VendorsMicrosoftexcelall versions
Vulnerabilities

Microsoft Excel

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

502CVEs
CVE-2016-0054
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, Office Compatibility Pack SP3, Excel Viewer, Excel Services on SharePoint Server 2007 SP3, Excel Services on SharePoint Server 2010 SP2, Excel Services on SharePoint Server 2013 SP1, and Office Web Apps 2010 SP2 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Published 2016-02-10 · Modified
9.3EPSS 0.157
CVE-2020-0759
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.
Published 2020-02-11 · Modified
9.3EPSS 0.152
CVE-2016-3381
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3363.
Published 2016-09-14 · Modified
9.3EPSS 0.150
CVE-2016-3233
Microsoft Excel 2007 SP3, Excel 2010 SP2, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Published 2016-06-16 · Modified
9.3EPSS 0.148
CVE-2019-1327
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1331.
Published 2019-10-10 · Modified
9.3EPSS 0.140
CVE-2019-0828
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.
Published 2019-04-09 · Modified
9.3EPSS 0.137
CVE-2015-2377
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Published 2015-07-14 · Modified
9.3EPSS 0.136
CVE-2015-2415
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Published 2015-07-14 · Modified
9.3EPSS 0.136
CVE-2015-6040
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel for Mac 2011, Excel 2016 for Mac, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Published 2015-12-09 · Modified
9.3EPSS 0.136
CVE-2015-6122
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel for Mac 2011, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Published 2015-12-09 · Modified
9.3EPSS 0.136
CVE-2015-6177
Microsoft Excel 2007 SP3, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Published 2015-12-09 · Modified
9.3EPSS 0.136
CVE-2006-1302
Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with certain crafted fields in a SELECTION record, which triggers memory corruption, aka "Malformed SELECTION record Vulnerability."
Published 2006-07-13 · Modified
9.3EPSS 0.136
CVE-2006-3877
Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via an unspecified "crafted file," a different vulnerability than CVE-2006-3435, CVE-2006-4694, and CVE-2006-3876.
Published 2006-10-10 · Modified
9.3EPSS 0.134
CVE-2014-6360
Microsoft Excel 2007 SP3, Excel 2010 SP2, and Office Compatibility Pack allow remote attackers to execute arbitrary code via a crafted Office document, aka "Global Free Remote Code Execution in Excel Vulnerability."
Published 2014-12-11 · Modified
9.3EPSS 0.134
CVE-2014-6361
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 Gold and SP1, Excel 2013 RT Gold and SP1, and Office Compatibility Pack allow remote attackers to execute arbitrary code via a crafted Office document, aka "Excel Invalid Pointer Remote Code Execution Vulnerability."
Published 2014-12-11 · Modified
9.3EPSS 0.134
CVE-2011-1274
Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel Out of Bounds Array Access Vulnerability."
Published 2011-06-16 · Modified
9.3EPSS 0.133
CVE-2011-1275
Microsoft Excel 2002 SP3; Office 2004, 2008, and 2011 for Mac; and Open XML File Format Converter for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel Memory Heap Overwrite Vulnerability."
Published 2011-06-16 · Modified
9.3EPSS 0.133
CVE-2019-1110
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1111.
Published 2019-07-29 · Modified
9.3EPSS 0.132
CVE-2019-1111
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1110.
Published 2019-07-29 · Modified
9.3EPSS 0.132
CVE-2020-0906
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0979.
Published 2020-04-15 · Modified
9.3EPSS 0.115
CVE-2006-1304
Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted COLINFO record, which triggers the overflow during a "data filling operation."
Published 2006-07-13 · Modified
9.3EPSS 0.108
CVE-2006-2388
Microsoft Office Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via malformed cell comments, which lead to modification of "critical data offsets" during the rebuilding process.
Published 2006-07-13 · Modified
9.3EPSS 0.108
CVE-2006-1301
Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted SELECTION record that triggers memory corruption, a different vulnerability than CVE-2006-1302.
Published 2006-07-13 · Modified
9.3EPSS 0.098
CVE-2006-1309
Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted LABEL record that triggers memory corruption.
Published 2006-07-13 · Modified
9.3EPSS 0.097
CVE-2017-11884
Microsoft Excel 2016 Click-to-Run (C2R) allows an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11882.
Published 2017-11-15 · Modified
9.3EPSS 0.095
CVE-2006-1306
Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted BIFF record with an attacker-controlled array index that is used for a function pointer, aka "Malformed OBJECT record Vulnerability."
Published 2006-07-13 · Modified
9.3EPSS 0.092
CVE-2006-1308
Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted FNGROUPCOUNT value.
Published 2006-07-13 · Modified
9.3EPSS 0.092
CVE-2017-11878
Microsoft Excel 2007 Service Pack 3, Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Service Pack 1, Microsoft Excel 2013 RT Service Pack 1, Microsoft Excel 2016, Microsoft Office Compatibility Pack Service Pack 3, and Microsoft Excel Viewer 2007 Service Pack 3 allow an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memory, aka "Microsoft Excel Memory Corruption Vulnerability".
Published 2017-11-15 · Modified
9.3EPSS 0.062
CVE-2020-1495
Microsoft Excel Remote Code Execution Vulnerability
Published 2020-08-17 · Modified
9.3EPSS 0.042
CVE-2020-1496
Microsoft Excel Remote Code Execution Vulnerability
Published 2020-08-17 · Modified
9.3EPSS 0.042
CVE-2020-1494
Microsoft Excel Remote Code Execution Vulnerability
Published 2020-08-17 · Modified
9.3EPSS 0.042
CVE-2020-1504
Microsoft Excel Remote Code Execution Vulnerability
Published 2020-08-17 · Modified
9.3EPSS 0.042
CVE-2020-17066
Microsoft Excel Remote Code Execution Vulnerability
Published 2020-11-11 · Modified
9.3EPSS 0.041
CVE-2020-17065
Microsoft Excel Remote Code Execution Vulnerability
Published 2020-11-11 · Modified
9.3EPSS 0.041
CVE-2020-1498
Microsoft Excel Remote Code Execution Vulnerability
Published 2020-08-17 · Modified
9.3EPSS 0.039
CVE-2022-29110
Microsoft Excel Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
9.3EPSS 0.037
CVE-2020-17123
Microsoft Excel Remote Code Execution Vulnerability
Published 2020-12-09 · Modified
9.3EPSS 0.036
CVE-2020-17129
Microsoft Excel Remote Code Execution Vulnerability
Published 2020-12-09 · Modified
9.3EPSS 0.035
CVE-2020-17127
Microsoft Excel Remote Code Execution Vulnerability
Published 2020-12-09 · Modified
9.3EPSS 0.035
CVE-2020-17125
Microsoft Excel Remote Code Execution Vulnerability
Published 2020-12-09 · Modified
9.3EPSS 0.035
← Prev5 / 13Next →