cbcvebase.

Microsoft Publisher vulnerabilities

42 known vulnerabilities affecting microsoft/publisher.

Total CVEs
42
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL29HIGH11MEDIUM2

Vulnerabilities

Page 1 of 3
CVE-2007-0671P2HIGHCVSS 8.8KEVv2000v2002+1 more2007-02-03
CVE-2007-0671 [HIGH] CVE-2007-0671: Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Of Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.
nvd
CVE-2024-38226P1HIGHCVSS 7.3KEVv20162024-09-10
CVE-2024-38226 [HIGH] CWE-693 CVE-2024-38226: Microsoft Publisher Security Feature Bypass Vulnerability Microsoft Publisher Security Feature Bypass Vulnerability
nvd
CVE-2004-0200P3CRITICALCVSS 9.3PoCv2002v20032004-09-28
CVE-2004-0200 [CRITICAL] CVE-2004-0200: Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.
nvd
CVE-2013-1322P2CRITICALCVSS 10.0v20032013-05-15
CVE-2013-1322 [CRITICAL] CVE-2013-1322: Microsoft Publisher 2003 SP3 does not properly check table range data, which allows remote attackers Microsoft Publisher 2003 SP3 does not properly check table range data, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Invalid Range Check Vulnerability."
nvd
CVE-2013-1318P2CRITICALCVSS 10.0v20032013-05-15
CVE-2013-1318 [CRITICAL] CWE-20 CVE-2013-1318: Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publish Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers access to an invalid pointer, aka "Publisher Corrupt Interface Pointer Vulnerability."
nvd
CVE-2013-1316P2CRITICALCVSS 9.3v20032013-05-15
CVE-2013-1316 [CRITICAL] CWE-20 CVE-2013-1316: Microsoft Publisher 2003 SP3 does not properly validate the size of an unspecified array, which allo Microsoft Publisher 2003 SP3 does not properly validate the size of an unspecified array, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Negative Value Allocation Vulnerability."
nvd
CVE-2013-1321P3CRITICALCVSS 9.3v20032013-05-15
CVE-2013-1321 [CRITICAL] CWE-20 CVE-2013-1321: Microsoft Publisher 2003 SP3 does not properly check the data type of an unspecified return value, w Microsoft Publisher 2003 SP3 does not properly check the data type of an unspecified return value, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Return Value Validation Vulnerability."
nvd
CVE-2013-1323P2CRITICALCVSS 9.3v20032013-05-15
CVE-2013-1323 [CRITICAL] CWE-94 CVE-2013-1323: Microsoft Publisher 2003 SP3 does not properly handle NULL values for unspecified data items, which Microsoft Publisher 2003 SP3 does not properly handle NULL values for unspecified data items, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Incorrect NULL Value Handling Vulnerability."
nvd
CVE-2013-1328P2CRITICALCVSS 9.3v2003v2007+1 more2013-05-15
CVE-2013-1328 [CRITICAL] CVE-2013-1328: Microsoft Publisher 2003 SP3, 2007 SP3, and 2010 SP1 allows remote attackers to execute arbitrary co Microsoft Publisher 2003 SP3, 2007 SP3, and 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers incorrect pointer handling, aka "Publisher Pointer Handling Vulnerability."
nvd
CVE-2013-1319P3CRITICALCVSS 10.0v20032013-05-15
CVE-2013-1319 [CRITICAL] CVE-2013-1319: Microsoft Publisher 2003 SP3 does not properly check the return value of an unspecified method, whic Microsoft Publisher 2003 SP3 does not properly check the return value of an unspecified method, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Return Value Handling Vulnerability."
nvd
CVE-2011-3412P3CRITICALCVSS 9.3v2003v20072011-12-14
CVE-2011-3412 [CRITICAL] CWE-94 CVE-2011-3412: Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, allows remote attackers to execute arbitrary cod Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, allows remote attackers to execute arbitrary code via a crafted Publisher file that leverages incorrect memory handling, aka "Publisher Memory Corruption Vulnerability."
nvd
CVE-2008-0102P3CRITICALCVSS 10.0v2000v2002+1 more2008-02-12
CVE-2008-0102 [CRITICAL] CWE-399 CVE-2008-0102: Unspecified vulnerability in Microsoft Office Publisher 2000, 2002, and 2003 SP2 allows remote attac Unspecified vulnerability in Microsoft Office Publisher 2000, 2002, and 2003 SP2 allows remote attackers to execute arbitrary code via a crafted .pub file, related to invalid "memory values," aka "Publisher Invalid Memory Reference Vulnerability."
nvd
CVE-2010-0479P3CRITICALCVSS 9.3v2002v2003+1 more2010-04-14
CVE-2010-0479 [CRITICAL] CWE-119 CVE-2010-0479: Buffer overflow in Microsoft Office Publisher 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 allows remote Buffer overflow in Microsoft Office Publisher 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Microsoft Office Publisher File Conversion TextBox Processing Buffer Overflow Vulnerability."
nvd
CVE-2011-3410P3CRITICALCVSS 9.3v2003v20072011-12-14
CVE-2011-3410 [CRITICAL] CWE-20 CVE-2011-3410: Array index error in Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, allows remote attackers to Array index error in Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, allows remote attackers to execute arbitrary code via a crafted Publisher file that leverages incorrect handling of values in memory, aka "Publisher Out-of-bounds Array Index Vulnerability."
nvd
CVE-2011-3411P3CRITICALCVSS 9.3v20032011-12-14
CVE-2011-3411 [CRITICAL] CWE-94 CVE-2011-3411: Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publish Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that leverages incorrect handling of values in memory, aka "Publisher Invalid Pointer Vulnerability."
nvd
CVE-2013-1317P3CRITICALCVSS 9.3v20032013-05-15
CVE-2013-1317 [CRITICAL] CWE-190 CVE-2013-1317: Integer overflow in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code v Integer overflow in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers an improper allocation-size calculation, aka "Publisher Integer Overflow Vulnerability."
nvd
CVE-2013-1329P3CRITICALCVSS 9.3v20032013-05-15
CVE-2013-1329 [CRITICAL] CWE-189 CVE-2013-1329: Integer signedness error in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrar Integer signedness error in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers a buffer underflow, aka "Publisher Buffer Underflow Vulnerability."
nvd
CVE-2013-1327P3CRITICALCVSS 9.3v20032013-05-15
CVE-2013-1327 [CRITICAL] CWE-189 CVE-2013-1327: Integer signedness error in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrar Integer signedness error in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers an improper memory allocation, aka "Publisher Signed Integer Vulnerability."
nvd
CVE-2010-3955P3CRITICALCVSS 9.3v20022010-12-16
CVE-2010-3955 [CRITICAL] CWE-94 CVE-2010-3955: pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3 does not properly perf pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3 does not properly perform array indexing, which allows remote attackers to execute arbitrary code via a crafted Publisher file that uses an old file format, aka "Array Indexing Memory Corruption Vulnerability."
nvd
CVE-2010-2571P3CRITICALCVSS 9.3v2002v20032010-12-16
CVE-2010-2571 [CRITICAL] CWE-20 CVE-2010-2571: Array index error in pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3 a Array index error in pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher 97 file, aka "Memory Corruption Due To Invalid Index Into Array in Pubconv.dll Vulnerability."
nvd
Microsoft Publisher vulnerabilities | cvebase