Vulnerabilities > Microsoft > Visio > 2016

DATE CVE VULNERABILITY TITLE RISK
2024-02-13 CVE-2024-20673 Unspecified vulnerability in Microsoft products
Microsoft Office Remote Code Execution Vulnerability
local
low complexity
microsoft
7.8
2023-01-10 CVE-2023-21736 Unspecified vulnerability in Microsoft products
Microsoft Office Visio Remote Code Execution Vulnerability
local
low complexity
microsoft
7.8
2023-01-10 CVE-2023-21737 Unspecified vulnerability in Microsoft products
Microsoft Office Visio Remote Code Execution Vulnerability
local
low complexity
microsoft
7.8
2023-01-10 CVE-2023-21741 Unspecified vulnerability in Microsoft products
Microsoft Office Visio Information Disclosure Vulnerability
network
low complexity
microsoft
7.1
2022-12-13 CVE-2022-44695 Unspecified vulnerability in Microsoft 365 Apps, Office and Visio
Microsoft Office Visio Remote Code Execution Vulnerability
local
low complexity
microsoft
7.8
2021-03-11 CVE-2021-27055 Unspecified vulnerability in Microsoft 365 Apps, Office and Visio
Microsoft Visio Security Feature Bypass Vulnerability
local
high complexity
microsoft
7.0
2020-04-15 CVE-2020-0760 Improper Input Validation vulnerability in Microsoft products
A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries, aka 'Microsoft Office Remote Code Execution Vulnerability'.
network
microsoft CWE-20
6.8
2016-09-14 CVE-2016-3364 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Microsoft Visio 2016
Microsoft Visio 2016 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."
network
microsoft CWE-119
critical
9.3
2016-06-16 CVE-2016-3235 Permissions, Privileges, and Access Controls vulnerability in Microsoft Visio and Visio Viewer
Microsoft Visio 2007 SP3, Visio 2010 SP2, Visio 2013 SP1, Visio 2016, Visio Viewer 2007 SP3, and Visio Viewer 2010 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Microsoft Office OLE DLL Side Loading Vulnerability."
network
microsoft CWE-264
critical
9.3
2016-01-13 CVE-2016-0012 Information Exposure vulnerability in Microsoft products
Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Visio 2010 SP2, Word 2010 SP2, Office 2013 SP1, Excel 2013 SP1, PowerPoint 2013 SP1, Visio 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Office 2016, Excel 2016, PowerPoint 2016, Visio 2016, Word 2016, and Visual Basic 6.0 Runtime allow remote attackers to bypass the ASLR protection mechanism via unspecified vectors, aka "Microsoft Office ASLR Bypass."
network
microsoft CWE-200
4.3