Skip to main content

Vendor/product archive

microsoft / office CVEs

Beta · best-effort

1,033 CVEs tagged to microsoft / office282 Critical, 577 High, 166 Medium, 8 Low, 0 Unrated.

CVE-2006-1318

Published Sep 19, 2014

Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, Office 2004 for Mac, and Office X for Mac do not properly parse record lengths, which allows remote attackers to…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-1809

Published May 14, 2014

The MSCOMCTL library in Microsoft Office 2007 SP3, 2010 SP1 and SP2, and 2013 Gold, SP1, RT, and RT SP1 makes it easier for remote attackers to bypass the ASLR protection mechanis…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1808

Published May 14, 2014

Microsoft Office 2013 Gold, SP1, RT, and RT SP1 allows remote attackers to obtain sensitive token information via a web site that sends a crafted response during opening of an Off…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1756

Published May 14, 2014

Untrusted search path vulnerability in Microsoft Office 2007 SP3, 2010 SP1 and SP2, and 2013 Gold, SP1, RT, and RT SP1, when the Simplified Chinese Proofing Tool is enabled, allow…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-2730

Published Apr 5, 2014

The XML parser in Microsoft Office 2007 SP3, 2010 SP1 and SP2, and 2013, and Office for Mac 2011, does not properly detect recursion during entity expansion, which allows remote a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1761

Published Mar 25, 2014

Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation Services on SharePoint Ser…

CVSS 7.8 · High
evidence mentions
26
Buzz score
71.0
KEV listed

CVE-2013-5057

Published Dec 11, 2013

hxds.dll in Microsoft Office 2007 SP3 and 2010 SP1 and SP2 does not implement the ASLR protection mechanism, which makes it easier for remote attackers to execute arbitrary code v…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5054

Published Dec 11, 2013

Microsoft Office 2013 and 2013 RT allows remote attackers to discover authentication tokens via a crafted response to a file-open request for an Office file on a web site, as expl…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1325

Published Nov 13, 2013

Heap-based buffer overflow in Microsoft Office 2003 SP3 and 2007 SP3 allows remote attackers to execute arbitrary code via a crafted WordPerfect document (.wpd) file, aka "Word He…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-1324

Published Nov 13, 2013

Stack-based buffer overflow in Microsoft Office 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT allows remote attackers to execute arbitrary code via a crafted WordPerfect…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-0082

Published Nov 13, 2013

Microsoft Office 2003 SP3 and 2007 SP3 allows remote attackers to execute arbitrary code via a crafted WordPerfect document (.wpd) file, aka "WPD File Format Memory Corruption Vul…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-3906

Published Nov 6, 2013

GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Lync 2010, 2010 Attendee, 2013, and Ba…

CVSS 7.8 · High
evidence mentions
17
Buzz score
69.9
KEV listed

CVE-2013-3859

Published Sep 11, 2013

Microsoft Pinyin IME 2010, when used in conjunction with Microsoft Office 2010 SP1, does not properly restrict configuration options, which allows local users to gain privileges b…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3854

Published Sep 11, 2013

Microsoft Office 2007 SP3 and Word 2007 SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "W…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-3853

Published Sep 11, 2013

Microsoft Office 2007 SP3 and Word 2007 SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "W…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-1315

Published Sep 11, 2013

Microsoft SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013; Office Web Apps 2010; Excel 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Office for Mac 2011; Excel V…

CVSS 9.3 · Critical

CVE-2013-3129

Published Jul 10, 2013

Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 before 5.1.20513.0; win32k.sys in the kernel-mode drivers, and GDI+, DirectWrite, and Journal, in Windows X…

CVSS 7.8 · High
evidence mentions
2
Buzz score
17.5

CVE-2013-1331

Published Jun 12, 2013

Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Office document, leading to impro…

CVSS 7.8 · High
Buzz score
25.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2013-0095

Published Mar 13, 2013

Outlook in Microsoft Office for Mac 2008 before 12.3.6 and Office for Mac 2011 before 14.3.2 allows remote attackers to trigger access to a remote URL and consequently confirm the…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 726-750 of 1,033 CVEsPage 30 of 42