Microsoft Word
by Microsoft
CVEs (48)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-21511 | 0.00 | — | 0.00 | Feb 10, 2026 | Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. | |||
| CVE-2026-20948 | 0.00 | — | 0.00 | Jan 13, 2026 | Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |||
| CVE-2025-62559 | 0.00 | — | 0.00 | Dec 9, 2025 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |||
| CVE-2025-62558 | 0.00 | — | 0.00 | Dec 9, 2025 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |||
| CVE-2025-62555 | 0.00 | — | 0.00 | Dec 9, 2025 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |||
| CVE-2025-62562 | 0.00 | — | 0.00 | Dec 9, 2025 | Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code locally. | |||
| CVE-2025-59222 | 0.00 | — | 0.00 | Oct 14, 2025 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |||
| CVE-2025-59221 | 0.00 | — | 0.00 | Oct 14, 2025 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |||
| CVE-2025-54905 | 0.00 | — | 0.00 | Sep 9, 2025 | Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | |||
| CVE-2025-53738 | 0.00 | — | 0.00 | Aug 12, 2025 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |||
| CVE-2025-53736 | 0.00 | — | 0.00 | Aug 12, 2025 | Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | |||
| CVE-2025-53733 | 0.00 | — | 0.01 | Aug 12, 2025 | Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |||
| CVE-2025-49703 | 0.00 | — | 0.01 | Jul 8, 2025 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |||
| CVE-2025-49700 | 0.00 | — | 0.01 | Jul 8, 2025 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |||
| CVE-2025-49699 | 0.00 | — | 0.00 | Jul 8, 2025 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |||
| CVE-2025-49698 | 0.00 | — | 0.01 | Jul 8, 2025 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |||
| CVE-2025-47169 | 0.00 | — | 0.01 | Jun 10, 2025 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |||
| CVE-2025-47168 | 0.00 | — | 0.01 | Jun 10, 2025 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |||
| CVE-2025-29816 | 0.00 | — | 0.00 | Apr 8, 2025 | Improper input validation in Microsoft Office Word allows an unauthorized attacker to bypass a security feature over a network. | |||
| CVE-2025-27747 | 0.00 | — | 0.01 | Apr 8, 2025 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
- CVE-2026-21511Feb 10, 2026risk 0.00cvss —epss 0.00
Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-20948Jan 13, 2026risk 0.00cvss —epss 0.00
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2025-62559Dec 9, 2025risk 0.00cvss —epss 0.00
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2025-62558Dec 9, 2025risk 0.00cvss —epss 0.00
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2025-62555Dec 9, 2025risk 0.00cvss —epss 0.00
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2025-62562Dec 9, 2025risk 0.00cvss —epss 0.00
Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code locally.
- CVE-2025-59222Oct 14, 2025risk 0.00cvss —epss 0.00
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2025-59221Oct 14, 2025risk 0.00cvss —epss 0.00
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2025-54905Sep 9, 2025risk 0.00cvss —epss 0.00
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- CVE-2025-53738Aug 12, 2025risk 0.00cvss —epss 0.00
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2025-53736Aug 12, 2025risk 0.00cvss —epss 0.00
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- CVE-2025-53733Aug 12, 2025risk 0.00cvss —epss 0.01
Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2025-49703Jul 8, 2025risk 0.00cvss —epss 0.01
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2025-49700Jul 8, 2025risk 0.00cvss —epss 0.01
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2025-49699Jul 8, 2025risk 0.00cvss —epss 0.00
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2025-49698Jul 8, 2025risk 0.00cvss —epss 0.01
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2025-47169Jun 10, 2025risk 0.00cvss —epss 0.01
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2025-47168Jun 10, 2025risk 0.00cvss —epss 0.01
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2025-29816Apr 8, 2025risk 0.00cvss —epss 0.00
Improper input validation in Microsoft Office Word allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2025-27747Apr 8, 2025risk 0.00cvss —epss 0.01
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Page 2 of 3