Microsoft Outlook vulnerabilities
106 known vulnerabilities affecting microsoft/outlook.
Total CVEs
106
CISA KEV
5
actively exploited
Public exploits
18
Exploited in wild
6
Severity breakdown
CRITICAL11HIGH52MEDIUM43
Vulnerabilities
Page 4 of 6
CVE-2020-16949P3HIGHCVSS 7.5v2010v2013+1 more2020-10-16
CVE-2020-16949 [HIGH] CWE-401 CVE-2020-16949: <p>A denial of service vulnerability exists in Microsoft Outlook software when the software fails to
A denial of service vulnerability exists in Microsoft Outlook software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could cause a remote denial of service against a system.
Exploitation of the vulnerability requires that a specially crafted email be sent to a vulnerable Outlook
nvd
CVE-2017-8571P3HIGHCVSS 7.8v2007v2010+2 more2017-08-01
CVE-2017-8571 [HIGH] CWE-20 CVE-2017-8571: Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, and Outlook 201
Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, and Outlook 2016 as packaged in Microsoft Office allows a security feature bypass vulnerability due to the way that it handles input, aka "Microsoft Office Outlook Security Feature Bypass Vulnerability".
nvd
CVE-2024-26204P3HIGHCVSS 7.5fixed in 4.2404.02024-03-12
CVE-2024-26204 [HIGH] CWE-77 CVE-2024-26204: Outlook for Android Information Disclosure Vulnerability
Outlook for Android Information Disclosure Vulnerability
nvd
CVE-2019-1084P3MEDIUMCVSS 6.5v2013v20162019-07-15
CVE-2019-1084 [MEDIUM] CWE-200 CVE-2019-1084: An information disclosure vulnerability exists when Exchange allows creation of entities with Displa
An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security update addresses the issue by valida
nvd
CVE-2017-0204P3MEDIUMCVSS 5.5v2007v2010+2 more2017-04-12
CVE-2017-0204 [MEDIUM] CVE-2017-0204: Microsoft Outlook 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1, and Microsoft Ou
Microsoft Outlook 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1, and Microsoft Outlook 2016 allow remote attackers to bypass the Office Protected View via a specially crafted document, aka "Microsoft Office Security Feature Bypass Vulnerability."
nvd
CVE-2001-0322P4MEDIUMCVSS 5.0PoCv20002001-06-02
CVE-2001-0322 [MEDIUM] CVE-2001-0322: MSHTML.DLL HTML parser in Internet Explorer 4.0, and other versions, allows remote attackers to caus
MSHTML.DLL HTML parser in Internet Explorer 4.0, and other versions, allows remote attackers to cause a denial of service (application crash) via a script that creates and deletes an object that is associated with the browser window object.
nvd
CVE-2000-0419P4HIGHCVSS 7.5v20002000-05-11
CVE-2000-0419 [HIGH] CVE-2000-0419: The Office 2000 UA ActiveX Control is marked as "safe for scripting," which allows remote attackers
The Office 2000 UA ActiveX Control is marked as "safe for scripting," which allows remote attackers to conduct unauthorized activities via the "Show Me" function in Office Help, aka the "Office 2000 UA Control" vulnerability.
nvd
CVE-2020-0696P3MEDIUMCVSS 6.5v2010v2013+1 more2020-02-11
CVE-2020-0696 [MEDIUM] CVE-2020-0696: A security feature bypass vulnerability exists in Microsoft Outlook software when it improperly hand
A security feature bypass vulnerability exists in Microsoft Outlook software when it improperly handles the parsing of URI formats, aka 'Microsoft Outlook Security Feature Bypass Vulnerability'.
nvd
CVE-2017-0207P4MEDIUMCVSS 6.5v20112017-04-12
CVE-2017-0207 [MEDIUM] CVE-2017-0207: Microsoft Outlook for Mac 2011 allows remote attackers to spoof web content via a crafted email with
Microsoft Outlook for Mac 2011 allows remote attackers to spoof web content via a crafted email with specific HTML tags, aka "Microsoft Browser Spoofing Vulnerability."
