365_apps_for_enterprise vulnerabilities
CVEs whose affected-version data names the 365_apps_for_enterprise package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
168 CVEsRSS
CVE-2026-81955High· 8.8Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
CVE-2026-70105Medium· 6.5Microsoft Word Information Disclosure Vulnerability
Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
CVE-2026-70329High· 8.8Microsoft Outlook Remote Code Execution Vulnerability
Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
CVE-2026-70328Medium· 6.5Microsoft Excel Information Disclosure Vulnerability
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
CVE-2026-70327Medium· 6.5Microsoft Excel Information Disclosure Vulnerability
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
CVE-2026-70325Medium· 5.5Powerpoint Information Disclosure Vulnerability
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
CVE-2026-70323Medium· 5.5Microsoft Office Information Disclosure Vulnerability
Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-70322Medium· 5.5Powerpoint Information Disclosure Vulnerability
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
CVE-2026-70320Medium· 5.5Powerpoint Information Disclosure Vulnerability
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
CVE-2026-70319Medium· 5.5Microsoft Office Word Information Disclosure Vulnerability
Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-70318Medium· 5.5Microsoft Excel Information Disclosure Vulnerability
Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-70317Medium· 5.5Microsoft Office Information Disclosure Vulnerability
Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-70316Medium· 5.5Powerpoint Information Disclosure Vulnerability
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
CVE-2026-70315Medium· 5.5Microsoft Office Information Disclosure Vulnerability
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-70314Medium· 5.5Microsoft Office Information Disclosure Vulnerability
Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-70313High· 7.8Microsoft PowerPoint Remote Code Execution Vulnerability
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
CVE-2026-70312Medium· 5.5Powerpoint Information Disclosure Vulnerability
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
CVE-2026-70311High· 7.8Microsoft Office Word Remote Code Execution Vulnerability
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-70310Medium· 5.5Microsoft Word Information Disclosure Vulnerability
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-70130High· 8.4Microsoft Office Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-65657High· 7.8Microsoft Office Remote Code Execution Vulnerability
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-65656High· 7.8Microsoft Office Remote Code Execution Vulnerability
Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-63521Medium· 5.5Microsoft Office Word Information Disclosure Vulnerability
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-63519High· 7.8Microsoft Office Graphics Component Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-63518High· 7.8Microsoft Office Word Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-63517Medium· 5.5Microsoft Office Graphics Component Information Disclosure Vulnerability
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-63515High· 7.8Microsoft Office Remote Code Execution Vulnerability
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-63513High· 7.8Microsoft Office Graphics Component Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-68810High· 7.8Microsoft Excel Remote Code Execution Vulnerability
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68808Medium· 5.5Microsoft Excel Information Disclosure Vulnerability
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.