VendorsMicrosoftword2013
Vulnerabilities

Microsoft Word 2013

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

99CVEs
CVE-2019-1461
A denial of service vulnerability exists in Microsoft Word software when the software fails to properly handle objects in memory, aka 'Microsoft Word Denial of Service Vulnerability'.
Published 2019-12-10 · Modified
7.1EPSS 0.046
CVE-2023-36761
Microsoft Word Information Disclosure Vulnerability
Published 2023-09-12 · Analyzed
6.5KEVEPSS 0.196
CVE-2018-0950
An information disclosure vulnerability exists when Office renders Rich Text Format (RTF) email messages containing OLE objects when a message is opened or previewed, aka "Microsoft Office Information Disclosure Vulnerability." This affects Microsoft Word, Microsoft Office. This CVE ID is unique from CVE-2018-1007.
Published 2018-04-12 · Modified
6.5EPSS 0.089
CVE-2016-3279
Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Excel 2013 SP1, PowerPoint 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Excel 2016, Word 2016, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to execute arbitrary code via a crafted XLA file, aka "Microsoft Office Remote Code Execution Vulnerability."
Published 2016-07-13 · Modified
5.5EPSS 0.164
CVE-2021-31178
Microsoft Office Information Disclosure Vulnerability
Published 2021-05-11 · Modified
5.5EPSS 0.160
CVE-2017-0029
Microsoft Office 2010 SP2, Word 2010 SP2, Word 2013 RT SP1, and Word 2016 allow remote attackers to cause a denial of service (application hang) via a crafted Office document, aka "Microsoft Office Denial of Service Vulnerability."
Published 2017-03-17 · Modified
5.5EPSS 0.156
CVE-2019-0561
An information disclosure vulnerability exists when Microsoft Word macro buttons are used improperly, aka "Microsoft Word Information Disclosure Vulnerability." This affects Microsoft Word, Office 365 ProPlus, Microsoft Office, Word.
Published 2019-01-08 · Modified
5.5EPSS 0.079
CVE-2020-1342
An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory, aka 'Microsoft Office Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1445.
Published 2020-07-14 · Modified
5.5EPSS 0.064
CVE-2020-1445
An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory, aka 'Microsoft Office Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1342.
Published 2020-07-14 · Modified
5.5EPSS 0.061
CVE-2020-1503
Microsoft Word Information Disclosure Vulnerability
Published 2020-08-17 · Modified
5.5EPSS 0.046
CVE-2022-29107
Microsoft Office Security Feature Bypass Vulnerability
Published 2022-05-10 · Modified
5.5EPSS 0.029
CVE-2020-17020
Microsoft Word Security Feature Bypass Vulnerability
Published 2020-11-11 · Modified
5.5EPSS 0.013
CVE-2022-24511
Microsoft Office Word Tampering Vulnerability
Published 2022-03-09 · Modified
5.5EPSS 0.011
CVE-2022-41103
Microsoft Word Information Disclosure Vulnerability
Published 2022-11-09 · Modified
5.5EPSS 0.009
CVE-2022-41060
Microsoft Word Information Disclosure Vulnerability
Published 2022-11-09 · Modified
5.5EPSS 0.008
CVE-2015-2423
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10, Excel 2007 SP3, PowerPoint 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Visio 2010 SP2, Word 2010 SP2, Excel 2013 SP1, PowerPoint 2013 SP1, Visio 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Visio 2013 RT SP1, Word 2013 RT SP1, and Internet Explorer 7 through 11 allow remote attackers to gain privileges and obtain sensitive information via a crafted command-line parameter to an Office application or Notepad, as demonstrated by a transition from Low Integrity to Medium Integrity, aka "Unsafe Command Line Parameter Passing Vulnerability."
Published 2015-08-15 · Modified
4.3EPSS 0.199
CVE-2018-0919
Microsoft Office 2010 SP2, 2013 SP1, and 2016, Microsoft Office 2016 Click-to-Run Microsoft Office 2016 for Mac, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps 2013 SP1, Microsoft SharePoint Enterprise Server 2013 SP1, Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2010 SP2, Microsoft Word 2010 SP2, Word 2013 SP1 and Microsoft Word 2016 allow an information disclosure vulnerability due to how variables are initialized, aka "Microsoft Office Information Disclosure Vulnerability".
Published 2018-03-14 · Modified
4.3EPSS 0.117
CVE-2016-0012
Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Visio 2010 SP2, Word 2010 SP2, Office 2013 SP1, Excel 2013 SP1, PowerPoint 2013 SP1, Visio 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Office 2016, Excel 2016, PowerPoint 2016, Visio 2016, Word 2016, and Visual Basic 6.0 Runtime allow remote attackers to bypass the ASLR protection mechanism via unspecified vectors, aka "Microsoft Office ASLR Bypass."
Published 2016-01-13 · Modified
4.3EPSS 0.109
CVE-2020-1229
A security feature bypass vulnerability exists in Microsoft Outlook when Office fails to enforce security settings configured on a system, aka 'Microsoft Outlook Security Feature Bypass Vulnerability'.
Published 2020-06-09 · Modified
4.3EPSS 0.038
← Prev3 / 3