cbcvebase.

Microsoft Word vulnerabilities

265 known vulnerabilities affecting microsoft/word.

Total CVEs
265
CISA KEV
10
actively exploited
Public exploits
20
Exploited in wild
18
Severity breakdown
CRITICAL79HIGH142MEDIUM42LOW2

Vulnerabilities

Page 7 of 14
CVE-2020-0760P3HIGHCVSS 8.8v2010v2013+1 more2020-04-15
CVE-2020-0760 [HIGH] CVE-2020-0760: A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type l A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries, aka 'Microsoft Office Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0991.
nvd
CVE-2018-8430P3HIGHCVSS 7.8v20162018-09-13
CVE-2018-8430 [HIGH] CVE-2018-8430: A remote code execution vulnerability exists in Microsoft Word if a user opens a specially crafted P A remote code execution vulnerability exists in Microsoft Word if a user opens a specially crafted PDF file, aka "Word PDF Remote Code Execution Vulnerability." This affects Microsoft Word, Microsoft Office.
nvd
CVE-2016-3317P3HIGHCVSS 7.8v2007v20102016-08-09
CVE-2016-3317 [HIGH] CWE-119 CVE-2016-3317: Microsoft Office 2010 SP2, Word 2007 SP3, Word 2010 SP2, Word for Mac 2011, Word 2016 for Mac, and W Microsoft Office 2010 SP2, Word 2007 SP3, Word 2010 SP2, Word for Mac 2011, Word 2016 for Mac, and Word Viewer allow remote attackers to execute arbitrary code via a crafted file, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2007-1911P4HIGHCVSS 7.1PoCv20072007-04-10
CVE-2007-1911 [HIGH] CVE-2007-1911: Multiple unspecified vulnerabilities in Microsoft Word 2007 allow remote attackers to cause a denial Multiple unspecified vulnerabilities in Microsoft Word 2007 allow remote attackers to cause a denial of service (CPU consumption) via crafted documents, as demonstrated by (1) file798-1.doc and (2) file613-1.doc, possibly related to a buffer overflow.
nvd
CVE-2026-40361P3HIGHCVSS 8.4v20162026-05-12
CVE-2026-40361 [HIGH] CWE-416 CVE-2026-40361: Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2016-3280P3HIGHCVSS 7.8v2007v2010+1 more2016-07-13
CVE-2016-3280 [HIGH] CWE-119 CVE-2016-3280: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for M Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2017-0254P3HIGHCVSS 7.8v2007v2010+2 more2017-05-12
CVE-2017-0254 [HIGH] CWE-119 CVE-2017-0254: Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Office for Mac 2 Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Office for Mac 2011, Office for Mac 2016, Microsoft Office Web Apps 2010 SP2, Office Web Apps Server 2013 SP1, Word 2013 RT SP1, Word 2013 SP1, Word Automation Services on Microsoft SharePoint Server 2013 SP1, Office Word Viewer, SharePoint Enterprise Server 2016, and Wo
nvd
CVE-2018-0797P3HIGHCVSS 7.8v2007v2010+2 more2018-01-10
CVE-2018-0797 [HIGH] CWE-787 CVE-2018-0797: Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code executio Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way RTF content is handled, aka "Microsoft Word Memory Corruption Vulnerability".
nvd
CVE-2023-33150P3CRITICALCVSS 9.6v2013v20162023-07-11
CVE-2023-33150 [CRITICAL] CWE-693 CVE-2023-33150: Microsoft Office Security Feature Bypass Vulnerability Microsoft Office Security Feature Bypass Vulnerability
nvd
CVE-2018-8157P3HIGHCVSS 7.8vAutomation Services on Microsoft SharePoint Server 2010 Service Pack 2vAutomation Services on Microsoft SharePoint Server 2013 Service Pack 12018-05-09
CVE-2018-8157 [HIGH] CVE-2018-8157: A remote code execution vulnerability exists in Microsoft Office software when the software fails to A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Office. This CVE ID is unique from CVE-2018-8158, CVE-2018-8161.
nvd
CVE-2020-0850P3HIGHCVSS 8.8v2013v20162020-03-12
CVE-2020-0850 [HIGH] CVE-2020-0850: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0851, CVE-2020-0852, CVE-2020-0855, CVE-2020-0892.
nvd
CVE-2018-0793P3HIGHCVSS 7.8v2007v2010+2 more2018-01-10
CVE-2018-0793 [HIGH] CVE-2018-0793: Microsoft Outlook 2007, Microsoft Outlook 2010 and Microsoft Outlook 2013 allow a remote code execut Microsoft Outlook 2007, Microsoft Outlook 2010 and Microsoft Outlook 2013 allow a remote code execution vulnerability due to the way email messages are parsed, aka "Microsoft Outlook Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0791.
nvd
CVE-2018-8161P3HIGHCVSS 7.8v2010-sp2v2013-sp1+1 more2018-05-09
CVE-2018-8161 [HIGH] CVE-2018-8161: A remote code execution vulnerability exists in Microsoft Office software when the software fails to A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Word, Word, Microsoft Office, Microsoft SharePoint. This CVE ID is unique from CVE-2018-8157, CVE-2018-8158.
nvd
CVE-2014-0259P3CRITICALCVSS 9.3v20072014-01-15
CVE-2014-0259 [CRITICAL] CWE-119 CVE-2014-0259: Microsoft Word 2007 SP3 and Office Compatibility Pack SP3 allow remote attackers to execute arbitrar Microsoft Word 2007 SP3 and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability."
nvd
CVE-2026-45458P3HIGHCVSS 8.4v20162026-06-09
CVE-2026-45458 [HIGH] CWE-416 CVE-2026-45458: Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2018-0845P3HIGHCVSS 7.8v2007v2010+2 more2018-01-22
CVE-2018-0845 [HIGH] CVE-2018-0845: Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Of Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0805, CVE-2018-0806, and CVE-2018-0807.
nvd
CVE-2016-7235P3HIGHCVSS 7.8v2007v20102016-11-10
CVE-2016-7235 [HIGH] CWE-119 CVE-2016-7235: Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Excel for Mac 2011, and Offi Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Excel for Mac 2011, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2014-0258P3CRITICALCVSS 9.3v2003v20072014-01-15
CVE-2014-0258 [CRITICAL] CWE-119 CVE-2014-0258: Microsoft Word 2003 SP3 and 2007 SP3, Office Compatibility Pack SP3, and Word Viewer allow remote at Microsoft Word 2003 SP3 and 2007 SP3, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability."
nvd
CVE-2018-0812P3HIGHCVSS 7.8v2007v2010+2 more2018-01-10
CVE-2018-0812 [HIGH] CWE-787 CVE-2018-0812: Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Of Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Memory Corruption Vulnerability".
nvd
CVE-2015-2380P3CRITICALCVSS 9.3v2007v2010+1 more2015-07-14
CVE-2015-2380 [CRITICAL] CWE-119 CVE-2015-2380: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, and Word 2013 RT SP1 allow r Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, and Word 2013 RT SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd