VendorsMicrosoftoffice2013
Vulnerabilities

Microsoft Office 2013

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

178CVEs
CVE-2019-1463
An information disclosure vulnerability exists in Microsoft Access software when the software fails to properly handle objects in memory, aka 'Microsoft Access Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1400.
Published 2019-12-10 · Modified
5.5EPSS 0.022
CVE-2019-1400
An information disclosure vulnerability exists in Microsoft Access software when the software fails to properly handle objects in memory, aka 'Microsoft Access Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1463.
Published 2019-12-10 · Modified
5.5EPSS 0.022
CVE-2021-43255
Microsoft Office Trust Center Spoofing Vulnerability
Published 2021-12-15 · Modified
5.5EPSS 0.020
CVE-2023-41764
Microsoft Office Spoofing Vulnerability
Published 2023-09-12 · Modified
5.5EPSS 0.010
CVE-2022-23252
Microsoft Office Information Disclosure Vulnerability
Published 2022-02-09 · Modified
5.5EPSS 0.008
CVE-2023-33162
Microsoft Excel Information Disclosure Vulnerability
Published 2023-07-11 · Modified
5.5EPSS 0.008
CVE-2021-40472
Microsoft Excel Information Disclosure Vulnerability
Published 2021-10-13 · Modified
5.5EPSS 0.007
CVE-2021-40454
Rich Text Edit Control Information Disclosure Vulnerability
Published 2021-10-13 · Modified
5.5EPSS 0.005
CVE-2014-2730
The XML parser in Microsoft Office 2007 SP3, 2010 SP1 and SP2, and 2013, and Office for Mac 2011, does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory consumption and persistent application hang) via a crafted XML document containing a large number of nested entity references, as demonstrated by a crafted text/plain e-mail message to Outlook, a similar issue to CVE-2003-1564.
Published 2014-04-05 · Modified
5.0EPSS 0.115
CVE-2022-33632
Microsoft Office Security Feature Bypass Vulnerability
Published 2022-07-12 · Modified
4.7EPSS 0.011
CVE-2014-6362
Use-after-free vulnerability in Microsoft Office 2007 SP3, 2010 SP2, and 2013 Gold and SP1 allows remote attackers to bypass the ASLR protection mechanism via a crafted document, aka "Microsoft Office Component Use After Free Vulnerability."
Published 2015-02-11 · Modified
4.3EPSS 0.162
CVE-2013-5054
Microsoft Office 2013 and 2013 RT allows remote attackers to discover authentication tokens via a crafted response to a file-open request for an Office file on a web site, as exploited in the wild in 2013, aka "Token Hijacking Vulnerability."
Published 2013-12-11 · Modified
4.3EPSS 0.128
CVE-2018-0853
Microsoft Office 2010 SP2, Microsoft Office 2013 SP1 and RT SP1, Microsoft Office 2016, and Microsoft Office 2016 Click-to-Run (C2R) allow an information disclosure vulnerability, due to how Office initializes the affected variable, aka "Microsoft Office Information Disclosure Vulnerability".
Published 2018-02-15 · Modified
4.3EPSS 0.118
CVE-2016-0012
Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Visio 2010 SP2, Word 2010 SP2, Office 2013 SP1, Excel 2013 SP1, PowerPoint 2013 SP1, Visio 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Office 2016, Excel 2016, PowerPoint 2016, Visio 2016, Word 2016, and Visual Basic 6.0 Runtime allow remote attackers to bypass the ASLR protection mechanism via unspecified vectors, aka "Microsoft Office ASLR Bypass."
Published 2016-01-13 · Modified
4.3EPSS 0.109
CVE-2014-1808
Microsoft Office 2013 Gold, SP1, RT, and RT SP1 allows remote attackers to obtain sensitive token information via a web site that sends a crafted response during opening of an Office document, aka "Token Reuse Vulnerability."
Published 2014-05-14 · Modified
4.3EPSS 0.101
CVE-2016-0137
The Click-to-Run (C2R) implementation in Microsoft Office 2013 SP1 and 2016 allows local users to bypass the ASLR protection mechanism via a crafted application, aka "Microsoft APP-V ASLR Bypass."
Published 2016-09-14 · Modified
4.3EPSS 0.068
CVE-2020-1229
A security feature bypass vulnerability exists in Microsoft Outlook when Office fails to enforce security settings configured on a system, aka 'Microsoft Outlook Security Feature Bypass Vulnerability'.
Published 2020-06-09 · Modified
4.3EPSS 0.038
CVE-2023-36767
Microsoft Office Security Feature Bypass Vulnerability
Published 2023-09-12 · Modified
4.3EPSS 0.031
← Prev5 / 5