VYPR

Office

by Microsoft

CVEs (1,301)

  • CVE-2025-53766CriAug 12, 2025
    risk 0.64cvss 9.8epss 0.07

    Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.

  • CVE-2019-1449CriNov 12, 2019
    risk 0.64cvss 9.8epss 0.06

    A security feature bypass vulnerability exists in the way that Office Click-to-Run (C2R) components handle a specially crafted file, which could lead to a standard user, any AppContainer sandbox, and Office LPAC Protected View to escalate privileges to SYSTEM.To exploit this…

  • CVE-2019-1205CriAug 14, 2019
    risk 0.64cvss 9.8epss 0.04

    A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user.…

  • CVE-2016-7277CriDec 20, 2016
    risk 0.64cvss 9.6epss 0.18

    Microsoft Office 2016 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."

  • CVE-2016-0145HigApr 12, 2016
    risk 0.64cvss 8.8epss 0.43

    The font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold and 1511; Office 2007 SP3 and 2010 SP2; Word Viewer; .NET Framework 3.0 SP2, 3.5, and 3.5.1; Skype…

  • CVE-2012-1854HigKEVJul 10, 2012
    risk 0.64cvss 7.8epss 0.21

    Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for Applications (VBA); and Summit Microsoft Visual Basic for Applications SDK allows local users to gain privileges via a Trojan horse…

  • CVE-2026-21514HigKEVFeb 10, 2026
    risk 0.63cvss 7.8epss 0.02

    Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.

  • CVE-2023-33150CriJul 11, 2023
    risk 0.63cvss 9.6epss 0.02

    Microsoft Office Security Feature Bypass Vulnerability

  • CVE-2023-21823HigKEVFeb 14, 2023
    risk 0.63cvss 7.8epss 0.06

    Windows Graphics Component Remote Code Execution Vulnerability

  • CVE-2021-43905CriDec 15, 2021
    risk 0.63cvss 9.6epss 0.03

    Microsoft Office app Remote Code Execution Vulnerability

  • CVE-2017-0283HigJun 15, 2017
    risk 0.63cvss 8.8epss 0.39

    Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, Windows Server 2016, Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office Word Viewer, Microsoft Lync 2013…

  • CVE-2021-27059HigKEVMar 11, 2021
    risk 0.62cvss 7.6epss 0.03

    Microsoft Office Remote Code Execution Vulnerability

  • CVE-2023-33131HigJun 14, 2023
    risk 0.61cvss 8.8epss 0.06

    Microsoft Outlook Remote Code Execution Vulnerability

  • CVE-2019-1151HigAug 14, 2019
    risk 0.61cvss 8.8epss 0.15

    A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view,…

  • CVE-2019-1149HigAug 14, 2019
    risk 0.61cvss 8.8epss 0.14

    A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view,…

  • CVE-2018-1026HigApr 12, 2018
    risk 0.61cvss 8.8epss 0.42

    A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Office. This CVE ID is unique from CVE-2018-1030.

  • CVE-2024-38226HigKEVSep 10, 2024
    risk 0.60cvss 7.3epss 0.03

    Microsoft Publisher Security Feature Bypass Vulnerability

  • CVE-2020-1226HigJun 9, 2020
    risk 0.59cvss 8.8epss 0.17

    A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1225.

  • CVE-2020-1225HigJun 9, 2020
    risk 0.59cvss 8.8epss 0.17

    A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1226.

  • CVE-2019-1331HigOct 10, 2019
    risk 0.59cvss 8.8epss 0.19

    A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1327.

Page 3 of 66