsoft PowerPoint 2007 SP3, PowerPoint 2010 SP2, PowerPoint 2013 SP1, PowerPoint 2013 RT SP1, Pow
Microsoft PowerPoint 2007 SP3, PowerPoint 2010 SP2, PowerPoint 2013 SP1, PowerPoint 2013 RT SP1, PowerPoint 2016 for Mac, Office Compatibility Pack SP3, PowerPoint Viewer, SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, and Office Web Apps Server 2013 SP1 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Offic
nvd
CVE-2017-8742P3HIGHCVSS 7.8v2007v2010+2 more2017-09-13
CVE-2017-8742 [HIGH] CWE-119 CVE-2017-8742: A remote code execution vulnerability exists in Microsoft PowerPoint 2007 Service Pack 3, Microsoft
A remote code execution vulnerability exists in Microsoft PowerPoint 2007 Service Pack 3, Microsoft PowerPoint 2010 Service Pack 2, Microsoft PowerPoint 2013 Service Pack 1, Microsoft PowerPoint 2013 RT Service Pack 1, Microsoft PowerPoint 2016, Microsoft PowerPoint Viewer 2007, Microsoft SharePoint Server 2013 Service Pack 1, Microsoft SharePoint Enterp
nvd
CVE-2016-7230P3HIGHCVSS 7.8v20102016-11-10
CVE-2016-7230 [HIGH] CWE-119 CVE-2016-7230: Microsoft PowerPoint 2010 SP2, PowerPoint Viewer, and Office Web Apps 2010 SP2 allow remote attacker
Microsoft PowerPoint 2010 SP2, PowerPoint Viewer, and Office Web Apps 2010 SP2 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2018-8628P3HIGHCVSS 7.8v2010-sp2v2013-sp1+1 more2018-12-12
CVE-2018-8628 [HIGH] CVE-2018-8628: A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fail
A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Microsoft Office, Office 365 ProPlus, Microsoft PowerPoint, Microsoft SharePoint, Microsoft PowerPoint Viewer, Office Online Server, Microsoft Sha
nvd
CVE-2024-39804P3CRITICALCVSS 9.1v16.83v16.83 for macOS2024-12-18
CVE-2024-39804 [CRITICAL] CWE-347 CVE-2024-39804: A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafte
A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can leverage PowerPoint's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and then make use of the vulnerable application's permissions.
nvd
CVE-2011-3396P3CRITICALCVSS 9.3v2007v20102011-12-14
CVE-2011-3396 [CRITICAL] CVE-2011-3396: Untrusted search path vulnerability in Microsoft PowerPoint 2007 SP2 and 2010 allows local users to
Untrusted search path vulnerability in Microsoft PowerPoint 2007 SP2 and 2010 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "PowerPoint Insecure Library Loading Vulnerability."
nvd