Page 39 of 343 results (0.004 seconds)

CVSS: 9.3EPSS: 60%CPEs: 6EXPL: 1

Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016, Word 2016 for Mac, and Word Viewer allow remote attackers to execute arbitrary code via a crafted file, aka "Microsoft Office Memory Corruption Vulnerability." Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, 2013 RT SP1 y 2016, Word 2016 para Mac y Word Viewer permiten a atacantes remotos ejecutar código arbitrario a través de un archivo manipulado, también conocida como "Microsoft Office Memory Corruption Vulnerability". Microsoft Office Word versions 2007, 2010, 2013, and 2016 suffer from an out-of-bounds read that allows for remote code execution. This vulnerability is noted in MS16-099. • https://www.exploit-db.com/exploits/40224 http://www.securityfocus.com/bid/92289 http://www.securitytracker.com/id/1036559 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-099 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 9.3EPSS: 72%CPEs: 4EXPL: 0

Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allow remote attackers to execute arbitrary code via a crafted file, aka "Graphics Component Memory Corruption Vulnerability." Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1 y 2013 RT SP1 permiten a atacantes remotos ejecutar código arbitrario a través de un archivo manipulado, también conocida como "Graphics Component Memory Corruption Vulnerability". This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Office Word. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of a JPEG embedded within an RTF file. The issue lies in the failure to properly validate user-supplied data which can result in a write past the end of an allocated buffer. • http://www.securityfocus.com/bid/92308 http://www.securitytracker.com/id/1036559 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-099 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 9.3EPSS: 4%CPEs: 15EXPL: 0

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Office 2016, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, Office Web Apps Server 2013 SP1, and Office Online Server allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability." Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Office 2016, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, Office Web Apps Server 2013 SP1 y Office Online Server permiten a atacantes remotos ejecutar código arbitrario a través de un documento de Office manipulado, también conocida como "Microsoft Office Memory Corruption Vulnerability". • http://www.securitytracker.com/id/1036093 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-070 • CWE-20: Improper Input Validation •

CVSS: 9.3EPSS: 70%CPEs: 2EXPL: 0

Microsoft Office 2013 SP1, 2013 RT SP1, and 2016 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability." Microsoft Office 2013 SP1, 2013 RT SP1 y 2016 permite a atacantes remotos ejecutar código arbitrario a través de un documento Office manipulado, también conocido como "Microsoft Office Memory Corruption Vulnerability". • http://www.securityfocus.com/bid/89938 http://www.securitytracker.com/id/1035819 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-054 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 7.8EPSS: 0%CPEs: 4EXPL: 0

Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2016 does not properly sign an unspecified binary file, which allows local users to gain privileges via a Trojan horse file with a crafted signature, aka "Microsoft Office Security Feature Bypass Vulnerability." Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1 y 2016 no firma adecuadamente un archivo binario no especificado, lo que permite a usuarios locales obtener privilegios a través de un archivo Troyano con una firma manipulada, también conocido como "Microsoft Office Security Feature Bypass Vulnerability". • http://www.securityfocus.com/bid/84030 http://www.securitytracker.com/id/1035207 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-029 • CWE-264: Permissions, Privileges, and Access Controls •