Powerpoint
by Microsoft
CVEs (96)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-49705 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | ||
| CVE-2024-38171 | Hig | 0.51 | 7.8 | 0.01 | Aug 13, 2024 | Microsoft PowerPoint Remote Code Execution Vulnerability | ||
| CVE-2024-20673 | Hig | 0.51 | 7.8 | 0.01 | Feb 13, 2024 | Microsoft Office Remote Code Execution Vulnerability | ||
| CVE-2022-37962 | Hig | 0.51 | 7.8 | 0.01 | Sep 13, 2022 | Microsoft PowerPoint Remote Code Execution Vulnerability | ||
| CVE-2022-26903 | Hig | 0.51 | 7.8 | 0.03 | Apr 15, 2022 | Windows Graphics Component Remote Code Execution Vulnerability | ||
| CVE-2021-27056 | Hig | 0.51 | 7.8 | 0.03 | Mar 11, 2021 | Microsoft PowerPoint Remote Code Execution Vulnerability | ||
| CVE-2020-17124 | Hig | 0.51 | 7.8 | 0.03 | Dec 10, 2020 | Microsoft PowerPoint Remote Code Execution Vulnerability | ||
| CVE-2026-41102 | Hig | 0.46 | 7.1 | 0.00 | May 12, 2026 | Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally. | ||
| CVE-2026-26133 | Hig | 0.46 | 7.1 | 0.00 | Mar 16, 2026 | AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-49699 | Hig | 0.46 | 7.0 | 0.00 | Jul 8, 2025 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2024-39804 | Hig | 0.46 | 7.1 | 0.01 | Dec 18, 2024 | A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can leverage PowerPoint's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this… | ||
| CVE-2016-3279 | Med | 0.37 | 5.5 | 0.16 | Jul 13, 2016 | Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Excel 2013 SP1, PowerPoint 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Excel 2016, Word 2016, Word Automation Services on SharePoint Server 2010 SP2, and… | ||
| CVE-2026-68809 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | ||
| CVE-2016-0012 | Med | 0.29 | 4.3 | 0.11 | Jan 13, 2016 | Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Visio 2010 SP2, Word 2010 SP2, Office 2013 SP1, Excel 2013 SP1, PowerPoint 2013 SP1, Visio 2013 SP1, Word 2013 SP1, Excel 2013 RT… | ||
| CVE-2010-0033 | 0.07 | — | 0.51 | Feb 10, 2010 | Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint Viewer TextBytesAtom Record Stack Overflow Vulnerability." | |||
| CVE-2004-0200 | 0.07 | — | 0.49 | Sep 28, 2004 | Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length… | |||
| CVE-2015-0097 | 0.06 | — | 0.41 | Mar 11, 2015 | Microsoft Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Excel 2010 SP2, PowerPoint 2010 SP2, and Word 2010 SP2 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Word Local Zone Remote Code Execution Vulnerability." | |||
| CVE-2006-5296 | 0.05 | — | 0.26 | Oct 16, 2006 | PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record length, which allows user-assisted attackers to cause a denial of service (NULL dereference and application crash) via a crafted PowerPoint (.PPT) file, as… | |||
| CVE-2006-3655 | 0.05 | — | 0.21 | Jul 18, 2006 | Unspecified vulnerability in mso.dll in Microsoft PowerPoint 2003 allows user-assisted attackers to execute arbitrary code via a crafted PowerPoint file. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3656,… | |||
| CVE-2006-3656 | 0.05 | — | 0.21 | Jul 18, 2006 | Unspecified vulnerability in Microsoft PowerPoint 2003 allows user-assisted attackers to cause memory corruption via a crafted PowerPoint file, which triggers the corruption when the file is closed. NOTE: due to the lack of available details as of 20060717, it is unclear how… |
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.01
Microsoft PowerPoint Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Office Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft PowerPoint Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.03
Windows Graphics Component Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.03
Microsoft PowerPoint Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.03
Microsoft PowerPoint Remote Code Execution Vulnerability
- risk 0.46cvss 7.1epss 0.00
Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally.
- risk 0.46cvss 7.1epss 0.00
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
- risk 0.46cvss 7.0epss 0.00
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.46cvss 7.1epss 0.01
A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can leverage PowerPoint's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this…
- risk 0.37cvss 5.5epss 0.16
Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Excel 2013 SP1, PowerPoint 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Excel 2016, Word 2016, Word Automation Services on SharePoint Server 2010 SP2, and…
- risk 0.36cvss 5.5epss 0.00
Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
- risk 0.29cvss 4.3epss 0.11
Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Visio 2010 SP2, Word 2010 SP2, Office 2013 SP1, Excel 2013 SP1, PowerPoint 2013 SP1, Visio 2013 SP1, Word 2013 SP1, Excel 2013 RT…
- CVE-2010-0033Feb 10, 2010risk 0.07cvss —epss 0.51
Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint Viewer TextBytesAtom Record Stack Overflow Vulnerability."
- CVE-2004-0200Sep 28, 2004risk 0.07cvss —epss 0.49
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length…
- CVE-2015-0097Mar 11, 2015risk 0.06cvss —epss 0.41
Microsoft Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Excel 2010 SP2, PowerPoint 2010 SP2, and Word 2010 SP2 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Word Local Zone Remote Code Execution Vulnerability."
- CVE-2006-5296Oct 16, 2006risk 0.05cvss —epss 0.26
PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record length, which allows user-assisted attackers to cause a denial of service (NULL dereference and application crash) via a crafted PowerPoint (.PPT) file, as…
- CVE-2006-3655Jul 18, 2006risk 0.05cvss —epss 0.21
Unspecified vulnerability in mso.dll in Microsoft PowerPoint 2003 allows user-assisted attackers to execute arbitrary code via a crafted PowerPoint file. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3656,…
- CVE-2006-3656Jul 18, 2006risk 0.05cvss —epss 0.21
Unspecified vulnerability in Microsoft PowerPoint 2003 allows user-assisted attackers to cause memory corruption via a crafted PowerPoint file, which triggers the corruption when the file is closed. NOTE: due to the lack of available details as of 20060717, it is unclear how…
Page 2 of 5