Word
by Microsoft
CVEs (314)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2014-1757 | 0.01 | — | 0.17 | Apr 8, 2014 | Microsoft Word 2007 SP3 and 2010 SP1 and SP2, and Office Compatibility Pack SP3, allocates memory incorrectly for file conversions from a binary (aka .doc) format to a newer format, which allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft… | |||
| CVE-2014-0260 | 0.01 | — | 0.15 | Jan 15, 2014 | Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Office Compatibility Pack SP3; Word Viewer; SharePoint Server 2010 SP1 and SP2 and 2013; Office Web Apps 2010 SP1 and SP2; and Office Web Apps Server 2013 allow remote attackers to execute arbitrary code or… | |||
| CVE-2014-0259 | 0.01 | — | 0.16 | Jan 15, 2014 | Microsoft Word 2007 SP3 and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability." | |||
| CVE-2014-0258 | 0.01 | — | 0.16 | Jan 15, 2014 | Microsoft Word 2003 SP3 and 2007 SP3, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability." | |||
| CVE-2013-6801 | 0.01 | — | 0.14 | Nov 18, 2013 | Microsoft Word 2003 SP2 and SP3 on Windows XP SP3 allows remote attackers to cause a denial of service (CPU consumption) via a malformed .doc file containing an embedded image, as demonstrated by word2003forkbomb.doc, related to a "fork bomb" issue. | |||
| CVE-2013-3891 | 0.01 | — | 0.19 | Oct 9, 2013 | Microsoft Word 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Memory Corruption Vulnerability." | |||
| CVE-2010-3200 | 0.01 | — | 0.11 | Sep 20, 2010 | MSO.dll in Microsoft Word 2003 SP3 11.8326.11.8324 allows remote attackers to cause a denial of service (NULL pointer dereference and multiple-instance application crash) via a crafted buffer in a Word document, as demonstrated by word_crash_11.8326.8324_poc.doc. | |||
| CVE-2008-6063 | 0.01 | — | 0.10 | Feb 5, 2009 | Microsoft Word 2007, when the "Save as PDF" add-on is enabled, places an absolute pathname in the Subject field during an "Email as PDF" operation, which allows remote attackers to obtain sensitive information such as the sender's account name and a Temporary Internet Files… | |||
| CVE-2006-3877 | 0.01 | — | 0.13 | Oct 10, 2006 | Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via an unspecified "crafted file," a different vulnerability than CVE-2006-3435,… | |||
| CVE-2006-0935 | 0.01 | — | 0.06 | Feb 28, 2006 | Microsoft Word 2003 allows remote attackers to cause a denial of service (application crash) via a crafted file, as demonstrated by 101_filefuzz. | |||
| CVE-2005-1683 | 0.01 | — | 0.15 | May 20, 2005 | Buffer overflow in winword.exe 10.2627.6714 and earlier in Microsoft Word for the Macintosh, before SP3 for Word 2002, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted mcw file. | |||
| CVE-2005-0558 | 0.01 | — | 0.15 | May 2, 2005 | Buffer overflow in Microsoft Word 2000, Word 2002, and Word 2003 allows remote attackers to execute arbitrary code via a crafted document. | |||
| CVE-2002-0619 | 0.01 | — | 0.16 | Aug 12, 2002 | The Mail Merge Tool in Microsoft Word 2002 for Windows, when Microsoft Access is present on a system, allows remote attackers to execute Visual Basic (VBA) scripts within a mail merge document that is saved in HTML format, aka a "Variant of MS00-071, Word Mail Merge… | |||
| CVE-2002-1056 | 0.01 | — | 0.19 | May 16, 2002 | Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary scripts via an email that the… | |||
| CVE-2000-0788 | 0.01 | — | 0.08 | Oct 20, 2000 | The Mail Merge tool in Microsoft Word does not prompt the user before executing Visual Basic (VBA) scripts in an Access database, which could allow an attacker to execute arbitrary commands. | |||
| CVE-2026-55142 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-55134 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55132 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55130 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55128 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
- CVE-2014-1757Apr 8, 2014risk 0.01cvss —epss 0.17
Microsoft Word 2007 SP3 and 2010 SP1 and SP2, and Office Compatibility Pack SP3, allocates memory incorrectly for file conversions from a binary (aka .doc) format to a newer format, which allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft…
- CVE-2014-0260Jan 15, 2014risk 0.01cvss —epss 0.15
Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Office Compatibility Pack SP3; Word Viewer; SharePoint Server 2010 SP1 and SP2 and 2013; Office Web Apps 2010 SP1 and SP2; and Office Web Apps Server 2013 allow remote attackers to execute arbitrary code or…
- CVE-2014-0259Jan 15, 2014risk 0.01cvss —epss 0.16
Microsoft Word 2007 SP3 and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability."
