VendorsMicrosoftoffice_web_appsall versions
Vulnerabilities

Microsoft Office Web Apps

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

106CVEs
CVE-2017-0281
Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2016, Office Online Server 2016, Office Web Apps 2010 SP2,Office Web Apps 2013 SP1, Project Server 2013 SP1, SharePoint Enterprise Server 2013 SP1, SharePoint Enterprise Server 2016, SharePoint Foundation 2013 SP1, Sharepoint Server 2010 SP2, Word 2016, and Skype for Business 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0261 and CVE-2017-0262.
Published 2017-05-12 · Modified
9.3EPSS 0.158
CVE-2016-0183
The Windows font library in Microsoft Office 2010 SP2, Word 2010 SP2, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Microsoft Office Graphics RCE Vulnerability."
Published 2016-05-11 · Modified
9.3EPSS 0.157
CVE-2016-0054
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, Office Compatibility Pack SP3, Excel Viewer, Excel Services on SharePoint Server 2007 SP3, Excel Services on SharePoint Server 2010 SP2, Excel Services on SharePoint Server 2013 SP1, and Office Web Apps 2010 SP2 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Published 2016-02-10 · Modified
9.3EPSS 0.157
CVE-2016-0025
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Office 2016, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, Office Web Apps Server 2013 SP1, and Office Online Server allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Published 2016-06-16 · Modified
9.3EPSS 0.154
CVE-2014-0260
Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Office Compatibility Pack SP3; Word Viewer; SharePoint Server 2010 SP1 and SP2 and 2013; Office Web Apps 2010 SP1 and SP2; and Office Web Apps Server 2013 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability."
Published 2014-01-15 · Modified
9.3EPSS 0.154
CVE-2020-0980
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'.
Published 2020-04-15 · Modified
9.3EPSS 0.118
CVE-2020-0892
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0850, CVE-2020-0851, CVE-2020-0852, CVE-2020-0855.
Published 2020-03-12 · Modified
9.3EPSS 0.118
CVE-2019-1034
Microsoft Word Remote Code Execution Vulnerability
Published 2019-06-12 · Modified
9.3EPSS 0.049
CVE-2019-1201
Microsoft Word Remote Code Execution Vulnerability
Published 2019-08-14 · Modified
9.3EPSS 0.049
CVE-2020-17065
Microsoft Excel Remote Code Execution Vulnerability
Published 2020-11-11 · Modified
9.3EPSS 0.041
CVE-2021-1715
Microsoft Word Remote Code Execution Vulnerability
Published 2021-01-12 · Modified
9.3EPSS 0.036
CVE-2021-1716
Microsoft Word Remote Code Execution Vulnerability
Published 2021-01-12 · Modified
9.3EPSS 0.036
CVE-2020-17123
Microsoft Excel Remote Code Execution Vulnerability
Published 2020-12-09 · Modified
9.3EPSS 0.036
CVE-2020-17122
Microsoft Excel Remote Code Execution Vulnerability
Published 2020-12-09 · Modified
9.3EPSS 0.035
CVE-2020-17125
Microsoft Excel Remote Code Execution Vulnerability
Published 2020-12-09 · Modified
9.3EPSS 0.035
CVE-2020-17129
Microsoft Excel Remote Code Execution Vulnerability
Published 2020-12-09 · Modified
9.3EPSS 0.035
CVE-2020-17128
Microsoft Excel Remote Code Execution Vulnerability
Published 2020-12-09 · Modified
9.3EPSS 0.027
CVE-2020-1446
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1447, CVE-2020-1448.
Published 2020-07-14 · Modified
8.8EPSS 0.112
CVE-2020-1447
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1448.
Published 2020-07-14 · Modified
8.8EPSS 0.106
CVE-2020-1448
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1447.
Published 2020-07-14 · Modified
8.8EPSS 0.100
CVE-2020-1583
Microsoft Word Information Disclosure Vulnerability
Published 2020-08-17 · Modified
8.8EPSS 0.049
CVE-2020-1335
Microsoft Excel Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
8.8EPSS 0.039
CVE-2020-1218
Microsoft Word Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
8.8EPSS 0.038
CVE-2022-21840
Microsoft Office Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
8.8EPSS 0.031
CVE-2021-38655
Microsoft Excel Remote Code Execution Vulnerability
Published 2021-09-15 · Modified
7.8EPSS 0.063
CVE-2020-16931
Microsoft Excel Remote Code Execution Vulnerability
Published 2020-10-16 · Modified
7.8EPSS 0.048
CVE-2020-16932
Microsoft Excel Remote Code Execution Vulnerability
Published 2020-10-16 · Modified
7.8EPSS 0.048
CVE-2021-27053
Microsoft Excel Remote Code Execution Vulnerability
Published 2021-03-11 · Modified
7.8EPSS 0.046
CVE-2021-28453
Microsoft Word Remote Code Execution Vulnerability
Published 2021-04-13 · Modified
7.8EPSS 0.041
CVE-2021-27057
Microsoft Office Remote Code Execution Vulnerability
Published 2021-03-11 · Modified
7.8EPSS 0.040
CVE-2021-27054
Microsoft Excel Remote Code Execution Vulnerability
Published 2021-03-11 · Modified
7.8EPSS 0.040
CVE-2020-16929
Microsoft Excel Remote Code Execution Vulnerability
Published 2020-10-16 · Modified
7.8EPSS 0.037
CVE-2020-17064
Microsoft Excel Remote Code Execution Vulnerability
Published 2020-11-11 · Modified
7.8EPSS 0.034
CVE-2021-24069
Microsoft Excel Remote Code Execution Vulnerability
Published 2021-02-25 · Modified
7.8EPSS 0.025
CVE-2021-24070
Microsoft Excel Remote Code Execution Vulnerability
Published 2021-02-25 · Modified
7.8EPSS 0.025
CVE-2021-24068
Microsoft Excel Remote Code Execution Vulnerability
Published 2021-02-25 · Modified
7.8EPSS 0.025
CVE-2021-24067
Microsoft Excel Remote Code Execution Vulnerability
Published 2021-02-25 · Modified
7.8EPSS 0.025
CVE-2021-43256
Microsoft Excel Remote Code Execution Vulnerability
Published 2021-12-15 · Modified
7.8EPSS 0.021
CVE-2017-8696
Windows Uniscribe in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Office 2007 SP3; Office 2010 SP2; Word Viewer; Office for Mac 2011 and 2016; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live Meeting 2007 Add-in and Console allows an attacker to execute code remotely via a specially crafted website or a specially crafted document or email attachment, aka "Microsoft Graphics Component Remote Code Execution."
Published 2017-09-13 · Modified
7.6EPSS 0.143
CVE-2016-7291
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word for Mac 2011, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted document, aka "Microsoft Office Information Disclosure Vulnerability," a different vulnerability than CVE-2016-7290.
Published 2016-12-20 · Modified
7.1EPSS 0.228
← Prev2 / 3Next →