Filtered by vendor Microsoft Subscriptions
Filtered by product Office Subscriptions
Total 964 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2006-1316 1 Microsoft 1 Office 2025-04-03 N/A
Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via an Office file with malformed string that triggers memory corruption related to record lengths, aka "Microsoft Office Parsing Vulnerability," a different vulnerability than CVE-2006-2389.
CVE-2000-0419 1 Microsoft 10 Access, Excel, Frontpage and 7 more 2025-04-03 N/A
The Office 2000 UA ActiveX Control is marked as "safe for scripting," which allows remote attackers to conduct unauthorized activities via the "Show Me" function in Office Help, aka the "Office 2000 UA Control" vulnerability.
CVE-2001-0003 1 Microsoft 4 Office, Windows 2000, Windows Me and 1 more 2025-04-03 N/A
Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials and possibly obtain the password, aka the "Web Client NTLM Authentication" vulnerability.
CVE-2002-0021 1 Microsoft 1 Office 2025-04-03 N/A
Network Product Identification (PID) Checker in Microsoft Office v. X for Mac allows remote attackers to cause a denial of service (crash) via a malformed product announcement.
CVE-2002-0152 1 Microsoft 6 Entourage, Excel, Ie and 3 more 2025-04-03 N/A
Buffer overflow in various Microsoft applications for Macintosh allows remote attackers to cause a denial of service (crash) or execute arbitrary code by invoking the file:// directive with a large number of / characters, which affects Internet Explorer 5.1, Outlook Express 5.0 through 5.0.2, Entourage v. X and 2001, PowerPoint v. X, 2001, and 98, and Excel v. X and 2001 for Macintosh.
CVE-2002-0615 1 Microsoft 2 Excel, Office 2025-04-03 N/A
The Windows Media Active Playlist in Microsoft Windows Media Player 7.1 stores information in a well known location on the local file system, allowing attackers to execute HTML scripts in the Local Computer zone, aka "Media Playback Script Invocation".
CVE-2002-0616 1 Microsoft 2 Excel, Office 2025-04-03 N/A
The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code by attaching an inline macro to an object within an Excel workbook, aka the "Excel Inline Macros Vulnerability."
CVE-2002-0617 1 Microsoft 2 Excel, Office 2025-04-03 N/A
The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code by creating a hyperlink on a drawing shape in a source workbook that points to a destination workbook containing an autoexecute macro, aka "Hyperlinked Excel Workbook Macro Bypass."
CVE-2002-0618 1 Microsoft 2 Excel, Office 2025-04-03 N/A
The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code in the Local Computer zone by embedding HTML scripts within an Excel workbook that contains an XSL stylesheet, aka "Excel XSL Stylesheet Script Execution".
CVE-2002-0619 1 Microsoft 1 Office 2025-04-03 N/A
The Mail Merge Tool in Microsoft Word 2002 for Windows, when Microsoft Access is present on a system, allows remote attackers to execute Visual Basic (VBA) scripts within a mail merge document that is saved in HTML format, aka a "Variant of MS00-071, Word Mail Merge Vulnerability" (CVE-2000-0788).
CVE-2002-0862 2 Apple, Microsoft 10 Macos, Internet Explorer, Office and 7 more 2025-04-03 N/A
The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS.
CVE-2006-4534 1 Microsoft 1 Office 2025-04-03 N/A
Unspecified vulnerability in Microsoft Word 2000, 2002, and Office 2003 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors involving a crafted file resulting in a malformed stack, as exploited by malware with names including Trojan.Mdropper.Q, Mofei, and Femo.
CVE-2006-3493 1 Microsoft 1 Office 2025-04-03 N/A
Buffer overflow in LsCreateLine function (mso_203) in mso.dll and mso9.dll, as used by Microsoft Word and possibly other products in Microsoft Office 2003, 2002, and 2000, allows remote user-assisted attackers to cause a denial of service (crash) via a crafted Word DOC or other Office file type. NOTE: this issue was originally reported to allow code execution, but on 20060710 Microsoft stated that code execution is not possible, and the original researcher agrees.
CVE-2006-2389 1 Microsoft 1 Office 2025-04-03 N/A
Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via an Office file with a malformed property that triggers memory corruption related to record lengths, aka "Microsoft Office Property Vulnerability," a different vulnerability than CVE-2006-1316.
CVE-2022-37963 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2025-03-11 7.8 High
Microsoft Office Visio Remote Code Execution Vulnerability
CVE-2022-37962 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2025-03-11 7.8 High
Microsoft PowerPoint Remote Code Execution Vulnerability
CVE-2022-38010 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2025-03-11 7.8 High
Microsoft Office Visio Remote Code Execution Vulnerability
CVE-2023-36765 1 Microsoft 1 Office 2025-02-28 7.8 High
Microsoft Office Elevation of Privilege Vulnerability
CVE-2023-33150 1 Microsoft 3 365 Apps, Office, Word 2025-02-28 9.6 Critical
Microsoft Office Security Feature Bypass Vulnerability
CVE-2023-33148 1 Microsoft 2 365 Apps, Office 2025-02-28 7.8 High
Microsoft Office Elevation of Privilege Vulnerability