Vulnerabilities > Microsoft > Visio > Critical

DATE CVE VULNERABILITY TITLE RISK
2016-09-14 CVE-2016-3364 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Microsoft Visio 2016
Microsoft Visio 2016 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."
network
microsoft CWE-119
critical
9.3
2015-11-11 CVE-2015-2503 Permissions, Privileges, and Access Controls vulnerability in Microsoft products
Microsoft Access 2007 SP3, Excel 2007 SP3, InfoPath 2007 SP3, OneNote 2007 SP3, PowerPoint 2007 SP3, Project 2007 SP3, Publisher 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Office 2007 IME (Japanese) SP3, Access 2010 SP2, Excel 2010 SP2, InfoPath 2010 SP2, OneNote 2010 SP2, PowerPoint 2010 SP2, Project 2010 SP2, Publisher 2010 SP2, Visio 2010 SP2, Word 2010 SP2, Pinyin IME 2010, Access 2013 SP1, Excel 2013 SP1, InfoPath 2013 SP1, OneNote 2013 SP1, PowerPoint 2013 SP1, Project 2013 SP1, Publisher 2013 SP1, Visio 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, OneNote 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Access 2016, Excel 2016, OneNote 2016, PowerPoint 2016, Project 2016, Publisher 2016, Visio 2016, Word 2016, Skype for Business 2016, and Lync 2013 SP1 allow remote attackers to bypass a sandbox protection mechanism and gain privileges via a crafted web site that is accessed with Internet Explorer, as demonstrated by a transition from Low Integrity to Medium Integrity, aka "Microsoft Office Elevation of Privilege Vulnerability."
network
microsoft CWE-264
critical
9.3
2015-10-14 CVE-2015-2557 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Microsoft Visio 2007/2010
Buffer overflow in Microsoft Visio 2007 SP3 and 2010 SP2 allows remote attackers to execute arbitrary code via crafted UML data in an Office document, aka "Microsoft Office Memory Corruption Vulnerability."
network
microsoft CWE-119
critical
9.3
2013-03-13 CVE-2013-0079 Remote Code Execution vulnerability in Microsoft Office Filter Pack, Visio and Visio Viewer
Microsoft Visio Viewer 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Visio file that triggers incorrect memory allocation, aka "Visio Viewer Tree Object Type Confusion Vulnerability."
network
microsoft
critical
9.3
2012-08-15 CVE-2012-1888 Buffer Errors vulnerability in Microsoft Visio and Visio Viewer
Buffer overflow in Microsoft Visio 2010 SP1 and Visio Viewer 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Visio file, aka "Visio DXF File Format Buffer Overflow Vulnerability."
network
microsoft CWE-119
critical
9.3
2011-08-10 CVE-2011-1972 Improper Input Validation vulnerability in Microsoft Visio 2003/2007/2010
Microsoft Visio 2003 SP3, 2007 SP2, and 2010 Gold and SP1 does not properly validate objects in memory during Visio file parsing, which allows remote attackers to execute arbitrary code via a crafted file, aka "pStream Release RCE Vulnerability."
network
microsoft CWE-20
critical
9.3
2011-08-10 CVE-2011-1979 Improper Input Validation vulnerability in Microsoft Visio 2003/2007
Microsoft Visio 2003 SP3 and 2007 SP2 does not properly validate objects in memory during Visio file parsing, which allows remote attackers to execute arbitrary code via a crafted file, aka "Move Around the Block RCE Vulnerability."
network
microsoft CWE-20
critical
9.3
2011-02-10 CVE-2011-0092 Code Injection vulnerability in Microsoft Visio 2002/2003/2007
The LZW stream decompression functionality in ORMELEMS.DLL in Microsoft Visio 2002 SP2, 2003 SP3, and 2007 SP2 allows remote attackers to execute arbitrary code via a Visio file with a malformed VisioDocument stream that triggers an exception handler that accesses an object that has not been fully initialized, which triggers memory corruption, aka "Visio Object Memory Corruption Vulnerability."
network
microsoft CWE-94
critical
9.3
2011-02-10 CVE-2011-0093 Code Injection vulnerability in Microsoft Visio 2002/2003/2007
ELEMENTS.DLL in Microsoft Visio 2002 SP2, 2003 SP3, and 2007 SP2 does not properly parse structures during the opening of a Visio file, which allows remote attackers to execute arbitrary code via a file containing a malformed structure, aka "Visio Data Type Memory Corruption Vulnerability."
network
microsoft CWE-94
critical
9.3
2010-08-27 CVE-2010-3148 Unspecified vulnerability in Microsoft Visio 2003
Untrusted search path vulnerability in Microsoft Visio 2003 SP3 allows local users to gain privileges via a Trojan horse mfc71enu.dll file in the current working directory, as demonstrated by a directory that contains a .vsd, .vdx, .vst, or .vtx file, aka "Microsoft Visio Insecure Library Loading Vulnerability."
network
microsoft
critical
9.3