Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Word
(Microsoft)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 219 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2015-07-14 | CVE-2015-2424 | Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability." | Excel_viewer, Office, Office_compatibility_pack, Powerpoint, Word, Word_viewer | 8.8 | ||
2024-12-12 | CVE-2024-49065 | Microsoft Office Remote Code Execution Vulnerability | 365_apps, Office, Office_long_term_servicing_channel, Sharepoint_server, Word | 5.5 | ||
2022-05-10 | CVE-2022-29107 | Microsoft Office Security Feature Bypass Vulnerability | 365_apps, Office, Publisher, Word | 5.5 | ||
2012-12-12 | CVE-2012-2539 | Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office Web Apps 2010 SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, aka "Word RTF 'listoverridecount' Remote Code Execution Vulnerability." | Office_compatibility_pack, Office_web_apps, Office_word_viewer, Sharepoint_server, Word | 7.8 | ||
2014-03-25 | CVE-2014-1761 | Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation Services on SharePoint Server 2010 SP1 and SP2 and 2013; Office Web Apps 2010 SP1 and SP2; and Office Web Apps Server 2013 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, as exploited in the wild in March 2014. | Office, Office_compatibility_pack, Office_web_apps, Office_web_apps_server, Sharepoint_server, Word, Word_viewer | 7.8 | ||
2020-06-09 | CVE-2020-1229 | A security feature bypass vulnerability exists in Microsoft Outlook when Office fails to enforce security settings configured on a system, aka 'Microsoft Outlook Security Feature Bypass Vulnerability'. | 365_apps, Office, Word | 4.3 | ||
2020-06-09 | CVE-2020-1223 | A remote code execution vulnerability exists when Microsoft Word for Android fails to properly handle certain files.To exploit the vulnerability, an attacker would have to convince a user to open a specially crafted URL file.The update addresses the vulnerability by correcting how Microsoft Word for Android handles specially crafted URL files., aka 'Word for Android Remote Code Execution Vulnerability'. | Word | 8.8 | ||
2020-07-14 | CVE-2020-1342 | An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory, aka 'Microsoft Office Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1445. | 365_apps, Office, Office_online_server, Office_web_apps, Sharepoint_enterprise_server, Sharepoint_server, Word | 5.5 | ||
2020-07-14 | CVE-2020-1445 | An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory, aka 'Microsoft Office Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1342. | 365_apps, Office, Office_online_server, Office_web_apps, Sharepoint_enterprise_server, Word | 5.5 | ||
2020-07-14 | CVE-2020-1446 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1447, CVE-2020-1448. | 365_apps, Office, Office_online_server, Office_web_apps, Sharepoint_enterprise_server, Sharepoint_server, Word, Word_rt | 8.8 |