Microsoft Outlook vulnerabilities
106 known vulnerabilities affecting microsoft/outlook.
Total CVEs
106
CISA KEV
5
actively exploited
Public exploits
18
Exploited in wild
6
Severity breakdown
CRITICAL11HIGH52MEDIUM43
Vulnerabilities
Page 2 of 6
CVE-2013-3870P3CRITICALCVSS 9.3v2007v20102013-09-11
CVE-2013-3870 [CRITICAL] CWE-399 CVE-2013-3870: Double free vulnerability in Microsoft Outlook 2007 SP3 and 2010 SP1 and SP2 allows remote attackers
Double free vulnerability in Microsoft Outlook 2007 SP3 and 2010 SP1 and SP2 allows remote attackers to execute arbitrary code by including many nested S/MIME certificates in an e-mail message, aka "Message Certificate Vulnerability."
nvd
CVE-2010-2728P3CRITICALCVSS 9.3v2002v2003+1 more2010-09-15
CVE-2010-2728 [CRITICAL] CWE-119 CVE-2010-2728: Heap-based buffer overflow in Microsoft Outlook 2002 SP3, 2003 SP3, and 2007 SP2, when Online Mode f
Heap-based buffer overflow in Microsoft Outlook 2002 SP3, 2003 SP3, and 2007 SP2, when Online Mode for an Exchange Server is enabled, allows remote attackers to execute arbitrary code via a crafted e-mail message, aka "Heap Based Buffer Overflow in Outlook Vulnerability."
nvd
CVE-2006-0002P3HIGHCVSS 7.5v2000v2002+1 more2006-01-10
CVE-2006-0002 [HIGH] CVE-2006-0002: Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP
Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.
nvd
CVE-2000-0567P4MEDIUMCVSS 5.0PoCv97v98+1 more2000-07-18
CVE-2000-0567 [MEDIUM] CVE-2000-0567: Buffer overflow in Microsoft Outlook and Outlook Express allows remote attackers to execute arbitrar
Buffer overflow in Microsoft Outlook and Outlook Express allows remote attackers to execute arbitrary commands via a long Date field in an email header, aka the "Malformed E-mail Header" vulnerability.
nvd
CVE-2001-1088P4HIGHCVSS 7.5PoCv97v98+1 more2001-06-05
CVE-2001-1088 [HIGH] CVE-2001-1088: Microsoft Outlook 8.5 and earlier, and Outlook Express 5 and earlier, with the "Automatically put pe
Microsoft Outlook 8.5 and earlier, and Outlook Express 5 and earlier, with the "Automatically put people I reply to in my address book" option enabled, do not notify the user when the "Reply-To" address is different than the "From" address, which could allow an untrusted remote attacker to spoof legitimate addresses and intercept email from the client that is i
nvd
CVE-2020-1483P3HIGHCVSS 8.8v2010v2013+1 more2020-08-17
CVE-2020-1483 [HIGH] CWE-787 CVE-2020-1483: A remote code execution vulnerability exists in Microsoft Outlook when the software fails to properl
A remote code execution vulnerability exists in Microsoft Outlook when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affec
nvd
CVE-2007-0034P3CRITICALCVSS 9.3v2000v2002+1 more2007-01-09
CVE-2007-0034 [CRITICAL] CWE-119 CVE-2007-0034: Buffer overflow in the Advanced Search (Finder.exe) feature of Microsoft Outlook 2000, 2002, and 200
Buffer overflow in the Advanced Search (Finder.exe) feature of Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted Outlook Saved Searches (OSS) file that triggers memory corruption, aka "Microsoft Outlook Advanced Find Vulnerability."
nvd
CVE-2007-0033P3CRITICALCVSS 9.3v2000v2002+1 more2007-01-09
CVE-2007-0033 [CRITICAL] CVE-2007-0033: Microsoft Outlook 2002 and 2003 allows user-assisted remote attackers to execute arbitrary code via
Microsoft Outlook 2002 and 2003 allows user-assisted remote attackers to execute arbitrary code via a malformed VEVENT record in an .iCal meeting request or ICS file.
