Office Compatibility Pack

Vendor:

First CVE: Aug 14, 2007 · Active for 18 years

210
Total CVEs
More Total CVEs than 99% of tracked products
16.2
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
8.4
Avg CVSS
Higher Avg CVSS than 75% of tracked products
6.7%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Office Compatibility Pack over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 14, 2007
18 years ago
Most Recent CVE
Mar 5, 2019
2,698 days ago

CVE Severity & Scoring

Office Compatibility Pack210 CVEs
All CVEs352,231 CVEs
MediumHigh
Attack Vector
Local84 (40.0%)
Network22 (10.5%)
Unknown104 (49.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low104 (49.5%)
High2 (1.0%)
Unknown104 (49.5%)
User Interaction
None2 (1.0%)
Unknown104 (49.5%)
Required104 (49.5%)
Privileges Required
Low3 (1.4%)
High0 (0.0%)
None103 (49.0%)
Unknown104 (49.5%)

Top CVEs

Signals from CVEs in this product scope (210 CVEs).

210 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Lync 2010, 2010 Attendee, 2013, and Bas
Nov 6, 20137.897YESYES
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (me
Jun 13, 20128.897YESYES
Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation Services on SharePoint Serv
Mar 25, 20147.896YESYES
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way object
Jan 10, 20188.895YESNO
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects
Jan 10, 20187.894YESNO
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint S
Apr 14, 20157.894YESNO
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 201
Oct 13, 20177.892YESNO
Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File Format Converter for Mac; Micro
Jun 10, 20097.889YESNO
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow user-assisted remote attackers to exe
Dec 20, 20167.887YESNO
Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office Web Apps 2010 SP1 allow remote attackers to execute arbitrar
Dec 12, 20127.886YESNO

Exploit Exposure

Signals from CVEs in this product scope (210 CVEs).

CISA KEV
14 CVEs
6.7% of CVEs· 97th percentile
Metasploit
3 CVEs
1.4% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
14 CVEs
6.7% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (210 CVEs).

Media Mentions

Signals from CVEs in this product scope (210 CVEs).

Top CNAs Publishing CVEs For Office Compatibility Pack

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2007459.128.5%33