Vulnerabilities > Microsoft > Office > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-11-14 CVE-2018-8558 Information Exposure vulnerability in Microsoft Office and Office 365 Proplus
An information disclosure vulnerability exists when Microsoft Outlook fails to respect "Default link type" settings configured via the SharePoint Online Admin Center, aka "Microsoft Outlook Information Disclosure Vulnerability." This affects Office 365 ProPlus, Microsoft Office.
network
low complexity
microsoft CWE-200
6.5
2018-11-14 CVE-2018-8546 Unspecified vulnerability in Microsoft products
A denial of service vulnerability exists in Skype for Business, aka "Microsoft Skype for Business Denial of Service Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Lync, Skype.
network
high complexity
microsoft
5.9
2018-10-10 CVE-2018-8427 Information Exposure vulnerability in Microsoft products
An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka "Microsoft Graphics Components Information Disclosure Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Office 365 ProPlus, Windows Server 2008, Microsoft PowerPoint Viewer, Microsoft Excel Viewer.
local
low complexity
microsoft CWE-200
5.5
2018-09-13 CVE-2018-8429 Information Exposure vulnerability in Microsoft products
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel.
local
low complexity
microsoft CWE-200
5.5
2018-08-15 CVE-2018-8382 Information Exposure vulnerability in Microsoft products
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel.
local
low complexity
microsoft CWE-200
5.5
2018-08-15 CVE-2018-8378 Use of Uninitialized Resource vulnerability in Microsoft products
An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory, aka "Microsoft Office Information Disclosure Vulnerability." This affects Word, Microsoft SharePoint Server, Microsoft Office Word Viewer, Microsoft Excel Viewer, Microsoft SharePoint, Microsoft Office.
local
low complexity
microsoft CWE-908
5.5
2018-06-14 CVE-2018-8246 Information Exposure vulnerability in Microsoft products
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel.
local
low complexity
microsoft CWE-200
5.5
2018-06-14 CVE-2018-8244 Improper Input Validation vulnerability in Microsoft Office, Outlook and Outlook RT
An elevation of privilege vulnerability exists when Microsoft Outlook does not validate attachment headers properly, aka "Microsoft Outlook Elevation of Privilege Vulnerability." This affects Microsoft Office, Microsoft Outlook.
network
low complexity
microsoft CWE-20
6.5
2018-05-09 CVE-2018-8163 Information Exposure vulnerability in Microsoft Excel and Office
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Office, Microsoft Excel.
local
low complexity
microsoft CWE-200
5.5
2018-05-09 CVE-2018-8160 Information Exposure vulnerability in Microsoft products
An information disclosure vulnerability exists in Outlook when a message is opened, aka "Microsoft Outlook Information Disclosure Vulnerability." This affects Word, Microsoft Office.
network
low complexity
microsoft CWE-200
6.5