VendorsMicrosoftoffice_web_apps2013
Vulnerabilities

Microsoft Office Web Apps 2013

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

52CVEs
CVE-2023-21716
Microsoft Word Remote Code Execution Vulnerability
Published 2023-02-14 · Modified
9.8EPSS 0.848
CVE-2015-1641
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, and Office Web Apps Server 2010 SP2 and 2013 SP1 allow remote attackers to execute arbitrary code via a crafted RTF document, aka "Microsoft Office Memory Corruption Vulnerability."
Published 2015-04-14 · Analyzed
9.3KEVEPSS 0.967
CVE-2015-1650
Use-after-free vulnerability in Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, and Office Web Apps Server 2010 SP2 and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Component Use After Free Vulnerability."
Published 2015-04-14 · Modified
9.3EPSS 0.266
CVE-2015-1649
Use-after-free vulnerability in Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps Server 2010 SP2 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Component Use After Free Vulnerability."
Published 2015-04-14 · Modified
9.3EPSS 0.231
CVE-2018-8161
A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Word, Word, Microsoft Office, Microsoft SharePoint. This CVE ID is unique from CVE-2018-8157, CVE-2018-8158.
Published 2018-05-09 · Modified
9.3EPSS 0.217
CVE-2016-7234
Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Excel for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, and Office Web Apps Server 2013 SP1 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Published 2016-11-10 · Modified
9.3EPSS 0.206
CVE-2017-0254
Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Office for Mac 2011, Office for Mac 2016, Microsoft Office Web Apps 2010 SP2, Office Web Apps Server 2013 SP1, Word 2013 RT SP1, Word 2013 SP1, Word Automation Services on Microsoft SharePoint Server 2013 SP1, Office Word Viewer, SharePoint Enterprise Server 2016, and Word 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-0264 and CVE-2017-0265.
Published 2017-05-12 · Modified
9.3EPSS 0.198
CVE-2018-1028
A remote code execution vulnerability exists when the Office graphics component improperly handles specially crafted embedded fonts, aka "Microsoft Office Graphics Remote Code Execution Vulnerability." This affects Word, Microsoft Office, Microsoft SharePoint, Excel, Microsoft SharePoint Server.
Published 2018-04-12 · Modified
9.3EPSS 0.189
CVE-2018-0922
Microsoft Office 2010 SP2, 2013 SP1, and 2016, Microsoft Office 2016 Click-to-Run Microsoft Office 2016 for Mac, Microsoft Office Compatibility Pack SP2, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps 2013 SP1, Microsoft Office Word Viewer, Microsoft SharePoint Enterprise Server 2013 SP1, Microsoft SharePoint Enterprise Server 2016, Microsoft Office Compatibility Pack SP2, Microsoft Online Server 2016, Microsoft SharePoint Server 2010 SP2, Microsoft Word 2007 SP3, Microsoft Word 2010 SP2, Word 2013 and Microsoft Word 2016 allow a remote code execution vulnerability due to how objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability".
Published 2018-03-14 · Modified
9.3EPSS 0.180
CVE-2017-8632
A remote code execution vulnerability exists in Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Service Pack 1, Microsoft Excel 2013 RT Service Pack 1, Microsoft Excel 2016, Microsoft Office Web Apps 2013, Microsoft Excel for Mac 2011, Microsoft Excel 2016 for Mac, and Microsoft Office Compatibility Pack Service Pack 3, when they fail to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8630, CVE-2017-8631, and CVE-2017-8744.
Published 2017-09-13 · Modified
9.3EPSS 0.177
CVE-2017-8631
A remote code execution vulnerability exists in Excel Services, Microsoft Excel 2007 Service Pack 3, Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Service Pack 1, Microsoft Excel 2013 RT Service Pack 1, Microsoft Excel 2016, Microsoft Office Web Apps 2013, Microsoft Office Compatibility Pack Service Pack 3, Microsoft Excel Web App 2013 Service Pack 1, Microsoft Excel Viewer 2007 Service Pack 3, and Office Online Server when they fail to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8630, CVE-2017-8632, and CVE-2017-8744.
