Works

Vendor:

First CVE: May 11, 2000 · Active for 26 years

59
Total CVEs
More Total CVEs than 98% of tracked products
5.9
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
8.8
Avg CVSS
Higher Avg CVSS than 78% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Works over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 11, 2000
26 years ago
Most Recent CVE
Oct 9, 2012
5,036 days ago

CVE Severity & Scoring

Works59 CVEs
All CVEs352,294 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network1 (1.7%)
Unknown58 (98.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High1 (1.7%)
Unknown58 (98.3%)
User Interaction
None1 (1.7%)
Unknown58 (98.3%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (1.7%)
Unknown58 (98.3%)

Top CVEs

Signals from CVEs in this product scope (59 CVEs).

59 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and 2007, allows remote attackers to execute arbitrary code or
Apr 21, 20089.372NOYES
gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3,
Sep 11, 20089.362NOYES
Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and
Sep 11, 20089.362NOYES
Stack-based buffer overflow in wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to exe
Feb 12, 20089.362NOYES
Heap-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via a BIFF
Jan 9, 20079.361NOYES
Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2; Microsoft Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Word Viewer; Office Compatibility Pac
Aug 11, 20109.359NOYES
Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafte
Feb 12, 20089.359NOYES
Unspecified vulnerability in Microsoft Word 2000, 2002, and Word Viewer 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted DOC file that triggers me
Dec 14, 20069.355NOYES
wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file wit
Feb 12, 20089.354NOYES
Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of service on Word 2003, via unknown at
Jan 26, 20079.354NOYES

Exploit Exposure

Signals from CVEs in this product scope (59 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.7% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
11 CVEs
18.6% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (59 CVEs).

Media Mentions

Signals from CVEs in this product scope (59 CVEs).

Top CNAs Publishing CVEs For Works

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.079.329.7%01
8.5109.225.7%00
8.0238.735.2%06
7.019.352.0%01
200698.630.7%02
2005178.934.1%06
2004188.531.1%03
200367.122.1%00
200267.122.1%00
200157.021.1%00
200026.317.6%00