VendorsMicrosoftwordall versions
Vulnerabilities

Microsoft Word

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

320CVEs
CVE-2015-1651
Use-after-free vulnerability in Microsoft Word 2007 SP3, Word Viewer, and Office Compatibility Pack SP3 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Component Use After Free Vulnerability."
Published 2015-04-14 · Modified
9.3EPSS 0.165
CVE-2014-0259
Microsoft Word 2007 SP3 and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability."
Published 2014-01-15 · Modified
9.3EPSS 0.165
CVE-2014-6335
Microsoft Word 2007 SP3, Word Viewer, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Invalid Pointer Remote Code Execution Vulnerability."
Published 2014-11-11 · Modified
9.3EPSS 0.160
CVE-2016-0056
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Published 2016-02-10 · Modified
9.3EPSS 0.160
CVE-2017-0281
Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2016, Office Online Server 2016, Office Web Apps 2010 SP2,Office Web Apps 2013 SP1, Project Server 2013 SP1, SharePoint Enterprise Server 2013 SP1, SharePoint Enterprise Server 2016, SharePoint Foundation 2013 SP1, Sharepoint Server 2010 SP2, Word 2016, and Skype for Business 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0261 and CVE-2017-0262.
Published 2017-05-12 · Modified
9.3EPSS 0.158
CVE-2016-0183
The Windows font library in Microsoft Office 2010 SP2, Word 2010 SP2, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Microsoft Office Graphics RCE Vulnerability."
Published 2016-05-11 · Modified
9.3EPSS 0.157
CVE-2014-0258
Microsoft Word 2003 SP3 and 2007 SP3, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability."
Published 2014-01-15 · Modified
9.3EPSS 0.156
CVE-2016-0025
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Office 2016, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, Office Web Apps Server 2013 SP1, and Office Online Server allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Published 2016-06-16 · Modified
9.3EPSS 0.154
CVE-2014-0260
Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Office Compatibility Pack SP3; Word Viewer; SharePoint Server 2010 SP1 and SP2 and 2013; Office Web Apps 2010 SP1 and SP2; and Office Web Apps Server 2013 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability."
Published 2014-01-15 · Modified
9.3EPSS 0.154
CVE-2015-6091
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, and Word Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Published 2015-11-11 · Modified
9.3EPSS 0.145
CVE-2015-6092
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Published 2015-11-11 · Modified
9.3EPSS 0.145
CVE-2015-2379
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Office for Mac 2011, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Published 2015-07-14 · Modified
9.3EPSS 0.137
CVE-2015-2380
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, and Word 2013 RT SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Published 2015-07-14 · Modified
9.3EPSS 0.137
CVE-2015-6124
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Published 2015-12-09 · Modified
9.3EPSS 0.137
CVE-2015-0086
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 Gold and SP1, Word 2013 RT Gold and SP1, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 Gold and SP1, Web Applications 2010 SP2, and Web Apps Server 2013 Gold and SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted RTF document, aka "Microsoft Office Memory Corruption Vulnerability."
Published 2015-03-11 · Modified
9.3EPSS 0.135
CVE-2006-3877
Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via an unspecified "crafted file," a different vulnerability than CVE-2006-3435, CVE-2006-4694, and CVE-2006-3876.
Published 2006-10-10 · Modified
9.3EPSS 0.134
CVE-2019-0953
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'.
Published 2019-05-16 · Modified
9.3EPSS 0.129
CVE-2014-6356
Array index error in Microsoft Word 2007 SP3, Word 2010 SP2, and Office Compatibility Pack SP3 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Invalid Index Remote Code Execution Vulnerability."
Published 2014-12-11 · Modified
9.3EPSS 0.119
CVE-2020-0980
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'.
Published 2020-04-15 · Modified
9.3EPSS 0.118
CVE-2020-0892
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0850, CVE-2020-0851, CVE-2020-0852, CVE-2020-0855.
Published 2020-03-12 · Modified
9.3EPSS 0.118
CVE-2017-11854
Microsoft Word 2007 Service Pack 3, Microsoft Word 2010 Service Pack 2, Microsoft Office 2010 Service Pack 2, and Microsoft Office Compatibility Pack Service Pack 3 allow an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memory, aka "Microsoft Word Memory Corruption Vulnerability".
Published 2017-11-15 · Modified
9.3EPSS 0.084
CVE-2019-1034
Microsoft Word Remote Code Execution Vulnerability
Published 2019-06-12 · Modified
9.3EPSS 0.049
CVE-2019-1201
Microsoft Word Remote Code Execution Vulnerability
Published 2019-08-14 · Modified
9.3EPSS 0.049
CVE-2021-1716
Microsoft Word Remote Code Execution Vulnerability
Published 2021-01-12 · Modified
9.3EPSS 0.036
CVE-2021-1715
Microsoft Word Remote Code Execution Vulnerability
Published 2021-01-12 · Modified
9.3EPSS 0.036
CVE-2022-26903
Windows Graphics Component Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
9.3EPSS 0.027
CVE-2024-41165
A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Word's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and then make use of the vulnerable application's permissions.
Published 2024-12-18 · Analyzed
9.1EPSS 0.007
CVE-2020-1446
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1447, CVE-2020-1448.
Published 2020-07-14 · Modified
8.8EPSS 0.112
CVE-2020-1447
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1448.
Published 2020-07-14 · Modified
8.8EPSS 0.106
CVE-2020-1448
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1447.
Published 2020-07-14 · Modified
8.8EPSS 0.100
CVE-2020-0760
A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries, aka 'Microsoft Office Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0991.
Published 2020-04-15 · Modified
8.8EPSS 0.088
CVE-2020-0850
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0851, CVE-2020-0852, CVE-2020-0855, CVE-2020-0892.
Published 2020-03-12 · Modified
8.8EPSS 0.088
CVE-2020-1223
A remote code execution vulnerability exists when Microsoft Word for Android fails to properly handle certain files.To exploit the vulnerability, an attacker would have to convince a user to open a specially crafted URL file.The update addresses the vulnerability by correcting how Microsoft Word for Android handles specially crafted URL files., aka 'Word for Android Remote Code Execution Vulnerability'.
Published 2020-06-09 · Modified
8.8EPSS 0.080
CVE-2020-1583
Microsoft Word Information Disclosure Vulnerability
Published 2020-08-17 · Modified
8.8EPSS 0.049
CVE-2020-1218
Microsoft Word Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
8.8EPSS 0.038
CVE-2020-16933
Microsoft Word Security Feature Bypass Vulnerability
Published 2020-10-16 · Modified
8.8EPSS 0.027
CVE-2026-69759
Microsoft Office Word Remote Code Execution Vulnerability
Published 2026-09-08 · Analyzed
8.8EPSS 0.008
CVE-2026-69722
Microsoft Office Word Remote Code Execution Vulnerability
Published 2026-09-08 · Analyzed
8.8EPSS 0.008
CVE-2026-69686
Microsoft Office Word Remote Code Execution Vulnerability
Published 2026-09-08 · Analyzed
8.8EPSS 0.008
CVE-2026-69671
Microsoft Office Word Remote Code Execution Vulnerability
Published 2026-09-08 · Analyzed
8.8EPSS 0.008
← Prev4 / 8Next →