Microsoft Word vulnerabilities
265 known vulnerabilities affecting microsoft/word.
Total CVEs
265
CISA KEV
10
actively exploited
Public exploits
20
Exploited in wild
18
Severity breakdown
CRITICAL79HIGH142MEDIUM42LOW2
Vulnerabilities
Page 2 of 14
CVE-2015-2470P2CRITICALCVSS 9.3PoCv20072015-08-15
CVE-2015-2470 [CRITICAL] CWE-189 CVE-2015-2470: Integer underflow in Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1
Integer underflow in Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office for Mac 2011, and Word Viewer allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Integer Underflow Vulnerability."
nvd
CVE-2015-2469P2CRITICALCVSS 9.3PoCv2007v20102015-08-15
CVE-2015-2469 [CRITICAL] CWE-119 CVE-2015-2469: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, and Office for Mac 2011 allow remote attack
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, and Office for Mac 2011 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2015-0064P2CRITICALCVSS 9.3PoCv2007v20102015-02-11
CVE-2015-0064 [CRITICAL] CWE-399 CVE-2015-0064: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word Automation Services in SharePoint Serv
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word Automation Services in SharePoint Server 2010, Web Applications 2010 SP2, Word Viewer, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Office Remote Code Execution Vulne
nvd
CVE-2016-3316P2HIGHCVSS 7.8PoCv2013v20162016-08-09
CVE-2016-3316 [HIGH] CWE-119 CVE-2016-3316: Microsoft Word 2013 SP1, 2013 RT SP1, 2016, and 2016 for Mac allow remote attackers to execute arbit
Microsoft Word 2013 SP1, 2013 RT SP1, 2016, and 2016 for Mac allow remote attackers to execute arbitrary code via a crafted file, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2010-1900P2CRITICALCVSS 9.3PoCv2002v2003+1 more2010-08-11
CVE-2010-1900 [CRITICAL] CWE-94 CVE-2010-1900: Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2; Microsoft Office 2004 and 2008 for Mac; Open
Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2; Microsoft Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Word Viewer; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; and Works 9 do not properly handle malformed records in a Word file, which allows remote attackers to execute arbit
nvd
CVE-2015-0065P2CRITICALCVSS 9.3PoCv20072015-02-11
CVE-2015-0065 [CRITICAL] CWE-399 CVE-2015-0065: Microsoft Word 2007 SP3 allows remote attackers to execute arbitrary code or cause a denial of servi
Microsoft Word 2007 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "OneTableDocumentStream Remote Code Execution Vulnerability."
nvd
CVE-2004-0200P3CRITICALCVSS 9.3PoCv2002v20032004-09-28
CVE-2004-0200 [CRITICAL] CVE-2004-0200: Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.
nvd
CVE-2012-0183P2CRITICALCVSS 9.3PoCv2003v20072012-05-09
CVE-2012-0183 [CRITICAL] CVE-2012-0183: Microsoft Word 2003 SP3 and 2007 SP2 and SP3, Office 2008 and 2011 for Mac, and Office Compatibility
Microsoft Word 2003 SP3 and 2007 SP2 and SP3, Office 2008 and 2011 for Mac, and Office Compatibility Pack SP2 and SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, aka "RTF Mismatch Vulnerability."
nvd
CVE-2012-0182P2CRITICALCVSS 9.3v20072012-10-09
CVE-2012-0182 [CRITICAL] CWE-94 CVE-2012-0182: Microsoft Word 2007 SP2 and SP3 does not properly handle memory during the parsing of Word documents
Microsoft Word 2007 SP2 and SP3 does not properly handle memory during the parsing of Word documents, which allows remote attackers to execute arbitrary code via a crafted document, aka "Word PAPX Section Corruption Vulnerability."
nvd
CVE-2015-6172P2CRITICALCVSS 9.3v2007v2010+1 more2015-12-09
CVE-2015-6172 [CRITICAL] CWE-20 CVE-2015-6172: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2016, Word 2013 RT SP1,
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2016, Word 2013 RT SP1, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted email message processed by Outlook, aka "Microsoft Office RCE Vulnerability."
