Microsoft

Office

952 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 52.85%
  • Published 11.09.2013 14:03:48
  • Last modified 11.04.2025 00:51:21

Microsoft Office 2007 SP3 and Word 2007 SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability," a different vulnerability than CV...

  • EPSS 0.46%
  • Published 11.09.2013 14:03:48
  • Last modified 11.04.2025 00:51:21

Microsoft Pinyin IME 2010, when used in conjunction with Microsoft Office 2010 SP1, does not properly restrict configuration options, which allows local users to gain privileges by starting Internet Explorer from the IME toolbar, aka "Chinese IME Vul...

  • EPSS 46.52%
  • Published 10.07.2013 03:46:09
  • Last modified 11.04.2025 00:51:21

Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 before 5.1.20513.0; win32k.sys in the kernel-mode drivers, and GDI+, DirectWrite, and Journal, in Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Serv...

Warning
  • EPSS 85.15%
  • Published 12.06.2013 03:29:57
  • Last modified 11.04.2025 00:51:21

Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Office document, leading to improper memory allocation, aka "Office Buffer Overflow Vulnerability."

  • EPSS 29.25%
  • Published 13.03.2013 00:55:01
  • Last modified 11.04.2025 00:51:21

Outlook in Microsoft Office for Mac 2008 before 12.3.6 and Office for Mac 2011 before 14.3.2 allows remote attackers to trigger access to a remote URL and consequently confirm the rendering of an HTML e-mail message by including unspecified HTML5 ele...

  • EPSS 65.08%
  • Published 09.01.2013 18:09:40
  • Last modified 11.04.2025 00:51:21

Microsoft XML Core Services (aka MSXML) 3.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML Integer Truncation Vulnerability."

  • EPSS 27.2%
  • Published 09.01.2013 18:09:40
  • Last modified 11.04.2025 00:51:21

Microsoft XML Core Services (aka MSXML) 4.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML XSLT Vulnerability."

  • EPSS 65.94%
  • Published 14.11.2012 00:55:01
  • Last modified 11.04.2025 00:51:21

Heap-based buffer overflow in Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Office 2008 and 2011 for Mac; and Office Compatibility Pack SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Se...

  • EPSS 58.33%
  • Published 14.11.2012 00:55:01
  • Last modified 11.04.2025 00:51:21

Use-after-free vulnerability in Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 SP1, and Office 2008 and 2011 for Mac, allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel SST Invalid Length Use After Free Vuln...

  • EPSS 65.94%
  • Published 14.11.2012 00:55:01
  • Last modified 11.04.2025 00:51:21

Stack-based buffer overflow in Microsoft Excel 2007 SP2 and SP3 and 2010 SP1; Office 2011 for Mac; Excel Viewer; and Office Compatibility Pack SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Stack O...