Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Filtered by product Publisher
Total 43 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-3068 1 Microsoft 17 Access, Excel, Frontpage and 14 more 2018-10-11 7.5 HIGH N/A
Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times and IP addresses of recipients, and port-scan results, via a crafted certificate with an Authority Information Access (AIA) extension.
CVE-2017-8725 1 Microsoft 1 Publisher 2017-09-21 9.3 HIGH 7.8 HIGH
A remote code execution vulnerability exists in Microsoft Publisher 2007 Service Pack 3 and Microsoft Publisher 2010 Service Pack 2 when they fail to properly handle objects in memory, aka "Microsoft Office Publisher Remote Code Execution".
CVE-2007-1117 1 Microsoft 1 Publisher 2008-11-15 10.0 HIGH N/A
Unspecified vulnerability in Publisher 2007 in Microsoft Office 2007 allows remote attackers to execute arbitrary code via unspecified vectors, related to a "file format vulnerability." NOTE: this information is based upon a vague pre-advisory with no actionable information. However, the advisory is from a reliable source.