- CVE-2014-0258Jan 15, 2014risk 0.01cvss —epss 0.16
Microsoft Word 2003 SP3 and 2007 SP3, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability."
- CVE-2013-6801Nov 18, 2013risk 0.01cvss —epss 0.14
Microsoft Word 2003 SP2 and SP3 on Windows XP SP3 allows remote attackers to cause a denial of service (CPU consumption) via a malformed .doc file containing an embedded image, as demonstrated by word2003forkbomb.doc, related to a "fork bomb" issue.
- CVE-2013-3891Oct 9, 2013risk 0.01cvss —epss 0.19
Microsoft Word 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Memory Corruption Vulnerability."
- CVE-2010-3200Sep 20, 2010risk 0.01cvss —epss 0.11
MSO.dll in Microsoft Word 2003 SP3 11.8326.11.8324 allows remote attackers to cause a denial of service (NULL pointer dereference and multiple-instance application crash) via a crafted buffer in a Word document, as demonstrated by word_crash_11.8326.8324_poc.doc.
- CVE-2008-6063Feb 5, 2009risk 0.01cvss —epss 0.10
Microsoft Word 2007, when the "Save as PDF" add-on is enabled, places an absolute pathname in the Subject field during an "Email as PDF" operation, which allows remote attackers to obtain sensitive information such as the sender's account name and a Temporary Internet Files…
- CVE-2006-3877Oct 10, 2006risk 0.01cvss —epss 0.13
Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via an unspecified "crafted file," a different vulnerability than CVE-2006-3435,…
- CVE-2006-0935Feb 28, 2006risk 0.01cvss —epss 0.06
Microsoft Word 2003 allows remote attackers to cause a denial of service (application crash) via a crafted file, as demonstrated by 101_filefuzz.
- CVE-2005-1683May 20, 2005risk 0.01cvss —epss 0.15
Buffer overflow in winword.exe 10.2627.6714 and earlier in Microsoft Word for the Macintosh, before SP3 for Word 2002, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted mcw file.
- CVE-2005-0558May 2, 2005risk 0.01cvss —epss 0.15
Buffer overflow in Microsoft Word 2000, Word 2002, and Word 2003 allows remote attackers to execute arbitrary code via a crafted document.
- CVE-2002-0619Aug 12, 2002risk 0.01cvss —epss 0.16
The Mail Merge Tool in Microsoft Word 2002 for Windows, when Microsoft Access is present on a system, allows remote attackers to execute Visual Basic (VBA) scripts within a mail merge document that is saved in HTML format, aka a "Variant of MS00-071, Word Mail Merge…
- CVE-2002-1056May 16, 2002risk 0.01cvss —epss 0.19
Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary scripts via an email that the…
- CVE-2000-0788Oct 20, 2000risk 0.01cvss —epss 0.08
The Mail Merge tool in Microsoft Word does not prompt the user before executing Visual Basic (VBA) scripts in an Access database, which could allow an attacker to execute arbitrary commands.
- risk 0.00cvss 5.5epss 0.00
Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- risk 0.00cvss 7.8epss 0.00
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.8epss 0.00
Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.8epss 0.00
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Page 15 of 16