VendorsMicrosoftpublisherall versions
Vulnerabilities

Microsoft Publisher

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

45CVEs
CVE-2004-0573
Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website.
Published 2004-09-17 · Modified
7.5EPSS 0.423
CVE-2008-3068
Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times and IP addresses of recipients, and port-scan results, via a crafted certificate with an Authority Information Access (AIA) extension.
Published 2008-07-07 · Modified
7.5EPSS 0.174
CVE-2024-38226
Microsoft Publisher Security Feature Bypass Vulnerability
Published 2024-09-10 · Analyzed
7.3KEVEPSS 0.027
CVE-2007-6534
Multiple unspecified vulnerabilities in Microsoft Office Publisher allow user-assisted remote attackers to cause a denial of service (application crash) via a crafted PUB file, possibly involving wordart.
Published 2007-12-27 · Modified
6.8EPSS 0.111
CVE-2022-29107
Microsoft Office Security Feature Bypass Vulnerability
Published 2022-05-10 · Modified
5.5EPSS 0.029
← Prev2 / 2