Word Viewer
Vendor:
First CVE: Oct 10, 2006 · Active for 19 years
88
Total CVEs
More Total CVEs than 99% of tracked products
6.8
Avg CVEs / Year
Higher CVE frequency than 92% of tracked products
8.5
Avg CVSS
Higher Avg CVSS than 75% of tracked products
5.7%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Word Viewer over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 10, 2006
19 years ago
Most Recent CVE
Mar 5, 2019
2,699 days ago
CVE Severity & Scoring
Word Viewer88 CVEs
9%
90%
All CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local32 (36.4%)
Network7 (8.0%)
Unknown49 (55.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low38 (43.2%)
High1 (1.1%)
Unknown49 (55.7%)
User Interaction
None2 (2.3%)
Unknown49 (55.7%)
Required37 (42.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None39 (44.3%)
Unknown49 (55.7%)
Top CVEs
Signals from CVEs in this product scope (88 CVEs).
88 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-3906HIGH GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Lync 2010, 2010 Attendee, 2013, and Bas | Nov 6, 2013 | 7.8 | 97 | YES | YES |
CVE-2014-1761HIGH Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation Services on SharePoint Serv | Mar 25, 2014 | 7.8 | 96 | YES | YES |
CVE-2007-0671HIGH Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code v | Feb 3, 2007 | 8.8 | 84 | YES | NO |
CVE-2016-7193HIGH Microsoft Word 2007 SP2, Office 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automat | Oct 14, 2016 | 7.8 | 83 | YES | NO |
CVE-2015-2424HIGH Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow remote attackers to execute a | Jul 14, 2015 | 8.8 | 82 | YES | NO |
CVE-2016-3357HIGH Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Word for Mac 2011, Word 2016 for Mac, Word Viewer, Word Automation Services on SharePo | Sep 14, 2016 | 7.8 | 66 | NO | YES |
CVE-2007-2223HIGH Microsoft XML Core Services (MSXML) 3.0 through 6.0 allows remote attackers to execute arbitrary code via the substringData method on a (1) TextNode or (2) XMLDOM object, which cau | Aug 14, 2007 | 9.3 | 66 | NO | YES |
CVE-2016-3313HIGH Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016, Word 2016 for Mac, and Word Viewer allow remote attackers to execute arbitrary code via a crafted file, aka "M | Aug 9, 2016 | 7.8 | 65 | NO | YES |
CVE-2016-3304HIGH The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007 SP3, Office 2010 SP2, Word Viewer, Skype for Business 2016, | Aug 9, 2016 | 7.8 | 65 | NO | YES |
CVE-2016-3303HIGH The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007 SP3, Office 2010 SP2, Word Viewer, Skype for Business 2016, | Aug 9, 2016 | 7.8 | 65 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (88 CVEs).
CISA KEV
5 CVEs
5.7% of CVEs· 97th percentile
Metasploit
2 CVEs
2.3% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
17 CVEs
19.3% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (88 CVEs).
Media Mentions
Signals from CVEs in this product scope (88 CVEs).
Top CNAs Publishing CVEs For Word Viewer
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2003 | 17 | 9.1 | 27.6% | 1 | 2 |