Published 2017-09-13 · Modified
9.3EPSS 0.170
CVE-2017-0020
Microsoft Excel 2016, Excel 2010 SP2, Excel 2013 RT SP1, and Office Web Apps Server 2013 SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0006, CVE-2017-0019, CVE-2017-0030, CVE-2017-0031, CVE-2017-0052, and CVE-2017-0053.
Published 2017-03-17 · Modified
9.3EPSS 0.164
CVE-2018-8628
A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Microsoft Office, Office 365 ProPlus, Microsoft PowerPoint, Microsoft SharePoint, Microsoft PowerPoint Viewer, Office Online Server, Microsoft SharePoint Server.
Published 2018-12-12 · Modified
9.3EPSS 0.159
CVE-2017-0281
Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2016, Office Online Server 2016, Office Web Apps 2010 SP2,Office Web Apps 2013 SP1, Project Server 2013 SP1, SharePoint Enterprise Server 2013 SP1, SharePoint Enterprise Server 2016, SharePoint Foundation 2013 SP1, Sharepoint Server 2010 SP2, Word 2016, and Skype for Business 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0261 and CVE-2017-0262.
Published 2017-05-12 · Modified
9.3EPSS 0.158
CVE-2020-0980
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'.
Published 2020-04-15 · Modified
9.3EPSS 0.118
CVE-2020-17065
Microsoft Excel Remote Code Execution Vulnerability
Published 2020-11-11 · Modified
9.3EPSS 0.041
CVE-2020-17123
Microsoft Excel Remote Code Execution Vulnerability
Published 2020-12-09 · Modified
9.3EPSS 0.036
CVE-2020-17125
Microsoft Excel Remote Code Execution Vulnerability
Published 2020-12-09 · Modified
9.3EPSS 0.035
CVE-2020-17129
Microsoft Excel Remote Code Execution Vulnerability
Published 2020-12-09 · Modified
9.3EPSS 0.035
CVE-2020-17128
Microsoft Excel Remote Code Execution Vulnerability
Published 2020-12-09 · Modified
9.3EPSS 0.027
CVE-2020-1446
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1447, CVE-2020-1448.
Published 2020-07-14 · Modified
8.8EPSS 0.112
CVE-2020-1447
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1448.
Published 2020-07-14 · Modified
8.8EPSS 0.106
CVE-2020-1448
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1447.
Published 2020-07-14 · Modified
8.8EPSS 0.100
CVE-2020-1583
Microsoft Word Information Disclosure Vulnerability
Published 2020-08-17 · Modified
8.8EPSS 0.049
CVE-2020-1335
Microsoft Excel Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
8.8EPSS 0.039
CVE-2020-1218
Microsoft Word Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
8.8EPSS 0.038
CVE-2022-21840
Microsoft Office Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
8.8EPSS 0.031
CVE-2021-38655
Microsoft Excel Remote Code Execution Vulnerability
Published 2021-09-15 · Modified
7.8EPSS 0.063
CVE-2020-16931
Microsoft Excel Remote Code Execution Vulnerability
Published 2020-10-16 · Modified
7.8EPSS 0.048
CVE-2020-16932
Microsoft Excel Remote Code Execution Vulnerability
Published 2020-10-16 · Modified
7.8EPSS 0.048
CVE-2021-27053
Microsoft Excel Remote Code Execution Vulnerability
Published 2021-03-11 · Modified
7.8EPSS 0.046
CVE-2021-27057
Microsoft Office Remote Code Execution Vulnerability
Published 2021-03-11 · Modified
7.8EPSS 0.040
CVE-2021-27054
Microsoft Excel Remote Code Execution Vulnerability
Published 2021-03-11 · Modified
7.8EPSS 0.040
CVE-2020-16929
Microsoft Excel Remote Code Execution Vulnerability
Published 2020-10-16 · Modified
7.8EPSS 0.037
CVE-2020-17064
Microsoft Excel Remote Code Execution Vulnerability
Published 2020-11-11 · Modified
7.8EPSS 0.034
CVE-2021-24069
Microsoft Excel Remote Code Execution Vulnerability
Published 2021-02-25 · Modified
7.8EPSS 0.025
CVE-2021-24070
Microsoft Excel Remote Code Execution Vulnerability
Published 2021-02-25 · Modified
7.8EPSS 0.025
CVE-2021-24068
Microsoft Excel Remote Code Execution Vulnerability
Published 2021-02-25 · Modified
7.8EPSS 0.025
CVE-2021-24067
Microsoft Excel Remote Code Execution Vulnerability
Published 2021-02-25 · Modified
7.8EPSS 0.025
CVE-2021-43256
Microsoft Excel Remote Code Execution Vulnerability
Published 2021-12-15 · Modified
7.8EPSS 0.021
1 / 2Next →