CVE-2000-0036
published 1999-12-22CVE-2000-0036: Outlook Express 5 for Macintosh downloads attachments to HTML mail without prompting the user, aka the "HTML Mail Attachment" vulnerability.
PriorityP415medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
3.92%
89.2th percentile
Outlook Express 5 for Macintosh downloads attachments to HTML mail without prompting the user, aka the "HTML Mail Attachment" vulnerability.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | ie | — | — |
| microsoft | outlook_express | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft Outlook Express on Mac HTML Attachment privileges management (MS99-060 / XFDB-3551)
vuldb·2026-04-20·CVSS 5.0
CVE-2000-0036 [MEDIUM] Microsoft Outlook Express on Mac HTML Attachment privileges management (MS99-060 / XFDB-3551)
A vulnerability labeled as critical has been found in Microsoft Outlook Express on Mac. The impacted element is an unknown function of the component HTML Attachment Handler. Executing a manipulation can lead to improper privilege management.
This vulnerability appears as CVE-2000-0036. The attack may be performed from remote. There is no available exploit.
Applying a patch is advised to resolve this issue.
GHSA
GHSA-wh2w-hjg4-rm27: Outlook Express 5 for Macintosh downloads attachments to HTML mail without prompting the user, aka the "HTML Mail Attachment" vulnerability
ghsa_unreviewed·2022-04-30
CVE-2000-0036 [MEDIUM] GHSA-wh2w-hjg4-rm27: Outlook Express 5 for Macintosh downloads attachments to HTML mail without prompting the user, aka the "HTML Mail Attachment" vulnerability
Outlook Express 5 for Macintosh downloads attachments to HTML mail without prompting the user, aka the "HTML Mail Attachment" vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ249082https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-060http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ249082https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-060
1999-12-22
Published