cbcvebase.

Microsoft Project vulnerabilities

30 known vulnerabilities affecting microsoft/project.

Total CVEs
30
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
4
Severity breakdown
CRITICAL13HIGH14MEDIUM3

Vulnerabilities

Page 2 of 2
CVE-2006-3864P3CRITICALCVSS 9.3v2000v20022006-10-10
CVE-2006-3864 [CRITICAL] CVE-2006-3864: Unspecified vulnerability in mso.dll in Microsoft Office 2000, XP, and 2003, and Microsoft PowerPoin Unspecified vulnerability in mso.dll in Microsoft Office 2000, XP, and 2003, and Microsoft PowerPoint 2000, XP, and 2003, allows remote user-assisted attackers to execute arbitrary code via a malformed record in a (1) .DOC, (2) .PPT, or (3) .XLS file that triggers memory corruption, related to an "array boundary condition" (possibly an array index overflow)
nvd
CVE-2006-3877P3CRITICALCVSS 9.3v2000v2002+1 more2006-10-10
CVE-2006-3877 [CRITICAL] CVE-2006-3877: Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2 Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via an unspecified "crafted file," a different vulnerability than CVE-2006-3435, CVE-2006-4694, and CVE-2006-3876.
nvd
CVE-2004-0848P3HIGHCVSS 7.5v20022005-02-08
CVE-2004-0848 [HIGH] CVE-2004-0848: Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link with a URL file location containing long inputs after (1) "%00 (null byte) in .doc filenames or (2) "%0a" (carriage return) in .rtf filenames.
nvd
CVE-2002-0727P3HIGHCVSS 7.5v20022002-09-24
CVE-2002-0727 [HIGH] CVE-2002-0727: The Host function in Microsoft Office Web Components (OWC) 2000 and 2002 is exposed in components th The Host function in Microsoft Office Web Components (OWC) 2000 and 2002 is exposed in components that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via the setTimeout method.
nvd
CVE-2019-1264P3HIGHCVSS 7.8v2010v2013+1 more2019-09-11
CVE-2019-1264 [HIGH] CWE-20 CVE-2019-1264: A security feature bypass vulnerability exists when Microsoft Office improperly handles input, aka ' A security feature bypass vulnerability exists when Microsoft Office improperly handles input, aka 'Microsoft Office Security Feature Bypass Vulnerability'.
nvd
CVE-2000-0419P4HIGHCVSS 7.5v20002000-05-11
CVE-2000-0419 [HIGH] CVE-2000-0419: The Office 2000 UA ActiveX Control is marked as "safe for scripting," which allows remote attackers The Office 2000 UA ActiveX Control is marked as "safe for scripting," which allows remote attackers to conduct unauthorized activities via the "Show Me" function in Office Help, aka the "Office 2000 UA Control" vulnerability.
nvd
CVE-2002-0861P4HIGHCVSS 7.5v2000v20022002-09-24
CVE-2002-0861 [HIGH] CVE-2002-0861: Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to bypass the "Allow pas Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to bypass the "Allow paste operations via script" setting, even when it is disabled, via the (1) Copy method of the Cell object or (2) the Paste method of the Range object.
nvd
CVE-2020-1322P4MEDIUMCVSS 6.5v2010v2013+1 more2020-06-09
CVE-2020-1322 [MEDIUM] CWE-125 CVE-2020-1322: An information disclosure vulnerability exists when Microsoft Project reads out of bound memory due An information disclosure vulnerability exists when Microsoft Project reads out of bound memory due to an uninitialized variable, aka 'Microsoft Project Information Disclosure Vulnerability'.
nvd
CVE-2002-0860P4MEDIUMCVSS 5.0v2000v20022002-09-24
CVE-2002-0860 [MEDIUM] CVE-2002-0860: The LoadText method in the spreadsheet component in Microsoft Office Web Components (OWC) 2000 and 2 The LoadText method in the spreadsheet component in Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to read arbitrary files through Internet Explorer via a URL that redirects to the target file.
nvd
CVE-1999-0384P4MEDIUMCVSS 4.6v981999-01-01
CVE-1999-0384 [MEDIUM] CVE-1999-0384: The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content.
nvd
Microsoft Project vulnerabilities | cvebase