Word For Mac
Vendor:
First CVE: Jan 13, 2016 · Active for 10 years
24
Total CVEs
More Total CVEs than 95% of tracked products
12.0
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 60% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Word For Mac over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 13, 2016
10 years ago
Most Recent CVE
Jun 15, 2017
3,326 days ago
CVE Severity & Scoring
Word For Mac24 CVEs
8%
92%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local22 (91.7%)
Network2 (8.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low24 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None0 (0.0%)
Unknown0 (0.0%)
Required24 (100.0%)
Privileges Required
Low1 (4.2%)
High0 (0.0%)
None23 (95.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-3357HIGH Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Word for Mac 2011, Word 2016 for Mac, Word Viewer, Word Automation Services on SharePo | Sep 14, 2016 | 7.8 | 66 | NO | YES |
CVE-2016-3313HIGH Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016, Word 2016 for Mac, and Word Viewer allow remote attackers to execute arbitrary code via a crafted file, aka "M | Aug 9, 2016 | 7.8 | 65 | NO | YES |
CVE-2016-3316HIGH Microsoft Word 2013 SP1, 2013 RT SP1, 2016, and 2016 for Mac allow remote attackers to execute arbitrary code via a crafted file, aka "Microsoft Office Memory Corruption Vulnerabil | Aug 9, 2016 | 7.8 | 62 | NO | YES |
CVE-2016-0122HIGH Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Word 2016 for Mac, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers t | Apr 12, 2016 | 7.8 | 58 | NO | YES |
CVE-2016-3282HIGH Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewe | Jul 13, 2016 | 7.8 | 38 | NO | NO |
CVE-2016-3317HIGH Microsoft Office 2010 SP2, Word 2007 SP3, Word 2010 SP2, Word for Mac 2011, Word 2016 for Mac, and Word Viewer allow remote attackers to execute arbitrary code via a crafted file, | Aug 9, 2016 | 7.8 | 37 | NO | NO |
CVE-2016-7290HIGH Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word for Mac 2011, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Ap | Dec 20, 2016 | 7.1 | 35 | NO | NO |
CVE-2016-0134HIGH Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewe | Mar 9, 2016 | 7.8 | 35 | NO | NO |
CVE-2017-8509HIGH A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". Thi | Jun 15, 2017 | 8.8 | 34 | NO | NO |
CVE-2016-3281HIGH Microsoft Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Word Automation Services on SharePoint Server 2010 SP2, | Jul 13, 2016 | 7.8 | 34 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (24 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
16.7% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (24 CVEs).
Media Mentions
Signals from CVEs in this product scope (24 CVEs).
Top CNAs Publishing CVEs For Word For Mac
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2016 | 15 | 7.8 | 28.2% | 0 | 4 |
| 2011 | 20 | 7.5 | 23.6% | 0 | 1 |