Microsoft / Publisher
45 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-81385 | Microsoft Office Publisher Remote Code Execution Vulnerability | HIGH | 8.8 | Sep 8, 2026 |
| CVE-2026-69742 | Microsoft Office Publisher Remote Code Execution Vulnerability | HIGH | 8.8 | Sep 8, 2026 |
| CVE-2024-38226 KEV | Microsoft Publisher Security Feature Bypass Vulnerability | HIGH | 7.3 | Sep 10, 2024 |
| CVE-2024-20673 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | Feb 13, 2024 |
| CVE-2023-28295 | Microsoft Publisher Remote Code Execution Vulnerability | HIGH | 7.8 | Jun 17, 2023 |
| CVE-2023-28287 | Microsoft Publisher Remote Code Execution Vulnerability | HIGH | 7.8 | Jun 17, 2023 |
| CVE-2022-29107 | Microsoft Office Security Feature Bypass Vulnerability | MEDIUM | 5.5 | May 10, 2022 |
| CVE-2020-0760 | A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries, aka 'Microsoft Office Remote Code Execution Vulne… | HIGH | 8.8 | Apr 15, 2020 |
| CVE-2018-8245 | A remote code execution vulnerability exists when Microsoft Publisher fails to utilize features that lock down the Local Machine zone when instantiating OLE ob… | HIGH | 7.8 | Jun 14, 2018 |
| CVE-2017-8725 | A remote code execution vulnerability exists in Microsoft Publisher 2007 Service Pack 3 and Microsoft Publisher 2010 Service Pack 2 when they fail to properly… | HIGH | 7.8 | Sep 13, 2017 |
| CVE-2016-7289 | Microsoft Publisher 2010 SP2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Mi… | HIGH | 7.8 | Dec 20, 2016 |
| CVE-2015-2503 | Microsoft Access 2007 SP3, Excel 2007 SP3, InfoPath 2007 SP3, OneNote 2007 SP3, PowerPoint 2007 SP3, Project 2007 SP3, Publisher 2007 SP3, Visio 2007 SP3, Word… | HIGH | 9.3 | Nov 11, 2015 |
| CVE-2014-1759 | pubconv.dll in Microsoft Publisher 2003 SP3 and 2007 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (incorrect pointer dere… | HIGH | 9.3 | Apr 8, 2014 |
| CVE-2013-1329 | Integer signedness error in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers a buffer… | HIGH | 9.3 | May 15, 2013 |
| CVE-2013-1328 | Microsoft Publisher 2003 SP3, 2007 SP3, and 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers incorrect poi… | HIGH | 9.3 | May 15, 2013 |
| CVE-2013-1327 | Integer signedness error in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers an improp… | HIGH | 9.3 | May 15, 2013 |
| CVE-2013-1323 | Microsoft Publisher 2003 SP3 does not properly handle NULL values for unspecified data items, which allows remote attackers to execute arbitrary code via a cra… | HIGH | 9.3 | May 15, 2013 |
| CVE-2013-1322 | Microsoft Publisher 2003 SP3 does not properly check table range data, which allows remote attackers to execute arbitrary code via a crafted Publisher file, ak… | HIGH | 10.0 | May 15, 2013 |
| CVE-2013-1321 | Microsoft Publisher 2003 SP3 does not properly check the data type of an unspecified return value, which allows remote attackers to execute arbitrary code via… | HIGH | 9.3 | May 15, 2013 |
| CVE-2013-1320 | Buffer overflow in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Buffer Overflow… | HIGH | 10.0 | May 15, 2013 |
| CVE-2013-1319 | Microsoft Publisher 2003 SP3 does not properly check the return value of an unspecified method, which allows remote attackers to execute arbitrary code via a c… | HIGH | 10.0 | May 15, 2013 |
| CVE-2013-1318 | Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers access to an invalid pointer, aka "Pu… | HIGH | 10.0 | May 15, 2013 |
| CVE-2013-1317 | Integer overflow in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers an improper alloc… | HIGH | 9.3 | May 15, 2013 |
| CVE-2013-1316 | Microsoft Publisher 2003 SP3 does not properly validate the size of an unspecified array, which allows remote attackers to execute arbitrary code via a crafted… | HIGH | 9.3 | May 15, 2013 |
| CVE-2011-3412 | Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, allows remote attackers to execute arbitrary code via a crafted Publisher file that leverages incorrect mem… | HIGH | 9.3 | Dec 14, 2011 |
Showing 1 to 25 of 45 CVEs