Office Online Server
by Microsoft
CVEs (233)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-21362 | Hig | 0.55 | 8.4 | 0.01 | Jan 14, 2025 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2025-21354 | Hig | 0.55 | 8.4 | 0.01 | Jan 14, 2025 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2023-32029 | Hig | 0.55 | 7.8 | 0.54 | Jun 14, 2023 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2021-34501 | Hig | 0.55 | 7.8 | 0.51 | Jul 14, 2021 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2025-47165 | Hig | 0.54 | 7.8 | 0.02 | Jun 10, 2025 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-27751 | Hig | 0.54 | 7.8 | 0.02 | Apr 8, 2025 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2023-33137 | Hig | 0.54 | 7.8 | 0.03 | Jun 14, 2023 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2023-33133 | Hig | 0.54 | 7.8 | 0.44 | Jun 14, 2023 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2023-23399 | Hig | 0.54 | 7.8 | 0.03 | Mar 14, 2023 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2026-44822 | Hig | 0.53 | 8.2 | 0.01 | Jun 9, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2018-0797 | Hig | 0.53 | 7.8 | 0.25 | Jan 10, 2018 | Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way RTF content is handled, aka "Microsoft Word Memory Corruption Vulnerability". | ||
| CVE-2017-8501 | Hig | 0.53 | 7.8 | 0.23 | Jul 11, 2017 | Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8502. | ||
| CVE-2016-3282 | Hig | 0.53 | 7.8 | 0.26 | Jul 13, 2016 | Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint… | ||
| CVE-2021-31939 | Hig | 0.52 | 7.8 | 0.13 | Jun 8, 2021 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2021-31179 | Hig | 0.52 | 7.8 | 0.13 | May 11, 2021 | Microsoft Office Remote Code Execution Vulnerability | ||
| CVE-2020-0980 | Hig | 0.52 | 7.8 | 0.12 | Apr 15, 2020 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. | ||
| CVE-2020-0892 | Hig | 0.52 | 7.8 | 0.12 | Mar 12, 2020 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0850, CVE-2020-0851, CVE-2020-0852, CVE-2020-0855. | ||
| CVE-2020-0852 | Hig | 0.52 | 7.8 | 0.12 | Mar 12, 2020 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0850, CVE-2020-0851, CVE-2020-0855, CVE-2020-0892. | ||
| CVE-2019-0953 | Hig | 0.52 | 7.8 | 0.13 | May 16, 2019 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. | ||
| CVE-2018-8628 | Hig | 0.52 | 7.8 | 0.16 | Dec 12, 2018 | A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Microsoft Office, Office 365 ProPlus, Microsoft PowerPoint,… |
- risk 0.55cvss 8.4epss 0.01
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.55cvss 8.4epss 0.01
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.55cvss 7.8epss 0.54
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.55cvss 7.8epss 0.51
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.54cvss 7.8epss 0.02
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.54cvss 7.8epss 0.02
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.54cvss 7.8epss 0.03
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.54cvss 7.8epss 0.44
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.54cvss 7.8epss 0.03
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.53cvss 8.2epss 0.01
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
- risk 0.53cvss 7.8epss 0.25
Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way RTF content is handled, aka "Microsoft Word Memory Corruption Vulnerability".
- risk 0.53cvss 7.8epss 0.23
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8502.
- risk 0.53cvss 7.8epss 0.26
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint…
- risk 0.52cvss 7.8epss 0.13
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.52cvss 7.8epss 0.13
Microsoft Office Remote Code Execution Vulnerability
- risk 0.52cvss 7.8epss 0.12
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'.
- risk 0.52cvss 7.8epss 0.12
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0850, CVE-2020-0851, CVE-2020-0852, CVE-2020-0855.
- risk 0.52cvss 7.8epss 0.12
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0850, CVE-2020-0851, CVE-2020-0855, CVE-2020-0892.
- risk 0.52cvss 7.8epss 0.13
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'.
- risk 0.52cvss 7.8epss 0.16
A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Microsoft Office, Office 365 ProPlus, Microsoft PowerPoint,…
Page 2 of 12