Skip to main content

Vendor/product archive

microsoft / office CVEs

Beta · best-effort

1,033 CVEs tagged to microsoft / office282 Critical, 577 High, 166 Medium, 8 Low, 0 Unrated.

CVE-2018-0797

Published Jan 10, 2018

Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way RTF content is handled, aka "Microsoft Word Memo…

CVSS 7.8 · High
evidence mentions
2
Buzz score
17.5

CVE-2018-0795

Published Jan 10, 2018

Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Of…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0791

Published Jan 10, 2018

Microsoft Outlook 2007, Microsoft Outlook 2010, Microsoft Outlook 2013, and Microsoft Outlook 2016 allow a remote code execution vulnerability due to the way email messages are pa…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-11939

Published Dec 12, 2017

Microsoft Office 2016 Click-to-Run (C2R) allows an information disclosure vulnerability due to the way Microsoft Office enforces DRM copy/paste permissions, aka "Microsoft Office…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-11935

Published Dec 12, 2017

Microsoft Office 2016 Click-to-Run (C2R) allows a remote code execution vulnerability due to the way files are handled in memory, aka "Microsoft Excel Remote Code Execution Vulner…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-11934

Published Dec 12, 2017

Microsoft Office 2013 RT SP1, Microsoft Office 2013 SP1, and Microsoft Office 2016 allow an information disclosure vulnerability due to the way certain functions handle objects in…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-11882

Published Nov 15, 2017

Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow an attacker to run arbitrary code…

CVSS 7.8 · High
evidence mentions
119
Buzz score
72.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2017-8744

Published Sep 13, 2017

A remote code execution vulnerability exists in Excel Services, Microsoft Excel 2007 Service Pack 3, Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Service Pack 1, Micr…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8695

Published Sep 13, 2017

Windows Uniscribe in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, 1607, 1703,…

CVSS 5.3 · Medium

CVE-2017-8676

Published Sep 13, 2017

The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 1…

CVSS 3.3 · Low

CVE-2017-8630

Published Sep 13, 2017

Microsoft Office 2016 allows a remote code execution vulnerability when it fails to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8570

Published Jul 11, 2017

Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability". This CV…

CVSS 7.8 · High
evidence mentions
19
Buzz score
66.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2017-8550

Published Jun 15, 2017

A remote code execution vulnerability exists in Skype for Business when the software fails to sanitize specially crafted content, aka "Skype for Business Remote Code Execution Vul…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 576-600 of 1,033 CVEsPage 24 of 42