← All CVEs

CVE-2014-0260

high · 9.3

Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Office Compatibility Pack SP3; Word Viewer; SharePoint Server 2010 SP1 and SP2 and 2013; Office Web Apps 2010 SP1 and SP2; and Office Web Apps Server 2013 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability."

9.3
CVSS
15.4%
EPSS (exploit prob.)
97th
EPSS percentile
2014-01-15
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
microsoftoffice_compatibility_packall versions
microsoftoffice_web_apps2010
microsoftoffice_web_apps2010
microsoftoffice_web_apps_server2013
microsoftsharepoint_server2010
microsoftsharepoint_server2010
microsoftsharepoint_server2013
microsoftword2003
microsoftword2007
microsoftword2010
microsoftword2010
microsoftword2013
microsoftword_viewerall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-0260