nvd
CVE-2004-0502P4MEDIUMCVSS 5.0PoCv20032004-08-18
CVE-2004-0502 [MEDIUM] CVE-2004-0502: Outlook 2003, when replying to an e-mail message, stores certain files in a predictable location for
Outlook 2003, when replying to an e-mail message, stores certain files in a predictable location for the "src" of an img tag of the original message, which allows remote attackers to bypass zone restrictions and exploit other issues that rely on predictable locations, as demonstrated using a shell: URI.
nvd
CVE-2020-0760P3HIGHCVSS 8.8v2010v2013+1 more2020-04-15
CVE-2020-0760 [HIGH] CVE-2020-0760: A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type l
A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries, aka 'Microsoft Office Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0991.
nvd
CVE-2020-1349P3HIGHCVSS 7.8v2010v2013+1 more2020-07-14
CVE-2020-1349 [HIGH] CVE-2020-1349: A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly
A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka 'Microsoft Outlook Remote Code Execution Vulnerability'.
nvd
CVE-2017-0106P3HIGHCVSS 7.8v2007v2010+2 more2017-04-12
CVE-2017-0106 [HIGH] CWE-119 CVE-2017-0106: Microsoft Excel 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1, and Microsoft Outl
Microsoft Excel 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1, and Microsoft Outlook 2016 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2018-0791P3HIGHCVSS 7.8v2007v2010+2 more2018-01-10
CVE-2018-0791 [HIGH] CVE-2018-0791: Microsoft Outlook 2007, Microsoft Outlook 2010, Microsoft Outlook 2013, and Microsoft Outlook 2016 a
Microsoft Outlook 2007, Microsoft Outlook 2010, Microsoft Outlook 2013, and Microsoft Outlook 2016 allow a remote code execution vulnerability due to the way email messages are parsed, aka "Microsoft Outlook Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0793.
nvd
CVE-2016-3278P3HIGHCVSS 7.8v2010v2013+1 more2016-07-13
CVE-2016-3278 [HIGH] CWE-119 CVE-2016-3278: Microsoft Outlook 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016 allows remote attackers to execute arbit
Microsoft Outlook 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2017-8506P3HIGHCVSS 7.8v2010v2013+1 more2017-06-15
CVE-2017-8506 [HIGH] CVE-2017-8506: A remote code execution vulnerability exists in Microsoft Office when the software fails to properly
A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8509, CVE-2017-8510, CVE-2017-8511, CVE-2017-8512, and CVE-2017-0260.
nvd
CVE-2024-42220P3CRITICALCVSS 9.1v16.83.3v16.83.3 for macOS2024-12-18
CVE-2024-42220 [CRITICAL] CWE-347 CVE-2024-42220: A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted
A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and then make use of the vulnerable application's permissions.
nvd
CVE-2017-8663P3HIGHCVSS 7.8v2007v2010+2 more2017-08-01
CVE-2017-8663 [HIGH] CWE-119 CVE-2017-8663: Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, and Outlook 201
Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, and Outlook 2016 as packaged in Microsoft Office allows a remote code execution vulnerability due to the way Microsoft Outlook parses specially crafted email messages, aka "Microsoft Office Outlook Memory Corruption Vulnerability"
nvd
CVE-2017-8507P3HIGHCVSS 7.8v2007v2010+2 more2017-06-15
CVE-2017-8507 [HIGH] CWE-119 CVE-2017-8507: A remote code execution vulnerability exists in the way Microsoft Office software parses specially c
A remote code execution vulnerability exists in the way Microsoft Office software parses specially crafted email messages, aka "Microsoft Office Memory Corruption Vulnerability".
nvd
CVE-2018-8576P3HIGHCVSS 7.8v2010-sp2v2013-sp1+1 more2018-11-14
CVE-2018-8576 [HIGH] CVE-2018-8576: A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly
A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook. This CVE ID is unique from CVE-2018-8522, CVE-2018-8524, CVE-2018-8582.
nvd
CVE-2018-8522P3HIGHCVSS 7.8v2010-sp2v2013-sp1+1 more2018-11-14
CVE-2018-8522 [HIGH] CVE-2018-8522: A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly
A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook. This CVE ID is unique from CVE-2018-8524, CVE-2018-8576, CVE-2018-8582.
nvd