← Vulnerability feed

Vulnerability record · CVE-2015-6123 · published 11 November 2015

CVE-2015-6123: Microsoft excel for mac cross-site scripting vulnerability

Microsoft · Excel For Mac

Cross-site scripting (XSS) vulnerability in Microsoft Excel for Mac 2011 and Excel 2016 for Mac allows remote attackers to inject arbitrary web script or HTML via a crafted e-mail message that is mishandled by Outlook for Mac, aka "Microsoft Outlook for Mac Spoofing Vulnerability."

4.3 CVSS 2.0 Medium EPSS 11% · top 4.2% CWE-79 · Cross-site scripting
4.3CVSS 2.0 base score
11%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in Microsoft Excel for Mac 2011 and Excel 2016 for Mac allows remote attackers to inject arbitrary web script or HTML via a crafted e-mail message that is mishandled by Outlook for Mac, aka "Microsoft Outlook for Mac Spoofing Vulnerability."

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-6123 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2015-6122Microsoft excel memory buffer overflow vulnerabilityMicrosoft Excel 2007 SP3, Excel 2010 SP2, Excel for Mac 2011, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbit…EPSS 14%9.3CVE-2015-6040Microsoft excel memory buffer overflow vulnerabilityMicrosoft Excel 2007 SP3, Excel 2010 SP2, Excel for Mac 2011, Excel 2016 for Mac, Office Compatibility Pack SP3, and Excel Viewer allow remote attack…EPSS 14%9.3CVE-2015-6094Microsoft excel memory buffer overflow vulnerabilityMicrosoft Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, and Excel Services on SharePoint Ser…EPSS 21%9.3CVE-2015-6038Microsoft excel memory buffer overflow vulnerabilityMicrosoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, Office Compatibility…EPSS 36%9.3CVE-2015-2558Microsoft excel vulnerabilityUse-after-free vulnerability in Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 20…EPSS 20%9.3CVE-2015-2555Microsoft excel vulnerabilityUse-after-free vulnerability in Microsoft Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, and …EPSS 20%7.8CVE-2017-8567Microsoft excel for mac memory buffer overflow vulnerabilityA remote code execution vulnerability exists in Microsoft Excel for Mac 2011 when it fails to properly handle objects in memory, aka "Microsoft Offic…EPSS 20%7.8CVE-2017-8632Microsoft excel memory buffer overflow vulnerabilityA remote code execution vulnerability exists in Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Service Pack 1, Microsoft Excel 2013 RT Ser…EPSS 18%

Source: NIST National Vulnerability Database (record CVE-2015-6123), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.