Known vulnerabilities in Office Online Server - page 6
Vendor:
Microsoft
Software:
Office Online Server
Software CPE:
cpe:2.3:a:microsoft:office_online_server:*:*:*:*:*:*:*:*
Website:
https://www.microsoft.com
Total vulnerabilities:
218
Public exploits:
7
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
16.0.10417.20175
16.0.10417.20137
16.0.10417.20128
16.0.10417.20113
16.0.10417.20102
16.0.10417.20097
16.0.10417.20083
16.0.10417.20075
16.0.10417.20068
16.0.10417.20059
16.0.10417.20047
16.0.10417.20034
16.0.10417.20027
16.0.10417.20018
16.0.10417.20010
16.0.10417.20003
16.0.10416.20073
16.0.10416.20047
16.0.10416.20058
16.0.10402.20000
2016
1.0
Vulnerabilities (218)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU107211 - Integer overflow CVE-2025-26642 |
CWE-190 | High | - | 08.04.2025 | - | ||
| #VU105550 - Use After Free CVE-2025-24082 |
CWE-416 | High | - | 11.03.2025 | - | ||
| #VU105549 - Stack-based buffer overflow CVE-2025-24075 |
CWE-121 | High | - | 11.03.2025 | - | ||
| #VU105547 - Use After Free CVE-2025-24081 |
CWE-416 | High | - | 11.03.2025 | - | ||
| #VU103811 - Use After Free CVE-2025-21387 |
CWE-416 | High | - | 11.02.2025 | - | ||
| #VU103810 - Heap-based Buffer Overflow CVE-2025-21390 |
CWE-122 | High | - | 11.02.2025 | - | ||
| #VU103808 - Use After Free CVE-2025-21394 |
CWE-416 | High | - | 11.02.2025 | - | ||
| #VU103807 - Untrusted Pointer Dereference CVE-2025-21381 |
CWE-822 | High | - | 11.02.2025 | - | ||
| #VU103806 - Use After Free CVE-2025-21386 |
CWE-416 | High | - | 11.02.2025 | - | ||
| #VU102798 - Untrusted Pointer Dereference CVE-2025-21354 |
CWE-822 | High | - | 15.01.2025 | - | ||
| #VU102797 - Use After Free CVE-2025-21362 |
CWE-416 | High | - | 15.01.2025 | - | ||
| #VU100322 - Command injection CVE-2024-49026 |
CWE-77 | High | - | 12.11.2024 | - | ||
| #VU97097 - Use After Free CVE-2024-43465 |
CWE-416 | High | - | 10.09.2024 | - | ||
| #VU89487 - Deserialization of Untrusted Data CVE-2024-30042 |
CWE-502 | High | - | 14.05.2024 | - | ||
| #VU80726 - Exposure of sensitive information to an unauthorized actor CVE-2023-36766 |
CWE-200 | Medium | 16.0.10402.20000 | 13.09.2023 |
SB2023091319 |
||
| #VU79179 - Improper input validation CVE-2023-36896 |
CWE-20 | High | - | 08.08.2023 | - | ||
| #VU79174 - Improper input validation CVE-2023-35371 |
CWE-20 | High | - | 08.08.2023 | - | ||
| #VU78180 - Exposure of sensitive information to an unauthorized actor CVE-2023-33162 |
CWE-200 | Medium | - | 12.07.2023 | - | ||
| #VU77264 - Improper input validation CVE-2023-33137 |
CWE-20 | High | - | 13.06.2023 | - | ||
| #VU77260 - Improper input validation CVE-2023-33133 |
CWE-20 | High | - | 13.06.2023 | - |
Showing elements 101 - 120 out of 218