Word Viewer

Vendor:

First CVE: Oct 10, 2006 · Active for 19 years

88
Total CVEs
More Total CVEs than 99% of tracked products
6.8
Avg CVEs / Year
Higher CVE frequency than 92% of tracked products
8.5
Avg CVSS
Higher Avg CVSS than 75% of tracked products
5.7%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Word Viewer over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 10, 2006
19 years ago
Most Recent CVE
Mar 5, 2019
2,699 days ago

CVE Severity & Scoring

Word Viewer88 CVEs
All CVEs352,427 CVEs
MediumHighCritical
Attack Vector
Local32 (36.4%)
Network7 (8.0%)
Unknown49 (55.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low38 (43.2%)
High1 (1.1%)
Unknown49 (55.7%)
User Interaction
None2 (2.3%)
Unknown49 (55.7%)
Required37 (42.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None39 (44.3%)
Unknown49 (55.7%)

Top CVEs

Signals from CVEs in this product scope (88 CVEs).

88 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Lync 2010, 2010 Attendee, 2013, and Bas
Nov 6, 20137.897YESYES
Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation Services on SharePoint Serv
Mar 25, 20147.896YESYES
Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code v
Feb 3, 20078.884YESNO
Microsoft Word 2007 SP2, Office 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automat
Oct 14, 20167.883YESNO
Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow remote attackers to execute a
Jul 14, 20158.882YESNO
Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Word for Mac 2011, Word 2016 for Mac, Word Viewer, Word Automation Services on SharePo
Sep 14, 20167.866NOYES
Microsoft XML Core Services (MSXML) 3.0 through 6.0 allows remote attackers to execute arbitrary code via the substringData method on a (1) TextNode or (2) XMLDOM object, which cau
Aug 14, 20079.366NOYES
Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016, Word 2016 for Mac, and Word Viewer allow remote attackers to execute arbitrary code via a crafted file, aka "M
Aug 9, 20167.865NOYES
The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007 SP3, Office 2010 SP2, Word Viewer, Skype for Business 2016,
Aug 9, 20167.865NOYES
The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007 SP3, Office 2010 SP2, Word Viewer, Skype for Business 2016,
Aug 9, 20167.865NOYES

Exploit Exposure

Signals from CVEs in this product scope (88 CVEs).

CISA KEV
5 CVEs
5.7% of CVEs· 97th percentile
Metasploit
2 CVEs
2.3% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
17 CVEs
19.3% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (88 CVEs).

Media Mentions

Signals from CVEs in this product scope (88 CVEs).

Top CNAs Publishing CVEs For Word Viewer

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2003179.127.6%12