Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
124 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 20% | — | Microsoft WordMicrosoft Word Viewer | 11/9/2013 | 16/6/2026 | Microsoft Word 2003 SP3 and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability." | |
| Modificada | Alta (9.3) | 20% | — | Microsoft Office Compatibility PackMicrosoft WordMicrosoft Word Viewer | 11/9/2013 | 16/6/2026 | Microsoft Word 2003 SP3 and 2007 SP3, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability." | |
| Modificada | Alta (9.3) | 20% | — | Microsoft Office Compatibility PackMicrosoft WordMicrosoft Word Viewer | 11/9/2013 | 16/6/2026 | Microsoft Word 2003 SP3, 2007 SP3, and 2010 SP1; Office Compatibility Pack SP3; and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability." | |
| Modificada | Alta (9.3) | 20% | — | Microsoft Office Compatibility PackMicrosoft WordMicrosoft Word Viewer | 11/9/2013 | 16/6/2026 | Microsoft Office 2003 SP3 and 2007 SP3, Word 2003 SP3 and 2007 SP3, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability." | |
| Modificada | Alta (9.3) | 20% | — | Microsoft Office Compatibility PackMicrosoft WordMicrosoft Word Viewer | 11/9/2013 | 16/6/2026 | Microsoft Word 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability." | |
| Modificada | Alta (9.3) | 21% | — | Microsoft Office Compatibility PackMicrosoft WordMicrosoft Word ViewerMicrosoft Sharepoint Server+1 | 11/9/2013 | 16/6/2026 | Microsoft Word Automation Services in SharePoint Server 2010 SP1, Word Web App 2010 SP1 in Office Web Apps 2010, Word 2003 SP3, Word 2007 SP3, Word 2010 SP1, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted… | |
| Modificada | Alta (9.3) | 21% | — | Microsoft Office WEB AppsMicrosoft Office Compatibility PackMicrosoft WordMicrosoft Word Viewer+1 | 11/9/2013 | 16/6/2026 | Microsoft Word Automation Services in SharePoint Server 2010 SP1, Word Web App 2010 SP1 in Office Web Apps 2010, Word 2003 SP3, Word 2007 SP3, Word 2010 SP1, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted… | |
| Modificada | Alta (9.3) | 21% | — | Microsoft Sharepoint FoundationMicrosoft Sharepoint Portal ServerMicrosoft Sharepoint ServerMicrosoft Sharepoint Services+4 | 11/9/2013 | 16/6/2026 | Microsoft Word Automation Services in SharePoint Server 2010 SP1, Word Web App 2010 SP1 in Office Web Apps 2010, Word 2003 SP3, Word 2007 SP3, Word 2010 SP1, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted… | |
| Modificada | Media (5) | 23% | — | Microsoft OfficeMicrosoft WordMicrosoft Word Viewer | 11/9/2013 | 16/6/2026 | Microsoft Office 2003 SP3 and 2007 SP3, Word 2003 SP3 and 2007 SP3, and Word Viewer allow remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka "XML External Entities Resolution… | |
| Modificada | Alta (9.3) | 21% | — | Microsoft WordMicrosoft Word Viewer | 15/5/2013 | 16/6/2026 | Microsoft Word 2003 SP3 and Word Viewer allow remote attackers to execute arbitrary code via crafted shape data in a Word document, aka "Word Shape Corruption Vulnerability." | |
| Modificada | Alta (9.3) | 32% | 💥 PoC | Microsoft XML Core ServicesMicrosoft Windows 7Microsoft Windows 8Microsoft Windows Server 2003+11 | 9/1/2013 | 16/6/2026 | Microsoft XML Core Services (aka MSXML) 4.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML XSLT Vulnerability." | |
| Modificada | Alta (8.8) | 28% | — | Microsoft XML Core ServicesMicrosoft Windows 7Microsoft Windows 8Microsoft Windows Server 2003+11 | 9/1/2013 | 16/6/2026 | Microsoft XML Core Services (aka MSXML) 3.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML Integer Truncation Vulnerability." | |
| Analizada | Alta (7.8) | 53% | ⚠ Explotación activa | Microsoft Office Compatibility PackMicrosoft Office WEB AppsMicrosoft Office Word ViewerMicrosoft Sharepoint Server+1 | 12/12/2012 | 16/6/2026 | Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office Web Apps 2010 SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, aka "Word RTF 'listoverridecount' Remote Code Execution… | |
