Microsoft Word vulnerabilities
265 known vulnerabilities affecting microsoft/word.
Total CVEs
265
CISA KEV
10
actively exploited
Public exploits
20
Exploited in wild
18
Severity breakdown
CRITICAL79HIGH142MEDIUM42LOW2
Vulnerabilities
Page 3 of 14
CVE-2018-0792P3HIGHCVSS 8.8v20162018-01-10
CVE-2018-0792 [HIGH] CWE-787 CVE-2018-0792: Microsoft Word 2016 in Microsoft Office 2016 allows a remote code execution vulnerability due to the
Microsoft Word 2016 in Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0794.
nvd
CVE-2018-0805P2HIGHCVSS 8.8v2007v2010+2 more2018-01-10
CVE-2018-0805 [HIGH] CVE-2018-0805: Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Of
Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0804, CVE-2018-0806, and CVE-2018-0807
nvd
CVE-2018-0804P2HIGHCVSS 8.8v2007v2010+2 more2018-01-10
CVE-2018-0804 [HIGH] CVE-2018-0804: Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Of
Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0805, CVE-2018-0806, and CVE-2018-0807.
nvd
CVE-2015-1649P2CRITICALCVSS 9.3v2007v2010+1 more2015-04-14
CVE-2015-1649 [CRITICAL] CVE-2015-1649: Use-after-free vulnerability in Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word Viewer
Use-after-free vulnerability in Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps Server 2010 SP2 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Component Use After Free Vulner
nvd
CVE-2014-1758P2CRITICALCVSS 9.3v20032014-04-08
CVE-2014-1758 [CRITICAL] CWE-119 CVE-2014-1758: Stack-based buffer overflow in Microsoft Word 2003 SP3 allows remote attackers to execute arbitrary
Stack-based buffer overflow in Microsoft Word 2003 SP3 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Word Stack Overflow Vulnerability."
nvd
CVE-2010-3217P3CRITICALCVSS 9.3v20022010-10-13
CVE-2010-3217 [CRITICAL] CWE-399 CVE-2010-3217: Double free vulnerability in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary co
Double free vulnerability in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via a Word document with crafted List Format Override (LFO) records, aka "Word Pointer Vulnerability."
nvd
CVE-2018-0848P3HIGHCVSS 8.8v2007v2010+2 more2018-01-22
CVE-2018-0848 [HIGH] CVE-2018-0848: Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Of
Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0805, CVE-2018-0806, and CVE-2018-0807.
nvd
CVE-2018-0794P3HIGHCVSS 8.8v2007v2010+2 more2018-01-10
CVE-2018-0794 [HIGH] CVE-2018-0794: Microsoft Word in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft
Microsoft Word in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0792.
nvd
CVE-2018-1028P3HIGHCVSS 8.8vAutomation Services on Microsoft SharePoint Server 2010 Service Pack 2vAutomation Services on Microsoft SharePoint Server 2013 Service Pack 12018-04-12
CVE-2018-1028 [HIGH] CWE-94 CVE-2018-1028: A remote code execution vulnerability exists when the Office graphics component improperly handles s
A remote code execution vulnerability exists when the Office graphics component improperly handles specially crafted embedded fonts, aka "Microsoft Office Graphics Remote Code Execution Vulnerability." This affects Word, Microsoft Office, Microsoft SharePoint, Excel, Microsoft SharePoint Server.
nvd
CVE-2014-4117P3CRITICALCVSS 9.3v20102014-10-15
CVE-2014-4117 [CRITICAL] CWE-20 CVE-2014-4117: Microsoft Office 2007 SP3, Word 2007 SP3, Office 2010 SP1 and SP2, Word 2010 SP1 and SP2, Office for
Microsoft Office 2007 SP3, Word 2007 SP3, Office 2010 SP1 and SP2, Word 2010 SP1 and SP2, Office for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP1 and SP2, and Word Web Apps 2010 Gold, SP1, and SP2 allow remote attackers to execute arbitrary code via crafted properties in a Word document, aka "Microso
nvd
CVE-2010-1902P3CRITICALCVSS 9.3v2002v2003+1 more2010-08-11
CVE-2010-1902 [CRITICAL] CWE-119 CVE-2010-1902: Buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2; Microsoft Office 2004 and
Buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2; Microsoft Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Word Viewer; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 allows remote attackers to execute arbitrary code via unspecified properties in the data in
nvd
CVE-2018-0849P2HIGHCVSS 8.8v2007v2010+2 more2018-01-22
CVE-2018-0849 [HIGH] CVE-2018-0849: Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Of
Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0805, CVE-2018-0806, and CVE-2018-0807.
nvd
CVE-2018-0862P2HIGHCVSS 8.8v2007v2010+2 more2018-01-22
CVE-2018-0862 [HIGH] CVE-2018-0862: Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Of
Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0805, CVE-2018-0806, and CVE-2018-0807.
nvd
CVE-2018-0801P3HIGHCVSS 8.8v2007v2010+2 more2018-01-10
CVE-2018-0801 [HIGH] CVE-2018-0801: Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsof
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Remote Code Execution Vulnerability".
nvd
CVE-2012-2528P3CRITICALCVSS 9.3v2003v2007+1 more2012-10-09
CVE-2012-2528 [CRITICAL] CWE-399 CVE-2012-2528: Use-after-free vulnerability in Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer
Use-after-free vulnerability in Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; Word Automation Services on Microsoft SharePoint Server 2010; and Office Web Apps 2010 SP1 allows remote attackers to execute arbitrary code via a crafted RTF document, aka "RTF File listid Use-After-Free Vulne
nvd
CVE-2017-8510P3HIGHCVSS 8.8v20132017-06-15
CVE-2017-8510 [HIGH] CVE-2017-8510: A remote code execution vulnerability exists in Microsoft Office when the software fails to properly
A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8509, CVE-2017-8511, CVE-2017-8512, CVE-2017-0260, and CVE-2017-8506.
nvd
CVE-2013-3892P3CRITICALCVSS 9.3v20072013-10-09
CVE-2013-3892 [CRITICAL] CWE-119 CVE-2013-3892: Microsoft Word 2007 SP3 and Office Compatibility Pack SP3 allow remote attackers to execute arbitrar
Microsoft Word 2007 SP3 and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Memory Corruption Vulnerability."
nvd
CVE-2013-3891P3CRITICALCVSS 9.3v20032013-10-09
CVE-2013-3891 [CRITICAL] CWE-119 CVE-2013-3891: Microsoft Word 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Office docum
Microsoft Word 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Memory Corruption Vulnerability."
nvd
CVE-2014-6333P3CRITICALCVSS 9.3v20072014-11-11
CVE-2014-6333 [CRITICAL] CWE-94 CVE-2014-6333: Microsoft Word 2007 SP3, Word Viewer, and Office Compatibility Pack SP3 allow remote attackers to ex
Microsoft Word 2007 SP3, Word Viewer, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Double Delete Remote Code Execution Vulnerability."
nvd
CVE-2010-3218P3CRITICALCVSS 9.3v20022010-10-13
CVE-2010-3218 [CRITICAL] CWE-94 CVE-2010-3218: Heap-based buffer overflow in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary c
Heap-based buffer overflow in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via malformed records in a Word document, aka "Word Heap Overflow Vulnerability."
nvd