Known vulnerabilities in Office Online Server 2016

Vendor: Microsoft
Version: 2016
Software CPE: cpe:2.3:a:microsoft:office_online_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 81
Public exploits: 5
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Office Online Server version 2016 Office Online Server 2016 is affected by 81 vulnerabilities: 60 high, 9 medium, 12 low Critical High Medium Low

Vulnerabilities (81)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU60420 - Exposure of sensitive information to an unauthorized actor
CVE-2022-22716
CWE-200 Low
No
No
- 08.02.2022 SB2022020841
#VU59476 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-21840
CWE-94 High
No
No
- 11.01.2022 SB2022011159
#VU58907 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-43256
CWE-94 High
No
No
- 14.12.2021 SB2021121447
#VU58070 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-40442
CWE-94 High
No
No
- 09.11.2021 SB2021110941
#VU57267 - Exposure of sensitive information to an unauthorized actor
CVE-2021-40472
CWE-200 Low
No
No
- 12.10.2021 SB2021101217
#VU57264 - Use After Free
CVE-2021-40474
CWE-416 High
Public exploit available
No
- 12.10.2021 SB2021101217
#VU57262 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-40485
CWE-94 High
No
No
- 12.10.2021 SB2021101217
#VU57261 - Use After Free
CVE-2021-40486
CWE-416 High
No
No
- 12.10.2021 SB2021101216
#VU56573 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-38655
CWE-94 High
No
No
- 14.09.2021 SB2021091443
#VU54804 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-34501
CWE-94 High
No
No
- 13.07.2021 SB2021071359
#VU54773 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2021-34451
CWE-451 Low
No
No
- 13.07.2021 SB2021071348
#VU53912 - Use After Free
CVE-2021-31939
CWE-416 High
Public exploit available
No
- 08.06.2021 SB2021060831
#VU53112 - Out-of-bounds read
CVE-2021-31174
CWE-125 Low
Public exploit available
No
- 11.05.2021 SB2021051131
#VU53073 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-31179
CWE-94 High
Public exploit available
No
- 11.05.2021 SB2021051110
#VU53072 - Out-of-bounds read
CVE-2021-31178
CWE-125 Medium
Public exploit available
No
- 11.05.2021 SB2021051110
#VU53071 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-31177
CWE-94 High
No
No
- 11.05.2021 SB2021051110
#VU53069 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-31175
CWE-94 High
No
No
- 11.05.2021 SB2021051110
#VU52143 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-28453
CWE-94 High
No
No
- 13.04.2021 SB2021041329
#VU52111 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-28451
CWE-94 High
No
No
- 13.04.2021 SB2021041314
#VU52110 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-28454
CWE-94 High
No
No
- 13.04.2021 SB2021041314


Showing elements 1 - 20 out of 81