VYPR

Office Online Server

by Microsoft

CVEs (233)

  • CVE-2023-21716CriFeb 14, 2023
    risk 0.70cvss 9.8epss 0.82

    Microsoft Word Remote Code Execution Vulnerability

  • CVE-2017-11826HigKEVOct 13, 2017
    risk 0.69cvss 7.8epss 0.81

    Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office Online Server allow remote code execution when the software…

  • CVE-2016-7193HigKEVOct 14, 2016
    risk 0.67cvss 7.8epss 0.58

    Microsoft Word 2007 SP2, Office 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1,…

  • CVE-2019-1205CriAug 14, 2019
    risk 0.64cvss 9.8epss 0.04

    A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user.…

  • CVE-2019-1331HigOct 10, 2019
    risk 0.59cvss 8.8epss 0.19

    A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1327.

  • CVE-2019-0585HigJan 8, 2019
    risk 0.59cvss 8.8epss 0.22

    A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka "Microsoft Word Remote Code Execution Vulnerability." This affects Word, Microsoft Office, Microsoft Office Word Viewer, Office 365 ProPlus, Microsoft…

  • CVE-2018-0792HigJan 10, 2018
    risk 0.59cvss 8.8epss 0.28

    Microsoft Word 2016 in Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0794.

  • CVE-2017-8512HigJun 15, 2017
    risk 0.59cvss 8.8epss 0.22

    A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8509, CVE-2017-8510, CVE-2017-8511, CVE-2017-0260, and…

  • CVE-2020-1583HigAug 17, 2020
    risk 0.58cvss 8.8epss 0.05

    An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. To exploit the vulnerability, an attacker could…

  • CVE-2020-1495HigAug 17, 2020
    risk 0.58cvss 8.8epss 0.04

    A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is…

  • CVE-2020-1448HigJul 14, 2020
    risk 0.58cvss 8.8epss 0.10

    A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1447.

  • CVE-2020-1447HigJul 14, 2020
    risk 0.58cvss 8.8epss 0.11

    A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1448.

  • CVE-2020-1446HigJul 14, 2020
    risk 0.58cvss 8.8epss 0.11

    A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1447, CVE-2020-1448.

  • CVE-2020-0850HigMar 12, 2020
    risk 0.58cvss 8.8epss 0.09

    A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0851, CVE-2020-0852, CVE-2020-0855, CVE-2020-0892.

  • CVE-2022-41106HigNov 9, 2022
    risk 0.57cvss 8.8epss 0.02

    Microsoft Excel Remote Code Execution Vulnerability

  • CVE-2022-21840HigJan 11, 2022
    risk 0.57cvss 8.8epss 0.03

    Microsoft Office Remote Code Execution Vulnerability

  • CVE-2026-26109HigMar 10, 2026
    risk 0.55cvss 8.4epss 0.00

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-59236HigOct 14, 2025
    risk 0.55cvss 8.4epss 0.00

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-49697HigJul 8, 2025
    risk 0.55cvss 8.4epss 0.00

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-30377HigMay 13, 2025
    risk 0.55cvss 8.4epss 0.01

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Page 1 of 12