cbcvebase.

Microsoft Word vulnerabilities

265 known vulnerabilities affecting microsoft/word.

Total CVEs
265
CISA KEV
10
actively exploited
Public exploits
20
Exploited in wild
18
Severity breakdown
CRITICAL79HIGH142MEDIUM42LOW2

Vulnerabilities

Page 10 of 14
CVE-2016-7233P3MEDIUMCVSS 6.5v2007v20102016-11-10
CVE-2016-7233 [MEDIUM] CWE-200 CVE-2016-7233: Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Excel for Mac 2011, Word Vie Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Excel for Mac 2011, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2013 SP1, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a c
nvd
CVE-2005-0564P3HIGHCVSS 7.5v2000v20022005-07-12
CVE-2005-0564 [HIGH] CVE-2005-0564: Stack-based buffer overflow in Microsoft Word 2000 and Word 2002, and Microsoft Works Suites 2000 th Stack-based buffer overflow in Microsoft Word 2000 and Word 2002, and Microsoft Works Suites 2000 through 2004, might allow remote attackers to execute arbitrary code via a .doc file with long font information.
nvd
CVE-2025-27747P3HIGHCVSS 7.8v20162025-04-08
CVE-2025-27747 [HIGH] CWE-822 CVE-2025-27747: Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-24079P3HIGHCVSS 7.8v20162025-03-11
CVE-2025-24079 [HIGH] CWE-416 CVE-2025-24079: Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-47168P3HIGHCVSS 7.8v20162025-06-10
CVE-2025-47168 [HIGH] CWE-416 CVE-2025-47168: Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-49698P3HIGHCVSS 7.8v20162025-07-08
CVE-2025-49698 [HIGH] CWE-416 CVE-2025-49698: Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-49703P3HIGHCVSS 7.8v20162025-07-08
CVE-2025-49703 [HIGH] CWE-416 CVE-2025-49703: Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-49700P3HIGHCVSS 7.8v20162025-07-08
CVE-2025-49700 [HIGH] CWE-416 CVE-2025-49700: Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-29816P3HIGHCVSS 7.5v20162025-04-08
CVE-2025-29816 [HIGH] CWE-349 CVE-2025-29816: Improper input validation in Microsoft Office Word allows an unauthorized attacker to bypass a secur Improper input validation in Microsoft Office Word allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2006-3877P3CRITICALCVSS 9.3v2000v2002+1 more2006-10-10
CVE-2006-3877 [CRITICAL] CVE-2006-3877: Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2 Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via an unspecified "crafted file," a different vulnerability than CVE-2006-3435, CVE-2006-4694, and CVE-2006-3876.
nvd
CVE-2021-28453P3HIGHCVSS 7.8v2010v2013+1 more2021-04-13
CVE-2021-28453 [HIGH] CVE-2021-28453: Microsoft Word Remote Code Execution Vulnerability Microsoft Word Remote Code Execution Vulnerability
nvd
CVE-2004-0848P3HIGHCVSS 7.5v20022005-02-08
CVE-2004-0848 [HIGH] CVE-2004-0848: Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link with a URL file location containing long inputs after (1) "%00 (null byte) in .doc filenames or (2) "%0a" (carriage return) in .rtf filenames.
nvd
CVE-2024-21379P3HIGHCVSS 7.8v20162024-02-13
CVE-2024-21379 [HIGH] CWE-190 CVE-2024-21379: Microsoft Word Remote Code Execution Vulnerability Microsoft Word Remote Code Execution Vulnerability
nvd
CVE-2003-0820P3HIGHCVSS 7.5v97v98+2 more2003-12-15
CVE-2003-0820 [HIGH] CVE-2003-0820: Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not prope Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.
nvd
CVE-2026-45471P3HIGHCVSS 7.8v20162026-06-09
CVE-2026-45471 [HIGH] CWE-822 CVE-2026-45471: Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute co Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2003-0821P3HIGHCVSS 7.5v97v98+2 more2003-12-15
CVE-2003-0821 [HIGH] CVE-2003-0821: Microsoft Excel 97, 2000, and 2002 allows remote attackers to execute arbitrary code via a spreadshe Microsoft Excel 97, 2000, and 2002 allows remote attackers to execute arbitrary code via a spreadsheet with a malicious XLM (Excel 4) macro that bypasses the macro security model.
nvd
CVE-2019-1034P3HIGHCVSS 7.8v2010v2013+1 more2019-06-12
CVE-2019-1034 [HIGH] CVE-2019-1034: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with
nvd
CVE-2019-1201P3HIGHCVSS 7.8v2010v2013+1 more2019-08-14
CVE-2019-1201 [HIGH] CVE-2019-1201: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. The file could then take actions on behalf of the logged-on user with the same perm
nvd
CVE-2021-1716P3HIGHCVSS 7.8v2010v2013+1 more2021-01-12
CVE-2021-1716 [HIGH] CVE-2021-1716: Microsoft Word Remote Code Execution Vulnerability Microsoft Word Remote Code Execution Vulnerability
nvd
CVE-2021-1715P3HIGHCVSS 7.8v2010v2013+1 more2021-01-12
CVE-2021-1715 [HIGH] CWE-787 CVE-2021-1715: Microsoft Word Remote Code Execution Vulnerability Microsoft Word Remote Code Execution Vulnerability
nvd
Microsoft Word vulnerabilities | cvebase