Assuming that I have a need to share documents on a website that may
contain hostile code, what should I do to protect myself and my end
users?
I will go ahead and take a try at answering this question. The honest truth is that most exploits in a word document, pdf document, take your pick document contained both valid and malicious content.
One could in theory have a perfectly valid word document which contains a malicious third-party content ( some external content is allowed ) which causes either an unknown serious of events to occur which allowws malicous code to be run or say in the case of a PDF file within Adobe Reader malicious Javascript to be ran.
So there are several things you can do.
Convert all documents to a single format( my suggestion is PDF ) and use the built in security capabiltiies of Chrome, IE9, and Firefox and display the document within the browser itself. This means you don't actually transfer the file to the user unless they decide they want to save the file.
As I said you will be unable to catch every single thing.