nvd
CVE-2008-2752P3HIGHCVSS 7.1PoCv2000v20032008-06-18
CVE-2008-2752 [HIGH] CWE-399 CVE-2008-2752: Microsoft Word 2000 9.0.2812 and 2003 11.8106.8172 does not properly handle unordered lists, which a
Microsoft Word 2000 9.0.2812 and 2003 11.8106.8172 does not properly handle unordered lists, which allows user-assisted remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .doc file. NOTE: some of these details are obtained from third party information.
nvd
CVE-2015-1650P2CRITICALCVSS 9.3v2007v2010+1 more2015-04-14
CVE-2015-1650 [CRITICAL] CVE-2015-1650: Use-after-free vulnerability in Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 S
Use-after-free vulnerability in Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, and Office Web Apps Server 2010 SP2 and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted Office docu
nvd
CVE-2015-1682P2CRITICALCVSS 9.3v2010v2011+1 more2015-05-13
CVE-2015-1682 [CRITICAL] CWE-119 CVE-2015-1682: Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Office 2013 SP1, Exce
Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Office 2013 SP1, Excel 2013 SP1, PowerPoint 2013 SP1, Word 2013 SP1, Office 2013 RT SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Office for Mac 2011, Excel for Mac 2011, PowerPoint for Mac 2011, Word for Mac 2011, PowerPoint Viewer, Word Automation Se
nvd
CVE-2018-8504P2HIGHCVSS 8.8v2010-sp2v2013-sp1+1 more2018-10-10
CVE-2018-8504 [HIGH] CVE-2018-8504: A remote code execution vulnerability exists in Microsoft Word software when the software fails to p
A remote code execution vulnerability exists in Microsoft Word software when the software fails to properly handle objects in Protected View, aka "Microsoft Word Remote Code Execution Vulnerability." This affects Microsoft SharePoint Server, Office 365 ProPlus, Microsoft Office, Microsoft Word.
nvd
CVE-2010-3214P2CRITICALCVSS 9.3v2002v2003+2 more2010-10-13
CVE-2010-3214 [CRITICAL] CWE-119 CVE-2010-3214: Stack-based buffer overflow in Microsoft Word 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004 an
Stack-based buffer overflow in Microsoft Word 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; Word Viewer; Office Web Apps; and Word Web App allows remote attackers to execute arbitrary code via a crafted Wor
nvd
CVE-2002-1143P4MEDIUMCVSS 5.0PoCv97v98+3 more2003-04-11
CVE-2002-1143 [MEDIUM] CVE-2002-1143: Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field cod
Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka "Flaw in Word Fields and Excel External Updates Could Lead to Information Disclosure."
nvd
CVE-2019-0585P3HIGHCVSS 8.8v2010-sp2v2013-sp1+2 more2019-01-08
CVE-2019-0585 [HIGH] CVE-2019-0585: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka "Microsoft Word Remote Code Execution Vulnerability." This affects Word, Microsoft Office, Microsoft Office Word Viewer, Office 365 ProPlus, Microsoft SharePoint, Microsoft Office Online Server, Microsoft Word, Microsoft SharePoint Ser
nvd
CVE-2018-0806P2HIGHCVSS 8.8v2007v2010+2 more2018-01-10
CVE-2018-0806 [HIGH] CVE-2018-0806: Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Of
Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0804, CVE-2018-0805, and CVE-2018-0807.
nvd
CVE-2015-0085P2CRITICALCVSS 9.3v2007v2010+1 more2015-03-11
CVE-2015-0085 [CRITICAL] CVE-2015-0085: Use-after-free vulnerability in Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Word
Use-after-free vulnerability in Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Office 2013 Gold and SP1, Word 2013 Gold and SP1, Office 2013 RT Gold and SP1, Word 2013 RT Gold and SP1, Excel Viewer, Office Compatibility Pack SP3, Word Automation Services on
nvd
CVE-2018-0807P2HIGHCVSS 8.8v2007v2010+2 more2018-01-10
CVE-2018-0807 [HIGH] CVE-2018-0807: Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Of
Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0804, CVE-2018-0805, and CVE-2018-0806.
nvd