Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Word
(Microsoft)| Repositories |
Unknown: This might be proprietary software. |
| #Vulnerabilities | 234 |
| Date | Id | Summary | Products | Score | Patch | Annotated |
|---|---|---|---|---|---|---|
| 2025-04-08 | CVE-2025-29816 | Improper input validation in Microsoft Office Word allows an unauthorized attacker to bypass a security feature over a network. | 365_apps, Office, Office_long_term_servicing_channel, Word | N/A | ||
| 2025-06-10 | CVE-2025-47168 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 365_apps, Office, Office_long_term_servicing_channel, Sharepoint_enterprise_server, Sharepoint_server, Word | N/A | ||
| 2025-06-10 | CVE-2025-47169 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 365_apps, Office, Office_long_term_servicing_channel, Sharepoint_enterprise_server, Sharepoint_server, Word | N/A | ||
| 2025-03-11 | CVE-2025-24078 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 365_apps, Office, Office_long_term_servicing_channel, Word | 7.0 | ||
| 2025-03-11 | CVE-2025-24079 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 365_apps, Office, Office_long_term_servicing_channel, Word | 7.8 | ||
| 2019-06-12 | CVE-2019-1034 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with the same permissions as the current user. To exploit the vulnerability, a user must open a specially crafted file with an affected... | Office, Office_365_proplus, Office_online_server, Office_web_apps, Sharepoint_enterprise_server, Sharepoint_server, Word | 7.8 | ||
| 2022-11-09 | CVE-2022-41061 | Microsoft Word Remote Code Execution Vulnerability | 365_apps, Office, Office_online_server, Office_web_apps_server, Sharepoint_enterprise_server, Sharepoint_server, Word | N/A | ||
| 2023-07-11 | CVE-2023-33150 | Microsoft Office Security Feature Bypass Vulnerability | 365_apps, Office, Word | N/A | ||
| 2012-12-12 | CVE-2012-2539 | Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office Web Apps 2010 SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, aka "Word RTF 'listoverridecount' Remote Code Execution Vulnerability." | Office_compatibility_pack, Office_web_apps, Office_word_viewer, Sharepoint_server, Word | 7.8 | ||
| 2014-03-25 | CVE-2014-1761 | Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation Services on SharePoint Server 2010 SP1 and SP2 and 2013; Office Web Apps 2010 SP1 and SP2; and Office Web Apps Server 2013 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, as exploited in the wild in March 2014. | Office, Office_compatibility_pack, Office_web_apps, Office_web_apps_server, Sharepoint_server, Word, Word_viewer | 7.8 |