Vulnerabilities (CVE)

Filtered by vendor Microsoft
Filtered by product Office
Angry Yack Logo
Total 1007 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-1151 1 Microsoft 9 Office, Windows 10, Windows 7 and 6 more 2026-02-20 9.3 HIGH 8.8 HIGH
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. ...

Show More

CVE-2019-1149 1 Microsoft 9 Office, Windows 10, Windows 7 and 6 more 2026-02-20 9.3 HIGH 8.8 HIGH
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. ...

Show More

CVE-2019-1148 1 Microsoft 9 Office, Windows 10, Windows 7 and 6 more 2026-02-20 2.1 LOW 5.5 MEDIUM
An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The update addresses the vulnerability by correcting the way in which the Windows Graphics Component handles objects in ...

Show More

CVE-2026-21258 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2026-02-11 N/A 5.5 MEDIUM
Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-21259 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2026-02-11 N/A 7.8 HIGH
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to elevate privileges locally.
CVE-2026-21260 1 Microsoft 5 365 Apps, Office, Office Long Term Servicing Channel and 2 more 2026-02-11 N/A 7.5 HIGH
Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-21261 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2026-02-11 N/A 5.5 MEDIUM
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-21511 1 Microsoft 5 365 Apps, Office, Office Long Term Servicing Channel and 2 more 2026-02-11 N/A 7.5 HIGH
Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-21509 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2026-02-11 N/A 7.8 HIGH
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-20948 1 Microsoft 5 365 Apps, Office, Office Long Term Servicing Channel and 2 more 2026-01-16 N/A 7.8 HIGH
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-20946 1 Microsoft 4 365 Apps, Excel, Office and 1 more 2026-01-16 N/A 7.8 HIGH
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-20943 1 Microsoft 3 Office, Office Deployment Tool, Sharepoint Server 2026-01-16 N/A 7.0 HIGH
Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-20953 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2026-01-14 N/A 8.4 HIGH
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-20952 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2026-01-14 N/A 8.4 HIGH
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-20950 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2026-01-14 N/A 7.8 HIGH
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-20955 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2026-01-14 N/A 7.8 HIGH
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-20957 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2026-01-14 N/A 7.8 HIGH
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-62554 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2025-12-10 N/A 8.4 HIGH
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-62555 1 Microsoft 5 365 Apps, Office, Office Long Term Servicing Channel and 2 more 2025-12-10 N/A 7.0 HIGH
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-62556 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2025-12-10 N/A 7.8 HIGH
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-62557 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2025-12-10 N/A 8.4 HIGH
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-62558 1 Microsoft 5 365 Apps, Office, Office Long Term Servicing Channel and 2 more 2025-12-10 N/A 7.8 HIGH
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-62559 1 Microsoft 5 365 Apps, Office, Office Long Term Servicing Channel and 2 more 2025-12-10 N/A 7.8 HIGH
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-62560 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2025-12-10 N/A 7.8 HIGH
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-62561 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2025-12-10 N/A 7.8 HIGH
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-62562 1 Microsoft 5 365 Apps, Office, Office Long Term Servicing Channel and 2 more 2025-12-09 N/A 7.8 HIGH
Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code locally.
CVE-2025-62563 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2025-12-09 N/A 7.8 HIGH
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-62564 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2025-12-09 N/A 7.8 HIGH
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-62553 1 Microsoft 4 365 Apps, Excel, Office and 1 more 2025-12-09 N/A 7.8 HIGH
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-62552 1 Microsoft 4 365 Apps, Access, Office and 1 more 2025-12-09 N/A 7.8 HIGH
Relative path traversal in Microsoft Office Access allows an unauthorized attacker to execute code locally.
CVE-2025-62199 1 Microsoft 4 365 Apps, Excel, Office and 1 more 2025-11-19 N/A 7.8 HIGH
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-60727 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2025-11-17 N/A 7.8 HIGH
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-62200 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2025-11-17 N/A 7.8 HIGH
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-62201 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2025-11-17 N/A 7.8 HIGH
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-62202 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2025-11-17 N/A 7.1 HIGH
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2025-62203 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2025-11-17 N/A 7.8 HIGH
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-60726 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2025-11-17 N/A 7.1 HIGH
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2025-60724 1 Microsoft 16 Office, Office Long Term Servicing Channel, Windows 10 1607 and 13 more 2025-11-17 N/A 9.8 CRITICAL
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
CVE-2025-59240 1 Microsoft 4 365 Apps, Excel, Office and 1 more 2025-11-17 N/A 5.5 MEDIUM
Exposure of sensitive information to an unauthorized actor in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2023-32029 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2025-11-04 N/A 7.8 HIGH
Microsoft Excel Remote Code Execution Vulnerability