365 Apps
by Microsoft
CVEs (654)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-1447 | Hig | 0.58 | 8.8 | 0.11 | Jul 14, 2020 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1448. | ||
| CVE-2020-1446 | Hig | 0.58 | 8.8 | 0.11 | Jul 14, 2020 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1447, CVE-2020-1448. | ||
| CVE-2020-1240 | Hig | 0.58 | 8.8 | 0.14 | Jul 14, 2020 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. | ||
| CVE-2020-1321 | Hig | 0.58 | 8.8 | 0.12 | Jun 9, 2020 | A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory, aka 'Microsoft Office Remote Code Execution Vulnerability'. | ||
| CVE-2026-70329 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-65807 | Hig | 0.57 | 8.8 | 0.00 | Aug 11, 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-62870 | Hig | 0.57 | 8.8 | 0.01 | Aug 4, 2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-40420 | Hig | 0.57 | 8.8 | 0.00 | May 12, 2026 | Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-35436 | Hig | 0.57 | 8.8 | 0.00 | May 12, 2026 | Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | ||
| CVE-2024-38021 | Hig | 0.57 | 8.8 | 0.04 | Jul 9, 2024 | Microsoft Outlook Remote Code Execution Vulnerability | ||
| CVE-2024-30103 | Hig | 0.57 | 8.8 | 0.03 | Jun 11, 2024 | Microsoft Outlook Remote Code Execution Vulnerability | ||
| CVE-2022-41106 | Hig | 0.57 | 8.8 | 0.02 | Nov 9, 2022 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2022-34717 | Hig | 0.57 | 8.8 | 0.02 | Aug 9, 2022 | Microsoft Office Remote Code Execution Vulnerability | ||
| CVE-2021-28455 | Hig | 0.57 | 8.8 | 0.02 | May 11, 2021 | Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability | ||
| CVE-2023-36761 | Med | 0.56 | 6.5 | 0.19 | KEV | Sep 12, 2023 | Microsoft Word Information Disclosure Vulnerability | |
| CVE-2026-70130 | Hig | 0.55 | 8.4 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-45458 | Hig | 0.55 | 8.4 | 0.00 | Jun 9, 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-45456 | Hig | 0.55 | 8.4 | 0.00 | Jun 9, 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-40367 | Hig | 0.55 | 8.4 | 0.00 | May 12, 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-40366 | Hig | 0.55 | 8.4 | 0.00 | May 12, 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
- risk 0.58cvss 8.8epss 0.11
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1448.
- risk 0.58cvss 8.8epss 0.11
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1447, CVE-2020-1448.
- risk 0.58cvss 8.8epss 0.14
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.
- risk 0.58cvss 8.8epss 0.12
A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory, aka 'Microsoft Office Remote Code Execution Vulnerability'.
- risk 0.57cvss 8.8epss 0.01
Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.00
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.00
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
- risk 0.57cvss 8.8epss 0.00
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
- risk 0.57cvss 8.8epss 0.04
Microsoft Outlook Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.03
Microsoft Outlook Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft Office Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability
- risk 0.56cvss 6.5epss 0.19
Microsoft Word Information Disclosure Vulnerability
- risk 0.55cvss 8.4epss 0.00
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.55cvss 8.4epss 0.00
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.55cvss 8.4epss 0.00
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.55cvss 8.4epss 0.00
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.55cvss 8.4epss 0.00
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Page 2 of 33