nvd
CVE-2025-49699P3HIGHCVSS 7.0v20162025-07-08
CVE-2025-49699 [HIGH] CWE-416 CVE-2025-49699: Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2018-8244P3MEDIUMCVSS 6.5v2010-sp2v2013-sp1+1 more2018-06-14
CVE-2018-8244 [MEDIUM] CWE-20 CVE-2018-8244: An elevation of privilege vulnerability exists when Microsoft Outlook does not validate attachment h
An elevation of privilege vulnerability exists when Microsoft Outlook does not validate attachment headers properly, aka "Microsoft Outlook Elevation of Privilege Vulnerability." This affects Microsoft Office, Microsoft Outlook.
nvd
CVE-1999-0519P3HIGHCVSS 7.5v20001997-01-01
CVE-1999-0519 [HIGH] CVE-1999-0519: A NETBIOS/SMB share password is the default, null, or missing.
A NETBIOS/SMB share password is the default, null, or missing.
nvd
CVE-2019-0559P3MEDIUMCVSS 6.5v2010-sp2v2013-sp1+1 more2019-01-08
CVE-2019-0559 [MEDIUM] CVE-2019-0559: An information disclosure vulnerability exists when Microsoft Outlook improperly handles certain typ
An information disclosure vulnerability exists when Microsoft Outlook improperly handles certain types of messages, aka "Microsoft Outlook Information Disclosure Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook.
nvd
CVE-2018-0850P3MEDIUMCVSS 6.5v2007v2010+2 more2018-02-15
CVE-2018-0850 [MEDIUM] CVE-2018-0850: Microsoft Outlook 2007, Microsoft Outlook 2010, Microsoft Outlook 2013, Microsoft Outlook 2016, and
Microsoft Outlook 2007, Microsoft Outlook 2010, Microsoft Outlook 2013, Microsoft Outlook 2016, and Microsoft Office 2016 Click-to-Run allow an elevation of privilege vulnerability due to how the format of incoming message is validated, aka "Microsoft Outlook Elevation of Privilege Vulnerability".
nvd
CVE-2017-17688P4MEDIUMCVSS 5.9v20072018-05-16
CVE-2017-17688 [MEDIUM] CVE-2017-17688: The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can in
The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature or accept an obsolete packet type, not a problem in the OpenPGP specification
nvd
CVE-2024-38173P4MEDIUMCVSS 6.7v20162024-08-13
CVE-2024-38173 [MEDIUM] CWE-73 CVE-2024-38173: Microsoft Outlook Remote Code Execution Vulnerability
Microsoft Outlook Remote Code Execution Vulnerability
nvd
CVE-2024-43482P3MEDIUMCVSS 6.5fixed in 4.2435.02024-09-10
CVE-2024-43482 [MEDIUM] CWE-285 CVE-2024-43482: Microsoft Outlook for iOS Information Disclosure Vulnerability
Microsoft Outlook for iOS Information Disclosure Vulnerability
nvd
CVE-2025-21357P4MEDIUMCVSS 6.7v20162025-01-14
CVE-2025-21357 [MEDIUM] CWE-908 CVE-2025-21357: Microsoft Outlook Remote Code Execution Vulnerability
Microsoft Outlook Remote Code Execution Vulnerability
nvd
CVE-2000-0621P4HIGHCVSS 7.5v97v98+1 more2000-07-20
CVE-2000-0621 [HIGH] CVE-2000-0621: Microsoft Outlook 98 and 2000, and Outlook Express 4.0x and 5.0x, allow remote attackers to read fil
Microsoft Outlook 98 and 2000, and Outlook Express 4.0x and 5.0x, allow remote attackers to read files on the client's system via a malformed HTML message that stores files outside of the cache, aka the "Cache Bypass" vulnerability.
nvd
CVE-2003-1048P4HIGHCVSS 7.8v20002004-07-27
CVE-2003-1048 [HIGH] CWE-415 CVE-2003-1048: Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote
Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.
nvd