Vulnerabilities > Microsoft > Office

DATE CVE VULNERABILITY TITLE RISK
2019-08-14 CVE-2019-1151 Out-of-bounds Write vulnerability in Microsoft products
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts.
network
low complexity
microsoft CWE-787
8.8
2019-08-14 CVE-2019-1149 Out-of-bounds Write vulnerability in Microsoft products
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts.
network
low complexity
microsoft CWE-787
8.8
2019-08-14 CVE-2019-1148 Out-of-bounds Read vulnerability in Microsoft products
An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory.
local
low complexity
microsoft CWE-125
5.5
2019-07-15 CVE-2019-1112 Information Exposure vulnerability in Microsoft Office and Office 365 Proplus
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information Disclosure Vulnerability'.
local
low complexity
microsoft CWE-200
5.5
2019-07-15 CVE-2019-1111 Unspecified vulnerability in Microsoft Excel, Office and Office 365 Proplus
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.
network
low complexity
microsoft
8.8
2019-07-15 CVE-2019-1110 Unspecified vulnerability in Microsoft Excel, Office and Office 365 Proplus
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.
network
low complexity
microsoft
8.8
2019-07-15 CVE-2019-1109 Improper Input Validation vulnerability in Microsoft Office and Office 365
A spoofing vulnerability exists when Microsoft Office Javascript does not check the validity of the web page making a request to Office documents.An attacker who successfully exploited this vulnerability could read or write information in Office documents.The security update addresses the vulnerability by correcting the way that Microsoft Office Javascript verifies trusted web pages., aka 'Microsoft Office Spoofing Vulnerability'.
network
low complexity
microsoft CWE-20
critical
9.1
2019-07-15 CVE-2019-1084 Information Exposure vulnerability in Microsoft products
An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters.
network
low complexity
microsoft CWE-200
6.5
2019-06-12 CVE-2019-1035 Unspecified vulnerability in Microsoft products
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'.
local
low complexity
microsoft
7.8
2019-06-12 CVE-2019-1034 Unspecified vulnerability in Microsoft products
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'.
local
low complexity
microsoft
7.8