Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Filtered by product Office
Total 947 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2013-0007 1 Microsoft 15 Expression Web, Groove Server, Office and 12 more 2023-12-07 9.3 HIGH N/A
Microsoft XML Core Services (aka MSXML) 4.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML XSLT Vulnerability."
CVE-2023-36413 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2023-11-20 N/A 6.5 MEDIUM
Microsoft Office Security Feature Bypass Vulnerability
CVE-2023-36037 1 Microsoft 4 365 Apps, Excel, Office and 1 more 2023-11-20 N/A 7.8 HIGH
Microsoft Excel Security Feature Bypass Vulnerability
CVE-2008-7217 1 Microsoft 1 Office 2023-11-07 4.6 MEDIUM N/A
Microsoft Office 2008 for Mac, when running on Macintosh systems that restrict Office access to administrators, does not enforce this restriction for user ID 502, which allows local users with that ID to bypass intended security policy and access Office programs, related to permissions and ownership for certain directories.
CVE-2006-0009 1 Microsoft 2 Office, Works 2023-11-07 5.1 MEDIUM N/A
Buffer overflow in Microsoft Office 2000 SP3, XP SP3, and other versions and packages, allows user-assisted attackers to execute arbitrary code via a routing slip that is longer than specified by the provided length field, as exploited by malware such as TROJ_MDROPPER.BH and Trojan.PPDropper.E in attacks against PowerPoint.
CVE-2002-1716 1 Microsoft 1 Office 2023-11-07 5.0 MEDIUM N/A
The Host() function in the Microsoft spreadsheet component on Microsoft Office XP allows remote attackers to create arbitrary files using the SaveAs capability.
CVE-2002-0618 1 Microsoft 2 Excel, Office 2023-11-07 7.5 HIGH N/A
The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code in the Local Computer zone by embedding HTML scripts within an Excel workbook that contains an XSL stylesheet, aka "Excel XSL Stylesheet Script Execution".
CVE-1999-0794 1 Microsoft 2 Excel, Office 2023-11-07 4.6 MEDIUM N/A
Microsoft Excel does not warn a user when a macro is present in a Symbolic Link (SYLK) format file.
CVE-2022-33632 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2023-08-08 4.6 MEDIUM 4.7 MEDIUM
Microsoft Office Security Feature Bypass Vulnerability
CVE-2021-42295 1 Microsoft 2 365 Apps, Office 2023-08-08 4.3 MEDIUM 5.5 MEDIUM
Visual Basic for Applications Information Disclosure Vulnerability
CVE-2022-23252 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2023-08-08 2.1 LOW 5.5 MEDIUM
Microsoft Office Information Disclosure Vulnerability
CVE-2022-22716 1 Microsoft 7 365 Apps, Excel, Office and 4 more 2023-08-08 4.3 MEDIUM 5.5 MEDIUM
Microsoft Excel Information Disclosure Vulnerability
CVE-2021-31174 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2023-08-02 2.1 LOW 5.5 MEDIUM
Microsoft Excel Information Disclosure Vulnerability
CVE-2021-31179 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2023-08-02 6.8 MEDIUM 7.8 HIGH
Microsoft Office Remote Code Execution Vulnerability
CVE-2021-31178 1 Microsoft 6 365 Apps, Excel, Office and 3 more 2023-08-02 4.3 MEDIUM 5.5 MEDIUM
Microsoft Office Information Disclosure Vulnerability
CVE-2021-31175 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2023-08-02 6.8 MEDIUM 7.8 HIGH
Microsoft Office Remote Code Execution Vulnerability
CVE-2021-31176 1 Microsoft 4 365 Apps, Office, Office Online Server and 1 more 2023-08-02 6.8 MEDIUM 7.8 HIGH
Microsoft Office Remote Code Execution Vulnerability
CVE-2021-40486 1 Microsoft 6 Office, Office Online Server, Office Web Apps Server and 3 more 2023-08-01 6.8 MEDIUM 7.8 HIGH
Microsoft Word Remote Code Execution Vulnerability
CVE-2021-40481 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2023-08-01 6.8 MEDIUM 7.1 HIGH
Microsoft Office Visio Remote Code Execution Vulnerability
CVE-2021-31941 1 Microsoft 3 365 Apps, Office, Outlook 2023-08-01 6.8 MEDIUM 7.8 HIGH
Microsoft Office Graphics Remote Code Execution Vulnerability