Vulnerabilities > Microsoft > Office FOR MAC

DATE CVE VULNERABILITY TITLE RISK
2018-09-13 CVE-2018-8429 Information Exposure vulnerability in Microsoft products
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel.
network
microsoft CWE-200
4.3
2018-09-13 CVE-2018-8332 Unspecified vulnerability in Microsoft products
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Win32k Graphics Remote Code Execution Vulnerability." This affects Windows 7, Microsoft Office, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2008 R2, Windows Server 2012, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.
network
microsoft
critical
9.3
2018-08-15 CVE-2018-8412 Improper Input Validation vulnerability in Microsoft Office for mac 2016
An elevation of privilege vulnerability exists when the Microsoft AutoUpdate (MAU) application for Mac improperly validates updates before executing them, aka "Microsoft (MAU) Office Elevation of Privilege Vulnerability." This affects Microsoft Office.
local
low complexity
microsoft CWE-20
4.6
2018-05-23 CVE-2018-8176 Improper Input Validation vulnerability in Microsoft Office for mac 2016
A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly validate XML content, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Microsoft Office.
network
microsoft CWE-20
critical
9.3
2018-05-09 CVE-2018-8162 Unspecified vulnerability in Microsoft Excel, Office and Office FOR mac
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Excel.
network
microsoft
critical
9.3
2018-05-09 CVE-2018-8148 Unspecified vulnerability in Microsoft products
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Excel.
network
microsoft
critical
9.3
2018-05-09 CVE-2018-8147 Unspecified vulnerability in Microsoft products
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Excel.
network
microsoft
critical
9.3
2017-10-13 CVE-2017-11825 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Microsoft Office and Office FOR mac
Microsoft Office 2016 Click-to-Run (C2R) and Microsoft Office 2016 for Mac allow an attacker to use a specially crafted file to perform actions in the security context of the current user, due to how Microsoft Office handles files in memory, aka "Microsoft Office Remote Code Execution Vulnerability".
network
microsoft CWE-119
critical
9.3
2016-12-20 CVE-2016-7276 Out-of-bounds Read vulnerability in Microsoft Office and Office FOR mac
Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office for Mac 2011, and Office 2016 for Mac allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted document, aka "Microsoft Office Information Disclosure Vulnerability."
network
microsoft CWE-125
5.8
2016-12-20 CVE-2016-7257 Information Exposure vulnerability in Microsoft products
The GDI component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office for Mac 2011, and Office 2016 for Mac allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "GDI Information Disclosure Vulnerability."
network
microsoft CWE-200
4.3