Skip to main content

Vendor/product archive

microsoft / visio CVEs

Beta · best-effort

54 CVEs tagged to microsoft / visio32 Critical, 19 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2016-3364

Published Sep 14, 2016

Microsoft Visio 2016 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3235

Published Jun 16, 2016

Microsoft Visio 2007 SP3, Visio 2010 SP2, Visio 2013 SP1, Visio 2016, Visio Viewer 2007 SP3, and Visio Viewer 2010 mishandle library loading, which allows local users to gain priv…

CVSS 7.8 · High
Buzz score
25.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2015-2503

Published Nov 11, 2015

Microsoft Access 2007 SP3, Excel 2007 SP3, InfoPath 2007 SP3, OneNote 2007 SP3, PowerPoint 2007 SP3, Project 2007 SP3, Publisher 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Office 20…

CVSS 9.3 · Critical

CVE-2015-2557

Published Oct 14, 2015

Buffer overflow in Microsoft Visio 2007 SP3 and 2010 SP2 allows remote attackers to execute arbitrary code via crafted UML data in an Office document, aka "Microsoft Office Memory…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-2423

Published Aug 15, 2015

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10, Excel…

CVSS 4.3 · Medium

CVE-2013-1301

Published May 15, 2013

Microsoft Visio 2003 SP3 2007 SP3, and 2010 SP1 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1888

Published Aug 15, 2012

Buffer overflow in Microsoft Visio 2010 SP1 and Visio Viewer 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Visio file, aka "Visio DXF File Format Buffer…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-1979

Published Aug 10, 2011

Microsoft Visio 2003 SP3 and 2007 SP2 does not properly validate objects in memory during Visio file parsing, which allows remote attackers to execute arbitrary code via a crafted…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-1972

Published Aug 10, 2011

Microsoft Visio 2003 SP3, 2007 SP2, and 2010 Gold and SP1 does not properly validate objects in memory during Visio file parsing, which allows remote attackers to execute arbitrar…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-0093

Published Feb 10, 2011

ELEMENTS.DLL in Microsoft Visio 2002 SP2, 2003 SP3, and 2007 SP2 does not properly parse structures during the opening of a Visio file, which allows remote attackers to execute ar…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-0092

Published Feb 10, 2011

The LZW stream decompression functionality in ORMELEMS.DLL in Microsoft Visio 2002 SP2, 2003 SP3, and 2007 SP2 allows remote attackers to execute arbitrary code via a Visio file w…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-3148

Published Aug 27, 2010

Untrusted search path vulnerability in Microsoft Visio 2003 SP3 allows local users to gain privileges via a Trojan horse mfc71enu.dll file in the current working directory, as dem…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-1681

Published May 6, 2010

Buffer overflow in VISIODWG.DLL before 10.0.6880.4 in Microsoft Office Visio allows user-assisted remote attackers to execute arbitrary code via a crafted DXF file, a different vu…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 54 CVEsPage 1 of 3