VYPR

Word

by Microsoft

CVEs (314)

  • CVE-2026-26133HigMar 16, 2026
    risk 0.46cvss 7.1epss 0.00

    AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-62555HigDec 9, 2025
    risk 0.46cvss 7.0epss 0.01

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2025-59221HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2025-54905HigSep 9, 2025
    risk 0.46cvss 7.1epss 0.01

    Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

  • CVE-2025-49699HigJul 8, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-24078HigMar 11, 2025
    risk 0.46cvss 7.0epss 0.01

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2024-41165HigDec 18, 2024
    risk 0.46cvss 7.1epss 0.01

    A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Word's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and…

  • CVE-2020-16933HigOct 16, 2020
    risk 0.46cvss 7.0epss 0.03

    A security feature bypass vulnerability exists in Microsoft Word software when it fails to properly handle .LNK files. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user.…

  • CVE-2025-53736MedAug 12, 2025
    risk 0.44cvss 6.8epss 0.01

    Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

  • CVE-2016-7233MedNov 10, 2016
    risk 0.44cvss 6.5epss 0.22

    Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Excel for Mac 2011, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2013 SP1, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information…

  • CVE-2019-1461MedDec 10, 2019
    risk 0.43cvss 6.5epss 0.05

    A denial of service vulnerability exists in Microsoft Word software when the software fails to properly handle objects in memory, aka 'Microsoft Word Denial of Service Vulnerability'.

  • CVE-2018-8160MedMay 9, 2018
    risk 0.43cvss 6.5epss 0.09

    An information disclosure vulnerability exists in Outlook when a message is opened, aka "Microsoft Outlook Information Disclosure Vulnerability." This affects Word, Microsoft Office.

  • CVE-2018-0950MedApr 12, 2018
    risk 0.43cvss 6.5epss 0.09

    An information disclosure vulnerability exists when Office renders Rich Text Format (RTF) email messages containing OLE objects when a message is opened or previewed, aka "Microsoft Office Information Disclosure Vulnerability." This affects Microsoft Word, Microsoft Office. This…

  • CVE-2017-0105MedMar 17, 2017
    risk 0.38cvss 5.5epss 0.30

    Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from out-of-bound memory via a…

  • CVE-2016-3234MedJun 16, 2016
    risk 0.38cvss 5.5epss 0.24

    Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, and Office Web Apps Server 2013 SP1…

  • CVE-2021-31178MedMay 11, 2021
    risk 0.37cvss 5.5epss 0.16

    Microsoft Office Information Disclosure Vulnerability

  • CVE-2017-0029MedMar 17, 2017
    risk 0.37cvss 5.5epss 0.16

    Microsoft Office 2010 SP2, Word 2010 SP2, Word 2013 RT SP1, and Word 2016 allow remote attackers to cause a denial of service (application hang) via a crafted Office document, aka "Microsoft Office Denial of Service Vulnerability."

  • CVE-2016-3279MedJul 13, 2016
    risk 0.37cvss 5.5epss 0.16

    Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Excel 2013 SP1, PowerPoint 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Excel 2016, Word 2016, Word Automation Services on SharePoint Server 2010 SP2, and…

  • CVE-2026-70318MedAug 11, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

  • CVE-2026-70310MedAug 11, 2026
    risk 0.36cvss 5.5epss 0.00

    Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

Page 8 of 16