| Modificada | Alta (9.3) | 22% | — | Microsoft Word Automation ServicesMicrosoft Office Compatibility PackMicrosoft Office WEB AppsMicrosoft Word+1 | 9/10/2012 | 16/6/2026 | Use-after-free vulnerability in Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; Word Automation Services on Microsoft SharePoint Server 2010; and Office Web Apps 2010 SP1 allows remote attackers to execute arbitrary code via a crafted RTF document, aka "RTF… | |
| Modificada | Alta (9.3) | 19% | — | Microsoft OfficeMicrosoft WordMicrosoft Word Viewer | 13/10/2010 | 16/6/2026 | Microsoft Word 2002 SP3 and 2003 SP3, Office 2004 for Mac, and Word Viewer do not properly handle a malformed record during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Parsing Vulnerability." | |
| Modificada | Alta (9.3) | 24% | — | Microsoft OfficeMicrosoft Office Compatibility PackMicrosoft Office WEB AppsMicrosoft Open XML File Format Converter+3 | 13/10/2010 | 16/6/2026 | Stack-based buffer overflow in Microsoft Word 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; Word Viewer; Office Web Apps; and Word Web App allows remote attackers to execute… | |
| Modificada | Alta (9.3) | 19% | — | Microsoft WordMicrosoft Office Word Viewer | 11/8/2010 | 16/6/2026 | Microsoft Office Word 2002 SP3 and 2003 SP3, and Office Word Viewer, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed record in a Word file, aka "Word HTML Linked Objects Memory Corruption Vulnerability." | |
| Modificada | Alta (9.3) | 23% | — | Microsoft WordMicrosoft OfficeMicrosoft Open XML File Format ConverterMicrosoft Office Compatibility Pack+1 | 11/8/2010 | 16/6/2026 | Buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2; Microsoft Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Word Viewer; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 allows remote attackers to execute arbitrary code via… | |
| Modificada | Alta (9.3) | 19% | — | Microsoft WordMicrosoft OfficeMicrosoft Open XML File Format ConverterMicrosoft Office Compatibility Pack+1 | 11/8/2010 | 16/6/2026 | Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2; Microsoft Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Word Viewer; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 do not properly handle unspecified properties in rich text data, which allows… | |
| Modificada | Alta (9.3) | 40% | 💥 Exploit | Microsoft WordMicrosoft OfficeMicrosoft Open XML File Format ConverterMicrosoft Office Compatibility Pack+2 | 11/8/2010 | 16/6/2026 | Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2; Microsoft Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Word Viewer; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; and Works 9 do not properly handle malformed records in a Word file, which allows… | |
| Modificada | Alta (9.3) | 36% | — | Microsoft OfficeMicrosoft Office WordMicrosoft Office Word ViewerMicrosoft Open XML File Format Converter | 11/11/2009 | 16/6/2026 | Stack-based buffer overflow in Microsoft Office Word 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, Open XML File Format Converter for Mac, Office Word Viewer 2003 SP3, and Office Word Viewer allow remote attackers to execute arbitrary code via a Word document with a malformed File Information Block (FIB)… | |
| Modificada | Alta (9.3) | 23% | — | Microsoft Windows 2003 ServerMicrosoft Windows Server 2008Microsoft Windows VistaMicrosoft Windows XP+22 | 14/10/2009 | 16/6/2026 | Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office… | |
| Modificada | Alta (9.3) | 20% | — | Microsoft Windows 2003 ServerMicrosoft Windows Server 2008Microsoft Windows VistaMicrosoft Windows XP+22 | 14/10/2009 | 16/6/2026 | GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "Memory Corruption Vulnerability." | |
| Modificada | Alta (9.3) | 21% | — | Microsoft Windows 2003 ServerMicrosoft Windows Server 2008Microsoft Windows VistaMicrosoft Windows XP+22 | 14/10/2009 | 16/6/2026 | Multiple integer overflows in unspecified APIs in GDI+ in Microsoft .NET Framework 1.1 SP1, .NET Framework 2.0 SP1 and SP2, Windows XP SP2 and SP3, Windows Server 2003 SP2, Vista Gold and SP1, Server 2008 Gold, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio… | |
| Modificada | Alta (9.3) | 22% | — | Microsoft Windows 2003 ServerMicrosoft Windows Server 2008Microsoft Windows VistaMicrosoft Windows XP+22 | 14/10/2009 | 16/6/2026 | GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer,… |