Office
by Microsoft
CVEs (1,321)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-69626 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-64918 | Med | 0.42 | 6.5 | 0.00 | Sep 8, 2026 | Insufficiently protected credentials in Microsoft Office allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-70328 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-70327 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2024-43609 | Med | 0.42 | 6.5 | 0.02 | Oct 8, 2024 | Microsoft Office Spoofing Vulnerability | ||
| CVE-2024-38020 | Med | 0.42 | 6.5 | 0.02 | Jul 9, 2024 | Microsoft Outlook Spoofing Vulnerability | ||
| CVE-2023-36893 | Med | 0.42 | 6.5 | 0.02 | Aug 8, 2023 | Microsoft Outlook Spoofing Vulnerability | ||
| CVE-2022-38001 | Med | 0.42 | 6.5 | 0.02 | Oct 11, 2022 | Microsoft Office Spoofing Vulnerability | ||
| CVE-2022-26934 | Med | 0.42 | 6.5 | 0.03 | May 10, 2022 | Windows Graphics Component Information Disclosure Vulnerability | ||
| CVE-2021-42293 | Med | 0.42 | 6.5 | 0.03 | Dec 15, 2021 | Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerability | ||
| CVE-2021-41368 | Med | 0.40 | 6.1 | 0.05 | Nov 10, 2021 | Microsoft Access Remote Code Execution Vulnerability | ||
| CVE-2017-8550 | Med | 0.40 | 5.4 | 0.32 | Jun 15, 2017 | A remote code execution vulnerability exists in Skype for Business when the software fails to sanitize specially crafted content, aka "Skype for Business Remote Code Execution Vulnerability". | ||
| CVE-2017-0060 | Med | 0.40 | 5.5 | 0.16 | Mar 17, 2017 | The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information from… | ||
| CVE-2019-1153 | Med | 0.39 | 5.5 | 0.03 | Aug 14, 2019 | An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To exploit this… | ||
| CVE-2019-1148 | Med | 0.39 | 5.5 | 0.03 | Aug 14, 2019 | An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To exploit this… | ||
| CVE-2018-8546 | Med | 0.39 | 5.9 | 0.06 | Nov 14, 2018 | A denial of service vulnerability exists in Skype for Business, aka "Microsoft Skype for Business Denial of Service Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Lync, Skype. | ||
| CVE-2017-0194 | Med | 0.38 | 5.5 | 0.14 | Apr 12, 2017 | Microsoft Excel 2007 SP3, Microsoft Excel 2010 SP2, and Office Compatibility Pack SP2 allow remote attackers to obtain sensitive information from process memory via a crafted Office document, aka "Microsoft Office Information Disclosure Vulnerability." | ||
| CVE-2017-0105 | Med | 0.38 | 5.5 | 0.15 | Mar 17, 2017 | Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from out-of-bound memory via a… | ||
| CVE-2016-3263 | Med | 0.38 | 5.5 | 0.22 | Oct 14, 2016 | Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for… | ||
| CVE-2016-3262 | Med | 0.38 | 5.5 | 0.22 | Oct 14, 2016 | Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for… |
- risk 0.42cvss 6.5epss 0.01
Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.00
Insufficiently protected credentials in Microsoft Office allows an unauthorized attacker to perform spoofing over a network.
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.02
Microsoft Office Spoofing Vulnerability
- risk 0.42cvss 6.5epss 0.02
Microsoft Outlook Spoofing Vulnerability
- risk 0.42cvss 6.5epss 0.02
Microsoft Outlook Spoofing Vulnerability
- risk 0.42cvss 6.5epss 0.02
Microsoft Office Spoofing Vulnerability
- risk 0.42cvss 6.5epss 0.03
Windows Graphics Component Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.03
Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerability
- risk 0.40cvss 6.1epss 0.05
Microsoft Access Remote Code Execution Vulnerability
- risk 0.40cvss 5.4epss 0.32
A remote code execution vulnerability exists in Skype for Business when the software fails to sanitize specially crafted content, aka "Skype for Business Remote Code Execution Vulnerability".
- risk 0.40cvss 5.5epss 0.16
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information from…
- risk 0.39cvss 5.5epss 0.03
An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To exploit this…
- risk 0.39cvss 5.5epss 0.03
An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To exploit this…
- risk 0.39cvss 5.9epss 0.06
A denial of service vulnerability exists in Skype for Business, aka "Microsoft Skype for Business Denial of Service Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Lync, Skype.
- risk 0.38cvss 5.5epss 0.14
Microsoft Excel 2007 SP3, Microsoft Excel 2010 SP2, and Office Compatibility Pack SP2 allow remote attackers to obtain sensitive information from process memory via a crafted Office document, aka "Microsoft Office Information Disclosure Vulnerability."
- risk 0.38cvss 5.5epss 0.15
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from out-of-bound memory via a…
- risk 0.38cvss 5.5epss 0.22
Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for…
- risk 0.38cvss 5.5epss 0.22
Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for…
Page 39 of 67